We want AI. Legal says one byte of customer data off-prem and it's a newspaper story.
Enterprise AI platform cleared through OSFI B-13 in six weeks. Zero data egress.
The bank's internal team had built a RAG prototype on OpenAI's API six months earlier. It worked technically, but compliance had stopped the production rollout cold — the data was leaving the building, and no amount of TOS language was going to clear that with OSFI.
We rebuilt it on Bedrock with a multi-layer PII control pipeline, Claude as the reasoning model, OpenSearch for retrieval, and every prompt logged to an S3 bucket their auditor had read-only access to. Six weeks later it was serving 1,300 queries a day — and costing 61% less than the GPT-4 version would have.