1. ドメイン固有のチャットボットの課題
汎用チャットボットだけでは業界には十分ではありません 厳格なコンプライアンス要件 — ヘルスケア (HIPAA)、財務 (PCI-DSS、SOX)、法務 (弁護士と依頼者の特権)。各ドメインには、特殊なガードレール、知識、および応答パターンが必要です。
| ドメイン | コンプライアンス | 主要な課題 | リスクレベル |
|---|---|---|---|
| ヘルスケア | HIPAA、HL7 FHIR | PHI 保護、医療アドバイス責任 | クリティカル |
| 金融 | PCI-DSS、SOX、MiFID II | 財務上のアドバイスの免責事項、取引の安全性 | クリティカル |
| 法的 | 弁護士・依頼者の特権 | 法律を実践していない、文書の機密保持 | 高 |
| 教育 | フェルパ、コッパ | 学生データ、年齢に応じたコンテンツ | 高 |
| 電子商取引 | 消費者保護法 | 価格設定の正確性、返金ポリシーの遵守 | 中 |
2. ヘルスケア チャットボット — HIPAA 準拠
class HealthcareChatbotConfig {
static readonly guardrails: DomainGuardrails = {
// PHI (Protected Health Information) detection & masking
piiPatterns: [
{ type: 'medical_record_number', regex: /MRN[\s-]?\d{6,10}/gi },
{ type: 'insurance_id', regex: /INS[\s-]?\d{9,12}/gi },
{ type: 'diagnosis_code', regex: /[A-Z]\d{2}\.\d{1,4}/g }, // ICD-10
],
// Medical advice disclaimer
mandatoryDisclaimers: [
'Thông tin này chỉ mang tính chất tham khảo, không thay thế tư vấn y tế chuyên nghiệp.',
'Vui lòng liên hệ bác sĩ để được tư vấn chi tiết.',
],
// Topics requiring immediate escalation
emergencyKeywords: [
'đau ngực', 'khó thở', 'chảy máu nhiều', 'bất tỉnh',
'chest pain', 'difficulty breathing', 'unconscious',
],
// Forbidden responses
forbiddenActions: [
'Không được chẩn đoán bệnh',
'Không được kê đơn thuốc',
'Không được đưa ra lời khuyên y tế cụ thể',
'Không được xác nhận/phủ nhận tình trạng bệnh',
],
};
}
class HealthcareGuardrail implements GuardrailRule {
id = 'healthcare-compliance';
type = 'output' as const;
severity = 'block' as const;
async check(content: string, context: GuardrailContext): Promise<GuardrailResult> {
// Check for medical diagnosis patterns
const diagnosisPatterns = [
/bạn (có thể )?bị\s+(bệnh|hội chứng)/i,
/chẩn đoán.*là/i,
/bạn nên (uống|dùng)\s+thuốc/i,
/you (may )?have\s+(disease|condition|syndrome)/i,
];
for (const pattern of diagnosisPatterns) {
if (pattern.test(content)) {
return {
passed: false,
rule: this.id,
severity: 'block',
reason: 'Response contains medical diagnosis — not permitted',
modifiedContent: content + '\n\n⚕️ ' +
HealthcareChatbotConfig.guardrails.mandatoryDisclaimers[0],
};
}
}
// Emergency detection → immediate escalation
const isEmergency = HealthcareChatbotConfig.guardrails.emergencyKeywords
.some(kw => content.toLowerCase().includes(kw.toLowerCase()));
if (isEmergency) {
return {
passed: false,
rule: this.id,
severity: 'block',
reason: 'Emergency situation detected — escalate immediately',
modifiedContent: '🚨 Đây có thể là tình huống khẩn cấp. Vui lòng gọi ngay 115 hoặc đến cơ sở y tế gần nhất.',
};
}
return { passed: true, rule: this.id, severity: this.severity };
}
}
3. 財務チャットボット — PCI-DSS およびアドバイザリーコンプライアンス
class FinanceChatbotConfig {
static readonly guardrails: DomainGuardrails = {
piiPatterns: [
{ type: 'card_number', regex: /\b\d{4}[\s-]?\d{4}[\s-]?\d{4}[\s-]?\d{4}\b/g },
{ type: 'cvv', regex: /\bCVV[\s:]*\d{3,4}\b/gi },
{ type: 'account_number', regex: /\b\d{10,16}\b/g },
],
mandatoryDisclaimers: [
'Thông tin này không phải là tư vấn đầu tư. Đầu tư luôn có rủi ro.',
'Vui lòng tham khảo ý kiến chuyên gia tài chính trước khi quyết định.',
],
forbiddenActions: [
'Không được khuyên mua/bán cổ phiếu cụ thể',
'Không được dự đoán giá crypto/chứng khoán',
'Không được cam kết lợi nhuận',
'Không được yêu cầu thông tin thẻ/tài khoản qua chat',
],
};
}
class FinanceGuardrail implements GuardrailRule {
id = 'finance-compliance';
type = 'output' as const;
severity = 'block' as const;
async check(content: string, context: GuardrailContext): Promise<GuardrailResult> {
// Check for investment advice
const investmentAdvice = [
/nên (mua|bán)\s+(cổ phiếu|coin|crypto)/i,
