In February 2024, a Canadian tribunal ordered Air Canada to pay a grieving customer $812.02. His mistake was believing the airline's own chatbot, which described a bereavement refund policy that did not exist. Air Canada's defense was that the bot was, in its words, "a separate legal entity that is responsible for its own actions." The tribunal called that "a remarkable submission" and held that it should be obvious the airline "is responsible for all the information on its website," chatbot included.
Every compliance officer already knew that in their bones. You own what your bot says. It is the reason so many good chatbot proposals die in legal review, and it is the real subject of this post: not the chatbot that answers fast, but the one a compliance team can actually approve, and what has to be true before they will sign.
What is a compliance-grade chatbot?
A compliance-grade chatbot is a customer-facing AI agent that answers only from a company's approved content, cites its source on every reply, declines when it has no grounding, and records each exchange in an audit trail. It is built for regulated industries, banking, wealth management, healthcare, education, and government, where a wrong answer stops being a bad customer experience and becomes a reportable incident. The guardrails, not the conversation, are the product.
I spent close to thirty years selling enterprise technology through shifts exactly like this one, at Dell, VMware, and AWS. During my time at AWS I led the HIPAA and FedRAMP compliance certification work with the compliance team, standing up healthcare and public-sector solutions that had to pass review before a single patient record touched them. That work taught me the one thing every vendor in a regulated market eventually learns. The gate is never "does it work." The gate is "will the compliance officer put their name on it." A chatbot that dazzles in a demo and cannot survive that question is not a product. It is a liability with a text box.
What "approvable" actually requires
The features that clear a compliance review are not the ones in the marketing headline. They are the boring, provable ones, and there are six that matter.
Grounded answers, or none. The agent checks every answer against your own pages before it goes out. When nothing supports the question, it says so instead of inventing a reply. This is the single most important control, because grounding is not a solved problem. When Stanford's RegLab tested the leading legal AI research tools in May 2024, the retrieval-grounded, industry-specific products still "hallucinate between 17% and 33% of the time," and the researchers concluded the vendors' hallucination-free claims "are overstated." Grounding lowers the risk. It does not erase it. That is why "cite or decline" has to be enforced, not hoped for.
Rule packs that attach the disclaimers. A rule pack built for your industry watches every conversation for sensitive topics and attaches the disclaimer each one requires, before a person ever sees the answer. A disclaimer here means the specific language a regulator expects on a specific kind of statement, a suitability caveat on an investment question, for example.
Crisis routing. Anything that reads like a crisis goes straight to a human. The agent has to know what it must never handle alone.
A full audit trail. Every question asked and every citation returned is logged. When compliance or legal asks what the agent said and why, you show them, exactly.
Data isolation. Each brand's data is encrypted under its own keys and kept apart from every other tenant. What powers your agent never mingles with anyone else's.
A named human in control. Not in the loop as a rubber stamp, in control: an accountable person who owns what the agent is allowed to say.
The support-desk question
"How many tickets did we deflect this month?" It is a real and useful number. It measures efficiency, and a busy support team lives or dies by it.
The compliance question
"For any answer we gave, can we show exactly what was said, what it was based on, and that the disclaimer was attached?" It measures defensibility. In a regulated business, it is the one that decides whether the project launches at all.
The questions a compliance team asks before it signs
If you want to know whether an AI agent will survive review, ask it the way a compliance officer would. Six questions separate the approvable from the un-approvable.
1. Can it cite every answer, or does it guess? If a cited answer can appear without a real source behind it, the tool is guessing with footnotes. Ask to see a refusal, not just a good answer. The refusal is the proof the guardrail works.
2. Does it know what it must not touch? A safe agent has a list of topics it hands to a human on sight. If the vendor cannot tell you what is on that list, there is no list.
3. Does every sensitive topic carry its required disclaimer, automatically? In financial services this is not optional. FINRA reminded firms in Regulatory Notice 24-09, issued June 2024, that its rules "continue to apply when member firms use Gen AI or similar technologies" exactly as they apply to any other tool. The regulator did not carve out a chatbot exception, and it will not.
4. Is there a complete audit trail? Regulators increasingly assume one exists. The EU AI Act's heavier obligations for high-risk systems, logging, human oversight, and transparency, become binding on August 2, 2026. Breaches of those duties carry penalties up to 15 million euros or 3 percent of worldwide turnover, and the Act's ceiling for its gravest violations reaches 35 million or 7 percent. Even the Act's lighter rule for ordinary chatbots requires that people be "informed that they are interacting with an AI system, unless this is obvious." If you cannot reconstruct a conversation months later, you cannot answer a regulator, or a plaintiff.
5. Whose data touches the model, and where does it live? Per-tenant isolation and your own encryption keys are the difference between a vendor incident being your incident or someone else's.
6. Who is accountable when it is wrong? Air Canada's answer to this question, "not us, the bot," cost it in court and cost it more in trust. The right answer names a person.
Software or service: what are you actually buying?
Here is the comparison the shortlists skip, and it matters more than any feature grid. The best-known names in AI support, Wonderchat and Fini, are self-serve platforms you deploy and run. Trinzik is a service that builds the agent for you and owns the result. Comparing them feature for feature is apples to oranges. The real question is which kind of buyer you are.
Wonderchat calls itself "the all-in-one platform for AI customer support and inbound conversion agents." It is fast, "Live in five minutes," it says, promises that "every response cites its source," reports a "70+% Resolution Rate" with a case study that "deflected 92% of repetitive support tickets," and carries GDPR and AICPA SOC 2 certification. Fini goes after the enterprise support desk: "the first self-learning AI agent that resolves 90% support tickets" at "99% accuracy across fintech, banking, and regulated industries," across voice, chat, and email, priced at "$0.49 per resolution" with a zero-pay guarantee, and stacked with certifications, SOC 2 Type II, PCI DSS Level 1, ISO 27001, GDPR, and HIPAA with BAA-ready terms.
