Short answer. In regulated categories such as health, finance and law, AI answer engines behave conservatively. They concentrate citations on a small pool of government, academic and institutional domains, cite vendor sites rarely, and still produce confident errors. For a regulated brand, visibility depends on becoming a verifiable, expert-attributed source, while ordinary compliance rules apply unchanged.
Key takeaways
- Regulated categories are the most concentrated in AI search: in one 2026 study the top ten domains took 71.2% of healthcare citation slots, against 28.4% in SaaS.
- Engines cite fewer sources per health answer, around 2.4 unique domains in that study, and lean on government, academic and non-profit institutions; vendor sites held roughly 5.2% of healthcare citations in one 2026 dataset.
- Accuracy remains a live problem: a BMJ Open audit rated close to half of adversarially prompted health chatbot answers as problematic, with a median reference completeness of 40%.
- FINRA's 2026 oversight report confirms a technology-neutral position: generative content carries the same supervision, approval and recordkeeping obligations as any other communication.
- Realistic levers for a regulated brand are verifiable expert attribution, primary evidence only the brand holds, presence in trusted intermediaries, visible freshness, and consistency across markets and languages.
Why do regulated categories behave differently in AI answers?
Answer engines apply extra caution to topics where a wrong answer could harm someone's health, money or safety, so they draw on institutional sources far more than they do in consumer categories. Search systems have done this for years, and generative systems inherited the caution.
Your Money or Your Life (YMYL) is a label from Google's quality guidance for topics where inaccurate information could damage a person's health, financial stability or safety.
The practical effect is a narrower funnel. In consumer categories, an answer engine can afford to draw on blogs, forums and listicles, because the cost of a mediocre coffee-machine recommendation is low. Where a wrong answer could send someone to the wrong treatment or the wrong financial product, engines fall back on sources that carry institutional weight.
An empirical study of generative search citations across domains found this shift in source composition, not only in tone: government-institution sources accounted for a substantially higher share of citations in law, finance and health than in consumer verticals, while commercial and transactional sites, dominant in hotels and leisure, nearly disappeared from finance and law answers (arXiv, 2026).
Google's own site-owner guidance offers no special regulated-content route. Its advice for AI features in Search stays with fundamentals: allow crawling, keep important content in textual form, use internal links, and make structured data match visible text. There is no YMYL schema to deploy, only the option of being the kind of source a cautious system will use. The general mechanics are covered in how AI search engines decide which brands to mention and cite.
How concentrated is the citation pool in health and finance?
Very concentrated. In a 2026 study of healthcare prompts, the ten most-cited domains captured 71.2% of all citation slots, compared with 28.4% in SaaS.
Citation concentration is the share of all citations in a category that goes to its few most-cited domains; the higher it is, the less room a new source has.
The study ran 1,200 buyer-intent prompts three times each across ChatGPT Search, Claude, Gemini and Perplexity between April and May 2026. It found that in healthcare, the top ten cited domains captured 71.2% of all citation slots, against 28.4% in SaaS. Healthcare also had the fewest citations per answer, a blended 2.4 unique domains versus 5.1 in SaaS, because engines concentrate health answers on a small, high-trust pool rather than spreading risk across many sources.
A secondary analysis of that dataset alongside two other studies put institutional names on the concentration: NIH at roughly 14.7% of healthcare citations, Mayo Clinic at 12.3%, the CDC at 9.8%, with academic and government sources together at 24.1% and vendor sites at 5.2%.
Tracking published in August 2026 found the same shape on ChatGPT specifically: across tracked healthcare prompts, every one of the five most-cited domains was a government agency or a non-profit hospital system, and that held for nine of the top ten.
| Vertical | Top-10 domain share | Median domains cited per answer |
|---|---|---|
| Healthcare | 71.2% | 2.4 |
| SaaS | 28.4% | 5.1 |
Source: Attrifast, 1,200 buyer-intent prompts across four engines, April to May 2026. Treat as directional: one research panel, one window, and engines change citation behaviour frequently.
There is an uncomfortable but useful strategic reading. In a concentrated vertical, the realistic path to visibility is rarely to out-rank the NIH. It is to be cited within the answer as the named source for a specific claim the institutional sources do not make, such as your clinical data, your pricing mechanics or your service specifics, or to be present in the small set of trusted editorial intermediaries the engines accept as proxies. Analysis of where AI citations actually go shows the same pattern outside regulated fields.
Format habits differ by vertical too. One analysis of 25,337 AI citations across eight brands found listicles pulling 61% of citations in B2B services and none at all in healthcare, a reminder that a content format that performs in one category can be structurally irrelevant in another.
How often do AI engines get regulated answers wrong?
Often enough that the risk runs in both directions: your brand may be absent, and the answer about your category may be wrong. An April 2026 audit found close to half of adversarially prompted health answers problematic.
An audit published in BMJ Open in April 2026 tested five widely used chatbots against 250 health questions across vaccines, cancer, stem cells, nutrition and athletic performance. Close to half of responses were rated problematic, roughly 30% somewhat problematic and 19.6% highly problematic. The published paper records that performance was strongest on vaccines and cancer and weakest on stem cells, athletic performance and nutrition, that outputs were delivered with consistent confidence, and that reference quality was poor, with a median completeness score of 40%.
