AI Automation
Agency, Chicago.
Chicago anchors a major cluster of financial services, manufacturing, and legal businesses, home to the CME Group and one of the US's densest concentrations of mid-market law firms. Illinois's Biometric Information Privacy Act (BIPA) is among the strictest data laws in the world.
Illinois is the most litigated AI jurisdiction in the United States, because BIPA gives individuals a private right of action.
Most US privacy statutes are enforced by a regulator. Illinois' Biometric Information Privacy Act is enforced by individuals, with statutory damages reported in the range of 1,000 to 5,000 dollars per violation. Because violations are counted per person and often per scan, the exposure from a biometric feature shipped without written consent is not theoretical.
For automation that means voiceprints, face geometry and any other biometric identifier are a design decision with litigation consequences. A call-handling automation that fingerprints a caller's voice for authentication has entered BIPA territory. One that transcribes the call has not. We draw that line at the specification stage in Illinois rather than at review.
Since 1 January 2026 there is a second exposure. Illinois HB 3773 amended the Illinois Human Rights Act so that AI-driven employment discrimination is a civil rights violation. Any automation touching recruitment, promotion or performance assessment in Illinois needs documented human review and an auditable record of the factors used.
Who you answer to here
- Illinois Department of Human Rights
- Enforces the Human Rights Act as amended by HB 3773
- BIPA private right of action
- Enforced by individuals, not only by a regulator
- FINRA and SEC
- For the Chicago derivatives and trading cluster
Sources
- 01Illinois Department of Human Rights, State of Illinois
- 02FINRA Rule 3110, Supervision, Financial Industry Regulatory Authority
Six industries.
One engineering team.
Healthcare
Clinical admin, patient flow, and compliance automation.
HIPAA Privacy and Security Rules, 21st Century Cures Act interoperability mandates, and ONC information-blocking rules govern all healthcare AI deployments.
- Appointment scheduling and patient reminders
- Clinical documentation and records processing
- Referral routing and prior authorisation
Fintech
KYC, AML, reconciliation, and regulatory reporting.
SEC Rule 17a-4, FINRA Rules 3110 and 3120, BSA/AML requirements, and SOX Section 302/404 for publicly listed companies govern all financial AI automation.
- KYC/AML onboarding and ongoing monitoring
- Transaction reconciliation and exception handling
- Regulatory reporting and audit trail generation
Legal
Document review, client intake, and billing automation.
ABA Model Rules 1.1 (competence) and 1.6 (confidentiality), FRCP e-discovery requirements, and state bar ethics opinions on AI use in legal practice.
- Contract review and clause extraction
- Client intake and matter management automation
- Billing, time capture, and accounts receivable
Manufacturing
Predictive maintenance, quality control, and supply chain.
OSHA 29 CFR regulations, FDA 21 CFR Part 11 for electronic records and signatures, ISO 9001, and EPA environmental reporting requirements.
- Predictive maintenance and asset health monitoring
- Quality control inspection and defect classification
- Supply chain and inventory optimisation
Education
Admissions, student support, and administrative automation.
FERPA (Family Educational Rights and Privacy Act), COPPA for under-13 users, Section 508 accessibility requirements, and applicable state education codes.
- Admissions processing and applicant scoring
- Student support routing and early intervention alerts
- Administrative reporting and compliance documentation
E-commerce
Inventory, pricing, fulfilment, and customer service automation.
CCPA/CPRA (California), FTC Act Section 5, PCI DSS for payment data, and COPPA for platforms with under-13 users.
- Inventory forecasting and replenishment automation
- Dynamic pricing and margin optimisation
- Customer service triage and returns processing
Brief, engineer, ship.
Brief
Tell us what you are trying to stop doing manually. One hour, no deck required.
Week 1Engineer
We map the process, confirm the compliance requirements, and build it to a fixed spec.
Weeks 2–8Ship
You go live with a compliant, auditable automation. We stay alongside for support and iteration.
Week 8+