Those are strong products, and I will not pretend otherwise. If you run a high-volume support desk and you need a bot live this week to deflect repetitive tickets, Wonderchat's speed is a genuine advantage. If you are an enterprise measuring cost per resolution and you need named certifications on the vendor itself, Fini's deflection numbers and its compliance stack are a serious, defensible buy.
Software resolves tickets. A service owns the answer.
What a self-serve platform does not do is the part that follows the score. Someone on your team still has to decide which topics are off limits, tune the disclaimers to your regulator, review the audit log, and answer for the agent when it is wrong. The platform hands you the controls. It does not sit in your chair.
Trinzik sits on the other side of that line. We are a boutique, white-glove service, concierge-level by design, with our own technology underneath. We build a cited agent into your own website, tuned to your industry's rule packs, that declines what it cannot support, routes crises to your people, and logs every exchange for the audit trail. You see what visitors and AI actually ask: question volume, citation rate, refusals, and the top intents behind them, every answer traceable to its source. And a named human, not a setting, controls what it is allowed to say.
| The question | Self-serve platform (Wonderchat, Fini) | Trinzik |
|---|---|---|
| What you are buying | Software your team deploys and runs | A boutique, white-glove service that owns the outcome |
| Built for | Support teams that need a bot live fast | Regulated businesses that want full support without building the function |
| Who does the work | Your operators | Our team, concierge-level; your named expert approves |
| Time to value | Minutes to days | A build, tuned to your rule packs |
| Compliance posture | Vendor certifications on multi-tenant software | Per-tenant isolation, your own keys, an audit trail your team reviews directly |
| When it has no answer | Depends on the deployment | It declines and cites, by design |
| Who is accountable | Your team, after the fact | A named person, owning it up front |
One honest caveat runs the other way. Wonderchat and Fini carry named certifications on their own platforms today; Trinzik's assurance is architectural, per-tenant isolation, your own encryption, and an audit trail your compliance team reads directly, rather than a badge on a shared multi-tenant service. If your review turns on a specific certificate held by the vendor, weigh that honestly. If it turns on whether your own team can inspect and approve every control, that is the ground a boutique build is built for.
Our discipline here is not a pose. Trinzik's roots are in government and university web work, where Section 508, WCAG, and ADA were conditions of launch and every public property had to survive review before it went live. That is the same reflex we bring to a regulated chatbot: assume it will be audited, and build so it passes.
17-33%
how often grounded, industry-specific legal AI still hallucinated
Stanford RegLab, May 2024
Aug 2 2026
EU AI Act high-risk obligations become binding
logging, human oversight, transparency
EUR 35M
maximum EU AI Act penalty, or 7% of global turnover
Article 99
Where this is heading
I have watched this movie before. I sold virtualization when server admins swore they would never run production on a virtual machine, and I sold the public cloud in 2015 to the exact objection you hear about AI support today: a regulated business cannot put that in front of customers. Both times, the regulated industries did not stay out. They moved last and moved carefully, once the controls were provable. The winners were the ones who saw the shift early and built for the review instead of around it.
AI is rewriting how customers get answers, and Google is no longer the only front door. The chatbots that last in banking, healthcare, and wealth management will not be the ones that answer fastest. They will be the ones that can prove what they said, why they said it, and who is accountable for it. The same discipline extends past customer chat, too: the agent that answers your visitors can carry a signed identity at your domain, so as buyers send their own AI agents to do research, your website itself becomes the verified, cited source, not a guess.
Based in Austin, Texas, Trinzik builds it that way on purpose: a human in control, an answer that cites or declines, and a trail that survives the audit. If your compliance team has killed every chatbot proposal it has seen, that is the one worth showing them.
Questions this raises
What makes an AI chatbot safe for a regulated industry?
A chatbot is safe for a regulated industry when it cannot make things up. That means four things working together: it answers only from your approved content and cites the source on every reply, it declines when it has no grounding instead of guessing, it attaches the disclaimers your industry requires and routes anything sensitive to a human, and it records every exchange in an audit trail. The conversation is the easy part. The provable restraint is what clears a compliance review.
Are AI chatbots covered by regulations like the EU AI Act and FINRA rules?
Yes. The EU AI Act requires that people be told when they are interacting with an AI system, and its heavier obligations for high-risk uses, logging, human oversight, and transparency, become binding on August 2, 2026; breaches of those duties carry penalties up to 15 million euros or 3 percent of global turnover. In the United States, FINRA's Notice 24-09 says existing securities rules apply to generative AI like any other tool, and the Air Canada ruling made a company liable for what its chatbot said.
What is the difference between Trinzik and a platform like Wonderchat or Fini?
They are different kinds of product. Wonderchat and Fini are self-serve support platforms: you connect your content, deploy the bot, and your team runs it, with fast setup and strong ticket-deflection numbers. Trinzik is a boutique, white-glove service. We build a cited, policy-enforced agent into your own website, tuned to your industry's rule packs, with a full audit trail and a named human accountable for every answer. Software your team operates, versus an outcome owned for you with full support.
Sources
- Moffatt v. Air Canada (McCarthy Tetrault, TechLex), the Civil Resolution Tribunal ruling holding the airline liable for its chatbot
- Magesh et al., Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools, Stanford RegLab / HAI
- EU AI Act, Article 50 (transparency obligations), artificialintelligenceact.eu
- FINRA Regulatory Notice 24-09, obligations when using generative AI and large language models, finra.org
- Wonderchat (wonderchat.io), product positioning and claims, as published on their site
- Fini (usefini.com), product positioning and claims, as published on their site