Two caveats belong with that study, and the researchers state them. The prompts were adversarial by design, a red-teaming technique intended to surface failure modes, so the error rate overstates what a neutral question would produce. And the tested models were free tiers available at the time. Both caveats cut the number down; neither removes the finding that confident, poorly referenced answers are a normal output in the categories most prone to misinformation.
| Rating of 250 chatbot responses | Share of responses |
|---|---|
| Not problematic | 50% |
| Somewhat problematic | 30% |
| Highly problematic | 19.6% |
Source: Tiller et al., BMJ Open, April 2026. Prompts were deliberately adversarial, so these rates are an upper bound rather than a typical-use estimate.
For a regulated brand, monitoring is not optional. If half of adversarial answers in your category carry a problem, some share of those problems will be about you. Guidance on what to do when an AI gets your brand wrong covers the general remediation path.
Do compliance rules still apply to content written for AI answer engines?
Yes. Nothing in financial, health or legal communication rules has been suspended for AI. Content written to be extracted by an answer engine is still a communication to the public and needs the same review, approval and retention.
In financial services, FINRA devoted a standalone section of its 2026 Annual Regulatory Oversight Report, published December 2025, to generative AI, expanding considerably on previous years and, for the first time, addressing AI agents. The framework is technology-neutral: firms remain responsible for compliance when using generative tools, and the report sets expectations for governance, testing, monitoring and documentation (Debevoise summary). Earlier guidance in Regulatory Notice 24-09 had already reminded member firms that their obligations do not change when generative models are involved, naming content supervision, recordkeeping and customer information protection.
Fair and balanced presentation is the regulatory expectation that a communication presents benefits and risks together rather than promoting one without the other.
Read against an AEO programme, three constraints appear:
- Published claims are communications. Content created to be extractable is subject to the same review, approval and retention requirements as any other. "It was written for AI" is not a category.
- Balance cannot be optimised away. AEO rewards short, self-contained, quotable passages, while regulated communications require fair and balanced presentation. The resolution is not to abandon the answer-first format but to make the balancing material part of the extractable unit rather than a footnote the engine will drop.
- You cannot control the recombination. An engine may quote your benefit statement and omit your risk statement. That is a monitoring and content-design problem, not a legal defence, which is why regulated teams increasingly treat AI answers as a surface to audit rather than a channel to publish into.
Similar logic applies in health and legal marketing, where claim substantiation, fair balance and professional-conduct rules govern what may be said, irrespective of which machine repeats it.
What can a regulated brand realistically influence?
A regulated brand can influence the credibility and specificity of its own claims, not the institutional pool itself. Five levers matter most: verifiable expert attribution, unique primary evidence, presence in trusted intermediaries, freshness, and consistency across markets.
Expert attribution that a machine can verify. In concentrated verticals, the credential attached to a claim is part of the claim. A clinically reviewed page with a named, verifiable reviewer and a review date is a materially different artefact from an anonymous blog post, both to human readers and to systems assessing whether a source is safe to quote.
Primary evidence nobody else holds. Institutional domains cover general knowledge comprehensively and your specific product poorly. Your own trial data, outcome statistics, methodology, pricing mechanics and published safety information are claims only you can make, and they are the claims worth making extractable.
Presence in the intermediaries. When the institutional pool is closed, editorial intermediaries the engines already trust are the accessible route. Getting the facts right on those platforms is usually higher-yield than another page on your own domain, as the evidence on why third-party brand mentions matter for GEO suggests.
Freshness. Regulated categories move with guidance updates and rule changes, and a visibly dated, currently maintained page is a safer citation than an undated one.
Consistency across languages and markets. A regulated claim that differs between a company's English and non-English properties gives an engine grounds to distrust both. For multinational health and finance brands this is one of the most common, and least examined, sources of AI-answer inconsistency.
How does Lifewood approach AEO and GEO for regulated brands?
Lifewood treats regulated AEO and GEO as a data-quality discipline with expert review rather than a publishing sprint. Lifewood provides AEO and GEO services, so it has a commercial interest in this subject.
The work looks less like content marketing: verifying claims against primary sources, keeping the same fact identical across markets and languages, attaching review metadata, and re-checking outputs on a schedule. That is close to the human-in-the-loop verification Lifewood's teams already run on AI data programmes. You can see the scope of its AEO and GEO services on the service pages, and a comparison of AEO and GEO agencies lists other providers, including Lifewood, ranked against a stated criterion.
Other organisations cover adjacent ground. BrightEdge and Profound publish tracking data on which domains are cited in health and finance prompts. Law and compliance firms such as Debevoise have published practitioner analysis of the FINRA generative-AI expectations. Academic groups, the BMJ Open audit team among them, supply the independent accuracy measurement that no vendor can credibly supply about itself. A compliance-led programme usually needs several of these at once.
What should you do if AI describes your regulated product wrongly?
Trace the source of the error, correct it through your normal approval process, and keep measuring. The fix follows the cited source, not the answer text, and any remediation page is itself a regulated communication.
- Build a monitoring prompt set that includes the adversarial version. Not just "what is X" but the sceptical, comparative and misinformation-adjacent phrasings a real person uses. Measuring share of answer across repeated runs gives a steadier baseline.
- Log the cited sources, not only the answer. If a wrong figure traces to an outdated regulator filing or a third-party listing, fixing your own page will not move it.
- Route corrections through the existing approval process. Treat an AEO remediation page as a regulated communication from the first draft.
- Make the caveat extractable. Put the limitation inside the same passage as the claim, in the same paragraph, so it travels when the passage is quoted.
- Name and date your reviewer. Credential, affiliation and review date, in text rather than in an image.
- Re-check after every guidance change. Freshness is both a compliance duty and a citation signal.
- Measure three times before believing anything. Run-to-run variation in these engines is large enough that single observations mislead.