Role
For CISOs
Your teams already use AI. The problem is not stopping them but making it visible and recorded.
What is at stake here.
Shadow usage cannot be measured
Traffic through one gateway is countable: how many requests, which rule, what cost.
Attack attempts are invisible
Jailbreak attempts are logged with category, signals and score; the user gets one generic message.
Audit day needs evidence
Pick a date range and a PDF/CSV report is produced; it contains no raw personal data.
Why it is not optional
You cannot defend traffic you cannot see.
Where a legal duty is the reason, the article is named. No penalty figures and no circular numbers — those change, and a marketing page is the wrong place to be wrong about them.
A ban is not a policy
Banning use does not stop use, it only hides it. Traffic you cannot see is traffic you can neither measure nor defend.
No evidence, no control
If you cannot show a control ran, then in an audit that control does not exist. This is not a statute; it is how audits work.
Accountability does not transfer
The model's own safety training is the provider's decision. Your organisation's policy has to be enforced in a layer of its own.
Use cases
What actually happens in the day's work.
These are mechanisms, not case studies. Each one is a concrete thing somebody does, and what the chain does about it.
Taking stock of shadow AI
Situation
Nobody knows who is using which model, with what data.
What happens
Once traffic flows through one gateway it becomes countable: how many requests, which rule, which department.
Responding to a suspected leak
Situation
There is a suspicion that customer data got out. You need to see, after the fact, which prompts went where.
What happens
Every request is recorded as an event and flows to the SIEM; the place to query is the audit log, not a chat transcript.
Bringing a new model into use
Situation
A team wants to try a different provider; a fresh security review for every trial is not workable.
What happens
The security layer sits in front of the model. Changing model changes one setting, not the policy.
The answer
Which part of the product responds.
Configuration
Recommended starting posture.
These are starting recommendations; the final policy is written with you during setup.
- If the policy cannot be read
- stop
- Deployment
- Per your corporate policy: SaaS, VPC or on-premise
The rules get written together
The rules for this sector are written with you during onboarding: blocked phrases, the competitor list and the entity rules are set against your own processes. Instead of adapting someone else's template, you start with a policy that is genuinely yours — and it goes live only after being tried in the simulation that runs without saving.
Other roles
Let's talk through your own scenario.
In a 30-minute technical session we run your prompts and your policy through it live.