/lợi nhuận.*%.*chắc chắn/i,
/cam kết.*lợi nhuận/i,
/buy|sell|invest in.*stock|crypto/i,
];
for (const pattern of investmentAdvice) {
if (pattern.test(content)) {
return {
passed: false,
rule: this.id,
severity: 'block',
reason: 'Response contains financial advice — adding disclaimer',
modifiedContent: content + '\n\n⚠️ ' +
FinanceChatbotConfig.guardrails.mandatoryDisclaimers[0],
};
}
}
// Never store card numbers in conversation
const hasCardData = FinanceChatbotConfig.guardrails.piiPatterns
.some(p => p.regex.test(content));
if (hasCardData) {
return {
passed: false,
rule: this.id,
severity: 'block',
reason: 'PCI-DSS: Card data detected in response',
modifiedContent: '[Thông tin thẻ đã được ẩn vì lý do bảo mật]',
};
}
return { passed: true, rule: this.id, severity: this.severity };
}
}
4. ドメイン知識の強化
class DomainKnowledgeManager {
// Terminology mapping for RAG improvement
private terminologyMaps: Record<string, Map<string, string[]>> = {
healthcare: new Map([
['đau đầu', ['headache', 'cephalgia', 'migraine', 'đau nửa đầu']],
['tiểu đường', ['diabetes', 'đái tháo đường', 'ĐTĐ', 'type 1', 'type 2']],
['huyết áp cao', ['hypertension', 'tăng huyết áp', 'high blood pressure']],
]),
finance: new Map([
['lãi suất', ['interest rate', 'APR', 'APY', 'LS']],
['cổ phiếu', ['stock', 'equity', 'shares', 'CP']],
['trái phiếu', ['bond', 'fixed income', 'TP']],
]),
};
// Expand query with domain synonyms for better RAG
expandQuery(query: string, domain: string): string {
const termMap = this.terminologyMaps[domain];
if (!termMap) return query;
let expanded = query;
for (const [term, synonyms] of termMap) {
if (query.toLowerCase().includes(term.toLowerCase())) {
expanded += ` (${synonyms.join(', ')})`;
}
}
return expanded;
}
// Domain-specific response templates
async formatDomainResponse(
response: string,
domain: string,
config: DomainGuardrails,
): Promise<string> {
let formatted = response;
// Add mandatory disclaimers
if (config.mandatoryDisclaimers.length > 0) {
const needsDisclaimer = await this.checkNeedsDisclaimer(response, domain);
if (needsDisclaimer) {
formatted += '\n\n---\n' + config.mandatoryDisclaimers[0];
}
}
return formatted;
}
}
5. コンプライアンス監査証跡
class ComplianceAuditService {
async logInteraction(event: ComplianceEvent): Promise<void> {
// Immutable audit log (append-only)
await this.db.complianceAudit.create({
tenantId: event.tenantId,
userId: event.userId,
conversationId: event.conversationId,
eventType: event.type,
domain: event.domain,
details: event.details,
guardrailsTriggered: event.guardrailsTriggered,
complianceStatus: event.status,
timestamp: new Date(),
// Hash for tamper detection
hash: this.computeHash(event),
});
}
async generateComplianceReport(
tenantId: string,
period: { from: Date; to: Date },
domain: string,
): Promise<ComplianceReport> {
const events = await this.db.complianceAudit.findMany({
where: {
tenantId,
domain,
timestamp: { gte: period.from, lte: period.to },
},
});
return {
period,
domain,
totalInteractions: events.length,
guardrailTriggers: events.filter(e => e.guardrailsTriggered.length > 0).length,
complianceViolations: events.filter(e => e.complianceStatus === 'violation').length,
escalations: events.filter(e => e.eventType === 'escalation').length,
topTriggers: this.aggregateTopTriggers(events),
recommendations: this.generateRecommendations(events),
};
}
}
レッスン 20 のまとめ
- ヘルスケア: HIPAA 準拠、PHI マスキング、医学的診断なし、緊急エスカレーション
- 金融: PCI-DSS (チャットにカード データなし)、投資アドバイスなし、必須の免責事項
- 法的: 弁護士と依頼者の特権、弁護士活動ではない、文書の機密保持
- ドメインの知識: より優れた RAG、ドメイン固有の応答テンプレートのための用語マッピング
- コンプライアンス監査: 不変の監査証跡、改ざん検出、定期的なコンプライアンスレポート
次の記事: マルチモーダル AI — 画像理解、ドキュメント OCR、チャート/グラフ分析、視覚的な質問応答。