Case Study: When Usage Outruns Control — Closing the Governance Gap Without Braking
A financial-services team had AI in half its client deliverables and controls on paper only. Ninety days later, usage was higher — and every material workflow was covered.

The most dangerous readiness profile we see is not low adoption. It is high adoption over low control1 — real client work flowing through AI faster than anyone is watching it.1This case is a composite drawn from several Fellow engagements, anonymised and simplified. The numbers are representative of what we measure in this pattern, not one client's audited results.
The situation
A financial-services organisation of roughly 800 people came to us after an internal audit question nobody could answer: which client deliverables involve AI, and under what safeguards? The honest answer was a shrug. Analysts were drafting reports, summarising filings, and answering client queries with AI daily. There was a policy document. Almost nobody had read it, and nothing verified the output before it shipped.
A readiness snapshot made the shape visible: Applied use scored high while Judgment & risk scored near the bottom◦. Leadership's instinct was to restrict access until governance caught up.By the numbers71% vs 21%Applied use versus Judgment & risk — the signature gap of the usage-outruns-controls pattern
What made the gap wider than it looked was that leadership's mental model of it was wrong in a specific way. Asked to guess, the executive team named research and marketing as the places AI was being used, and estimated perhaps thirty regular users. The inventory found AI in every client-facing function, including two that had assured us they had none — and it found that the heaviest use was not in idea generation at all, but in the last mile: reformatting, summarising and tightening documents that were about to leave the building.
The two examples that reframed the conversation for the board were both mundane. A draft set of client financials had been pasted into a consumer chatbot to convert a table; the analyst had done it at speed, on a personal account, and thought nothing of it. A confidential mandate summary had been produced on a phone the night before a meeting, because the sanctioned tool required a VPN session that took four minutes to establish. Neither was reckless. Both were invisible, and both had been repeated many times.
This is not a local problem
We would be more cautious calling this a pattern if it were not so well documented outside our own work. Cyberhaven's 2026 AI Adoption and Risk Report, which monitors actual enterprise data flows rather than asking people what they do, found that 39.7% of data movements into AI tools involve sensitive data◦, and that 32.3% of workplace ChatGPT use runs through personal accounts1. That second number is the governance gap stated as a measurement: a third of the usage is, by construction, outside anything the organisation can log, review or retain.By the numbers39.7%Cyberhaven's 2026 report: the share of data going into AI tools that is sensitiveSourceCyberhaven Labs, 2026 AI Adoption & Risk Report
The policy side of the ledger is just as consistent. ISACA's 2025 AI Pulse Poll found that 83% of respondents believe employees at their organisation are using AI, while only 31% said their organisation has a formal, comprehensive AI policy2◦. KPMG and the University of Melbourne, surveying more than 48,000 people across 47 countries in 2025, found that 48% had uploaded sensitive company information into public AI tools and that only two in five said their employer had a generative-AI policy at all3.SourceISACA, 2025 AI Pulse PollBy the numbers83% vs 31%ISACA's 2025 poll: belief that staff use AI, versus organisations with a formal AI policySourceKPMG & University of Melbourne, "Trust, attitudes and use of AI", 2025
Nor is this a story about employees going around IT out of mischief. Microsoft's 2024 Work Trend Index found that 78% of AI users bring their own AI tools to work4◦. People bring tools because the tool is faster than the alternative they have been given. That is a supply problem before it is a discipline problem.SourceMicrosoft, 2024 Work Trend IndexDefinitionBYOAI Bring your own AI — using a personal AI account for work because the sanctioned option is slower, harder to reach, or does not exist
The consequences are documented too. In 2023, Samsung engineers pasted internal source code into ChatGPT — three separate leaks within roughly twenty days. Samsung's response in May 2023 was to ban generative-AI chatbots for employees, citing the fact that data submitted to external servers could not be retrieved or deleted5. It is worth noting what that sequence cost: the exposure had already happened before anyone knew to look, and the remedy arrived as a blanket prohibition rather than as a control.SourceSamsung's gen-AI ban after a source-code leak, 2023 (via Forbes)
Why restriction was the wrong move
Restriction does not reduce usage; it relocates it. The workflows delivering real value would not have stopped — they would have moved to personal accounts, out of sight, with the same data and none of the oversight. The exposure would have grown while the dashboard said it had shrunk◦.DefinitionShadow migration The predictable move of useful-but-banned workflows into personal tools, where the same risk continues invisibly
Two of the firm's partners argued hard for a hard block, and their argument was not unreasonable: regulated industries have done exactly that, and JPMorgan Chase restricted staff use of ChatGPT as early as February 2023 over the regulatory risk of sharing financial data6. What we put to them was a narrower question — not whether a block was defensible, but what it would actually do to the eleven workflows the inventory had just surfaced. For nine of them there was no sanctioned substitute that was faster than the workaround. A block would have converted nine visible risks into nine invisible ones and bought the firm an audit answer that was true only on paper.SourceJPMorgan Chase restricting staff ChatGPT use, 2023 (via Forbes)
That reframing took one ninety-minute session and the inventory to win. Without the inventory it would have been an argument about principles, and it would have been lost.
The operating principle we set instead: make the safe path the fast path. Governance had to arrive as an upgrade, not a punishment.
What we did, in order
