Over the past decade, our team has delivered enterprise search and knowledge discovery across some of Australia’s most complex information environments. Federal government agencies. Major financial institutions. National regulators. Organisations where the cost of surfacing the wrong information, or failing to surface the right information, is measured in real consequences, not user experience scores.
That work has shaped how we think about search in ways that are difficult to absorb from a product demo or a vendor comparison. The things that matter most in these environments are not the things that feature most prominently in sales conversations.
The problem is rarely the search engine
In practice, organisations that struggle with enterprise search rarely have a problem with the retrieval technology itself. The problem is almost always upstream: fragmented content, unclear ownership, access rules that were designed for one system and applied inconsistently across many, and a governance model that nobody has reviewed since the original deployment.
When a search implementation fails in a regulated environment, the instinct is often to question the platform. In most cases, the platform is the least interesting part of the problem. What failed was the information architecture underneath it.
This matters because it changes where you start. In every successful deployment we have been part of, the first serious conversation was not about indexing or relevance tuning. It was about what information existed, where it lived, who was responsible for it, and what access model would govern how it appeared in results.
Access controls are not a constraint. They are the design.
In organisations outside regulated sectors, permissions are often treated as a post-implementation concern. You build the search experience first, and then you figure out what people should and should not be able to see. In government and financial services, this sequence is reversed by necessity.
What we found over time is that this constraint produces better systems. When access controls are treated as the design rather than an afterthought, the result is search that people actually trust. Staff in regulated environments are acutely aware of what they should and should not have access to. A search system that surfaces results indiscriminately — or worse, that fails silently when it cannot show something — erodes that trust quickly.
One of the more interesting problems we have worked on repeatedly is what happens at the boundary between accessible and inaccessible content. In most search systems, if you do not have permission to access a document, it simply does not appear in results. You cannot know it exists. For most use cases this is fine. But in large organisations with complex departmental structures, it creates a different problem: people are searching for things that exist, not finding them, and assuming they do not exist.
The solution we developed allows users to see that relevant material exists across permission boundaries without exposing the content itself. A search across a large organisation can return a result that says, in effect, there are relevant documents in this area that you do not currently have access to. The user can then seek access through the appropriate channels. This sounds simple. The implementation, particularly in environments with complex identity systems and layered access models, is not.
The objectors are part of the project
Anyone who has delivered a large enterprise search project in a regulated environment will recognise this pattern. You have strong sponsorship from the business. You have a clear use case and a willing technology partner. And then the IT security team, the data governance team, or the compliance function raises a concern, and the project slows.
This is not dysfunction. It is how these organisations are supposed to work. The people raising concerns are doing their jobs. The mistake is treating their involvement as an obstacle to be overcome rather than a process to be managed.
In our experience, the projects that fail are the ones where the sponsoring team tries to move around these stakeholders. The projects that succeed are the ones where those conversations happen early, are taken seriously, and result in a design that everyone with a stake can support. That process takes time and costs money. It is also the only reliable path to a system that stays in production rather than being quietly decommissioned eighteen months later.
This is also why we approach enterprise search engagements through an audit and discovery process rather than a direct implementation pitch. The value of understanding the environment first is not just technical. It is political. It gives every stakeholder a reason to be involved before the decisions are made, rather than a reason to raise concerns after them.
What this means for AI
The reason regulated environment experience matters now is that the problems organisations are encountering with AI initiatives are structurally identical to the problems we have been managing in enterprise search for years.
An AI system that cannot reliably access governed enterprise knowledge will produce unreliable outputs. An AI system deployed without a clear access model will create security and compliance concerns that are legitimate, not paranoid. An AI initiative that does not involve the technology, data governance, and compliance functions from the beginning will encounter the same objectors at a later and more expensive stage.
The organisations that are making AI work in production in 2026 are, in most cases, the ones that treated their knowledge infrastructure as a prerequisite rather than an afterthought. That is not a coincidence.

