A Fortune 500 healthcare CIO told me last quarter, after we’d won her business, that there were three questions she had wanted to ask in every AI vendor pitch she had taken in the previous 18 months, and never had.
Not because the questions were embarrassing.
Because asking them would have signaled, to her board and her own engineering team, that she didn’t already know the answers.
So she made her decision without asking. Which means most AI vendors have been losing deals to questions they were never given a chance to answer.
If you sell AI into regulated industries, you should know what those three questions are.
I have been on the receiving end of versions of them for two years, sometimes asked directly, more often implied by what the CIO did not say. After enough deals, the pattern becomes obvious. Every senior buyer in healthcare, financial services, legal, and insurance is silently testing for the same three things.
The vendors who answer them, without being asked, win.
The vendors who don’t, lose, and never find out why.
QUESTION
1. “If your model changes tomorrow, what changes in my system?”
The scene
I was on a video call with the COO of a multi-state hospital network last spring. She had been quiet for most of the demo. Right at the end, she asked our engineer one question.
"What model are you using?"
Our engineer answered: "Claude Opus 4.4."
She nodded. "And next month?"
We told her honestly: "Probably Opus 4.5, depending on what releases."
She closed her laptop. "Send me a write-up."
We knew immediately what had happened.
What she was really asking
"When your foundation model upgrades, what changes in my regulatory posture, my audit trail, my evidentiary record, and my contractual liability?"
Most AI vendors hear "what model are you using?" as a technical question and answer it with model names. The CIO is asking a governance question. She wants to know whether your architecture absorbs the upgrade, or whether her compliance posture shifts every time Anthropic ships a release.
What the winning answer sounds like
"Nothing on your side changes. The model upgrade is contained. Our policy layer is versioned independently. Your audit trail uses a stable hash that doesn’t change when the model does. We notify you with a 30-day window, and the contract pins the audit guarantees regardless of model version."
If you cannot say that, she assumes, correctly, that her compliance team will have to re-evaluate your vendor every time you upgrade. That is, in her language, an unacceptable answer.
QUESTION
2. “If your agent does the wrong thing at 2am, who calls me?”
The scene
A General Counsel at an insurance carrier asked this one explicitly. Final-stage pitch. She didn’t ask about features. She didn’t ask about pricing. She leaned forward and asked:
"If your agent does the wrong thing at 2am, who calls me, and what do they say?"
We had the answer. We won that deal.
What she was really asking
"When this goes wrong, and it will, who owns the failure? Is it me? Is it you? What is the playbook? Do I have to design the incident response, or have you?"
Most AI vendors do not have an answer to this question. They have a status page. They have a Slack channel. They have an on-call rotation for their own team.
What they don’t have is a named incident protocol for the customer’s environment. Who calls whom. In what order. With what information. With what authority to pause the agent. With what mechanism for the customer to halt all agent activity unilaterally, without asking you for permission.
What the winning answer sounds like
"At 2am, a named on-call engineer on our side calls a named on-call lead on yours. The playbook is in your hands today, in writing, before contract signature. You have a kill switch that you control. Every agent decision in the last 90 days is replayable in five minutes."
If you can’t say that, she assumes she’ll be writing your incident-response document for you, on her time, while her board is asking why the AI did what it did.
Most AI vendors are still selling capability. Senior regulated-industry buyers stopped buying capability 18 months ago. They are buying defensibility, and the vendors who realize that, win.
QUESTION
3. “What do I tell my regulator when she asks how this decision was made?”
The scene
Fortune 100 financial services firm, deal review call, February. We had done the demo, we had answered the procurement questionnaire, we had survived three rounds of security review. The last meeting was with the Chief Risk Officer.
She asked one question.
"When our regulator asks us, not you, us, how this AI made a specific decision, what is the answer we give them?"
This is the deepest question in regulated-industry AI right now. It is also the one most vendors are not prepared for.
What she was really asking
"Are you giving me a tool, or are you giving me a regulator-defensible system?"
There is no good answer that starts with the model. The good answer starts with the policy, the evidentiary record, the named human reviewer, the audit-replayable decision log, and the structured refusal record for every decision the agent escalated.
What the winning answer sounds like
"For any decision your AI made in the last 90 days, we produce, in under five minutes, the exact inputs your model received, the policy that governed it, the model version that handled it, the output it produced, the human reviewer (if any), and a stable hash that proves the record was not tampered with. That packet is yours, formatted for your regulator’s expected schema, with no work required on your side."
If you can’t say that, she assumes, correctly, that her firm is on the hook for explaining the AI’s behavior to a regulator. That is not a partnership. That is a liability she is taking on alone.
The deeper truth
Capability is now table stakes. Defensibility is the moat.
Here is the thing nobody is saying out loud.
In 2026, the most senior buyers in regulated industries are no longer evaluating AI vendors on intelligence.
They are evaluating them on the blast radius of being wrong.
Capability is now table stakes. Every model is smart enough. Every demo lands. Every benchmark is impressive. The differentiator is no longer how smart your agent is.
It is what happens the day your agent is wrong.
That is the entire game. And the vendors who answer that question, clearly, contractually, architecturally, win the deals the loud vendors miss.
Capability is table stakes. Defensibility is the moat. The CIO who closes your deal isn’t buying your AI. She’s buying the blast-radius design behind it.
THE BUILDER'S TAKEAWAYS
How to answer the questions the buyer will not ask
1. Write the incident protocol before the first sales call.
If a customer’s GC asks you "who calls me at 2am?", you should have a one-page answer with named roles, a kill-switch description, and a 90-day decision-replay guarantee. Send it unsolicited in the pitch deck. The buyer reads it as confidence.
2. Version your policy layer independently of your model.
If your compliance posture changes every time Anthropic ships a release, your customer cannot trust the contract. Build the abstraction layer that decouples them before your first regulated-industry customer, not after. Retrofitting this under deal pressure is 10x more expensive than building it cleanly.
3. Build a "regulator packet" feature before you need it.
For any decision your AI made, produce a complete, audit-replayable record in your customer’s regulator-expected schema, in under five minutes. This is the moat. Build it before deal pressure forces you to retrofit it. By the time a CRO asks for it on a pitch call, it is too late.
The smartest CIO I’ve ever sold to closed our deal with one sentence at the end of the last meeting.
"I’m not buying AI from you.
I’m buying defensibility from you.
The AI is the engine."
That sentence is the entire next decade of enterprise AI.
The vendors who hear it, win.
The ones who don’t, lose deals they thought they had already won, and never find out why.