- Inventoried real usage first. Two weeks of structured conversations — not a survey — mapping which deliverables already touched AI, through which tools, carrying what data, owned by whom. Forty-one conversations, thirty to forty-five minutes each, every one opened with an explicit amnesty: nothing said here becomes a disciplinary matter.
- Wrote the one-page data rule. One page, plain language, three categories: never leaves approved tools, fine with care, fine freely. Taught in thirty minutes with examples from the team's own deliverables, not hypotheticals. The hardest editorial decision was cutting the edge cases — every deleted exception made the page more usable and the legal reviewer more uncomfortable.
- Built verification into the two riskiest workflows. A named reviewer and a short checklist at the point where output met the client — inside the workflow, not in a separate compliance step. We deliberately chose two, not ten: a control that covers everything badly is worth less than one that covers the worst two properly◦.RelatedThe same gap, seen from the usage side
- Upgraded the approved tooling until it beat the workarounds. The enterprise deployment got the same models and fewer logins than the personal accounts people had been quietly using. Compliance stopped costing speed.
The whole thing cost about six person-weeks of Fellow time across the quarter, plus roughly forty hours of the client's own — mostly the interviews, four teaching sessions and a standing thirty-minute weekly checkpoint we kept short on purpose. No new headcount, and no new tooling budget beyond licences the firm was already partly paying for through expense claims.
It nearly went wrong once, and early. A middle manager received the interview invitation, read it as an audit, and forwarded the question list to his team with the words "answer carefully". Three of those interviews produced visibly rehearsed answers, and one analyst told us afterwards that she had left out the tool she used most. We restated the amnesty in writing, from the COO rather than from us, and re-ran those conversations two weeks later. The re-run surfaced the single riskiest workflow in the inventory. The lesson we took: an inventory run with the wrong sponsor produces a clean, useless map◦.Figure
Inventory conversations worked best with the real deliverable open on screen, not from a question list
What changed in ninety days
Usage went up, not down — and moved into approved tools where it could be seen. Verification coverage on material workflows went from zero to complete◦. The audit question that started the engagement became answerable in one meeting. And the one-page rule proved the point about brevity: at the follow-up assessment, most respondents could quote it from memory — which was never true of its forty-page predecessor.By the numbers0 → 100%material client workflows with a named verification step, within one quarter
The second-order effects were the ones leadership had not predicted. Because the sanctioned tool was now genuinely faster, three teams brought forward workflows they had not previously mentioned to anyone, including a client-onboarding summarisation step that turned out to carry more sensitive data than either of the two workflows we had prioritised. Visibility, once it starts, is self-reinforcing: people volunteer what they are doing when volunteering stops being risky.
The room where the rule was taught mattered as much as the rule◦.Figure
Guidance that is taught, with the team's own examples, is guidance that survives contact with deadlines
The part that is harder than it sounds
Two things about this engagement are less durable than the numbers suggest, and it would be dishonest to leave them out.
The first is that verification coverage is a headcount fact dressed up as a process fact. "A named reviewer" works until the named reviewer is on leave, and in the quarter after the engagement, coverage on one of the two workflows lapsed for eleven days because no deputy had been designated. The control was real; the redundancy was not. If we ran it again we would name two people per workflow from the start and treat a single-named control as incomplete.
The second is that an inventory is a photograph, not a system. Within six weeks, two AI features had appeared inside tools the firm already licensed — a summarisation panel in one, a drafting assistant in another — neither of which existed when we mapped the estate, and neither of which anyone thought to classify, because using them did not feel like "using AI". The map does not stay accurate on its own. A quarterly ten-minute re-ask, attached to a meeting that already happens, is the cheapest thing we know that keeps it honest, and it is also the first thing organisations quietly drop.
What to steal
- This week: write the one-page data rule and read it aloud to one team. If it takes more than five minutes to explain, cut it again.
- This month: inventory AI in your real deliverables — tools, accounts, data, owners. Conversations beat forms, and the amnesty has to come from someone senior enough to grant it.
- This month: add a named verification step to the two workflows where a wrong output costs the most — and name a deputy for each while you are there.
- This quarter: make the approved path faster than the workaround, then re-measure. If usage did not move into the light, the approved path is still losing.
- Every quarter after that: re-ask the inventory question in ten minutes at a meeting that already exists. New AI features keep arriving inside tools you already own.
If your own readiness report flagged this pattern, the gap is already compounding — the sequence above is the repair. We are happy to help you run it◦.RelatedMeasure before you fix: running a first assessment
Sources
- Cyberhaven Labs, 2026 AI Adoption & Risk Report
- ISACA, 2025 AI Pulse Poll
- KPMG & University of Melbourne, "Trust, attitudes and use of AI", 2025
- Microsoft, 2024 Work Trend Index
- Samsung's gen-AI ban after a source-code leak, 2023 (via Forbes)
- JPMorgan Chase restricting staff ChatGPT use, 2023 (via Forbes)
Keep reading

Case Study: Turning Individual AI Wins Into Shared Capability
A capable, well-trained team where nothing compounded: every AI win stayed private. Five harvested workflows and one co-built assistant later, the median user caught up with the best.

Case Study: Putting a Defensible Number on AI Adoption
An AI programme everyone liked nearly lost its budget because nobody could prove it worked. Two baselined workflows later, it survived the cut — and earned an expansion.