Finding 60 unsanctioned AI tools before the auditors did
A 400-person firm had an AI policy, a procurement process, and — as we found — sixty AI tools in use that neither knew about. Including three sending client data offshore.
The challenge
The firm's leadership believed AI use was limited to a pilot program they had approved. Their upcoming audit under new regulatory expectations made them want proof rather than belief.
The real question was not "are we compliant with our AI policy" — it was "do we actually know where AI touches client data".
The approach
Discovery beyond the approved list
Interviews across departments plus network and SaaS telemetry surfaced every AI touchpoint: browser AI tools, personal accounts, browser extensions, and API keys embedded in team scripts.
Risk scored, not panic ranked
Each finding was scored by data sensitivity, exposure, and blast radius. Three items involving client data going to unapproved offshore services were classed stop-now; the rest mapped to a governance ladder.
A policy people can follow
We rewrote the AI usage policy around what teams actually need to do — approved tools for approved data classes, with a fast lane for requesting new ones. Bans that ignore workflow get ignored; usable policy gets used.
The outcome
The three critical exposures were closed within a week of the findings workshop. The remaining findings were remediated or scheduled across two quarters.
The firm entered its audit with a complete AI inventory, a risk register, and evidence of remediation — and kept the productivity gains from the tools teams had adopted, now inside the guardrails.
“We thought we were asking for a compliance document. What we got was a mirror — and we are much safer for having looked into it.”
Want results like these?
It starts with a 30-minute call about your problem.