Glossary
Regulated data
Information that carries obligations of its own, such as health or financial records, where what may be used to handle it is decided by rules rather than by preference.
In plain terms
Some material comes with strings attached because of what it is rather than because of who it is about. Health records and financial records are the usual examples. The practical difference for a buyer is that the ordinary evaluation, is this tool any good and can we afford it, happens second. What may be used at all is settled first, and often by somebody other than the person choosing.
Why it matters
Because it inverts how purchasing normally works, and teams that do not recognise the inversion waste an evaluation. The usual sequence is to find the best tool and then check it clears review. Here the shortlist is determined before anybody looks at a feature list, and a team that has fallen for a product and then discovers it cannot be used has spent weeks arriving at a conclusion available on day one.
How it works
The obligations attach to the material, so they follow it wherever it goes. Extracting figures into a spreadsheet, summarising a record into a note or pasting a paragraph into a prompt does not usually leave them behind, and the derived thing frequently carries the same character as the original. That is the property that surprises people, because the copy feels less consequential than the record.
It shrinks the candidate list before evaluation rather than after. What is permitted may rule out whole deployment shapes, which is why organisations handling this kind of material end up looking at self-hosted or regionally controlled options that a general buyer would not consider. Starting from what is allowed and then evaluating within that is the sequence that does not waste anybody's month.
The boundary spreads, and that is the practical difficulty. A single field in an otherwise ordinary dataset can pull the whole thing into scope, and a general-purpose tool that would have been fine becomes a question because of one column somebody added. Knowing where that boundary sits in your own material is worth more than knowing the rules in the abstract.
Separation is the usual answer and it works by keeping the material apart rather than by finding a permissive tool. Handling the regulated part in a controlled environment and the ordinary part anywhere sensible avoids applying the strictest constraint to everything, which is the alternative and is expensive. Getting the split right is where the actual work sits.
Two buying sequences
Seen in the wild
Running a model on your own hardware so material that cannot leave the organisation is never sent anywhere.
OllamaLoading a model on a controlled machine through a desktop application, which is the same containment without a command line.
LM StudioA general assistant that is entirely suitable for ordinary drafting and not a candidate for this material at all.
ChatGPT
Common misconceptions
People assume
We can use anything if we are careful with it.
In fact
What is permitted is frequently decided by rules rather than by care, which is the distinguishing feature of this material. That is why the shortlist is set before evaluation and why a team can do everything conscientiously and still arrive at a tool it may not use.
People assume
A summary is not the same as the record.
In fact
Derived material usually carries the same character as what it came from, because the obligations attach to what the information is rather than to the file it arrived in. A paragraph extracted into a prompt is generally the same proposition as the record it was extracted from.
Telling them apart
Regulated data vs PII
Regulated data
Material with obligations of its own, where the rules choose the tool.
Anything identifying a person, which is broader and mostly judgement.
This is usually a subset carrying extra weight; most personal data is not regulated in this specific sense.
Questions
- How does it change buying?
- It reverses the order. What is permitted is settled before the evaluation rather than after it, so the shortlist is decided by constraints rather than by features. Teams that evaluate first frequently spend weeks reaching a conclusion that was available before they started.
- Does extracting a summary help?
- Usually not, because the obligations follow the information rather than the file. A figure copied into a spreadsheet or a paragraph pasted into a prompt generally carries the same character as the record it came from, which is the step people most often assume changes something.
- What is the practical approach?
- Separate the material rather than searching for a permissive tool. Handle the constrained part in a controlled environment and the ordinary part wherever suits, which avoids applying the strictest constraint to all the work. Deciding where the line falls in your own material is the real task.
Key takeaways
- The obligations attach to the material and follow it into copies and summaries.
- The shortlist is set before evaluation, not after it.
- One field can pull an otherwise ordinary dataset into scope.
- Separate the material rather than looking for a tool that permits everything.
Last checked July 2026