A professional services firm with UK and international offices, carrying client confidentiality and professional-liability obligations, commissioned an independent read on where it actually stood. We found four distinct classes of AI activity, each needing a different kind of governance.
This was not an organisation resisting AI. It was the opposite. Practitioners across several offices had independently found genuine, material value — work that had taken days being produced in minutes, and tools built in-house that were good enough to put in front of clients.
What had not kept pace was the structure around it. There was no register of what was in use, no gate before a new tool entered the business, no named owner for any of it, and no consolidated view of what client data was travelling where. An AI strategy paper had been written at director level the previous year and had never been taken forward — less because of its content than because no standing body existed whose job it was to receive that thinking and convert it into action.
The firm did not lack AI ideas. It lacked structure.
There was a commercial edge to it as well. Business development leadership in one region reported losing bids in a market that had historically been a strength, attributing the losses to competitors responding faster with AI assistance. The exposure ran in both directions: ungoverned use carried risk, and failing to organise carried competitive cost.
Treating "AI" as one thing is the most common mistake we see. In practice the activity separates into classes that need genuinely different controls — an intellectual property question is not a data protection question, and neither is answered by a single policy document. Mapping the classes is what makes the governance tractable.
Tools developed under a formal arrangement with an external research partner, automating specialist technical analysis that would otherwise take a consultant several days per instance. Phase one complete and in testing.
A tool built solo by a senior practitioner that compresses roughly two days of skilled manual work into a single parameter adjustment, producing a client-deliverable output. Intellectual property position clean, resting with the firm by default of employment.
A third-party platform giving users one workspace across several upstream AI providers, with accounts held individually by practitioners rather than by the firm — and now being used on real client presentation work in more than one office.
The main CRM and marketing platform, with AI features enabled at entry tier and higher-tier agents available behind a paywall. The data flowing through it is personal data, which changes the governance shape entirely.
The two Red classes shared a root cause: tools procured individually by capable people acting in good faith, on personal terms, without anyone in the firm holding a view of the aggregate position. Neither was a failure of judgement. Both were a failure of structure.
Individually, several people held pieces of the diagnosis. What was missing was anyone holding all of it at once.
Where practitioners used personal-tier subscriptions on material covered by client non-disclosure agreements, confidentiality reduced to the vendor's general terms and the individual's discretion — rather than the controller and processor framework an organisational subscription would have provided.
Both in-house tools were genuinely valuable and both sat on individual machines, with no firm-controlled repository and no documented build steps. If either developer had become unavailable, the firm had no way to maintain or extend an asset it depended on and partly owned.
Two of the firm's most active AI users, in the same office, performing the same task, had built entirely different toolchains and had never met. Neither stack had been compared on quality, cost or data handling. The firm was paying twice and had no information on which to choose.
Centralised, request-and-approve licensing was already running successfully for the firm's design software estate. Extending that same pattern to AI tooling was an organisational decision, not a technical build — which made it one of the fastest available wins.
Assessing AI readiness without assessing the security baseline underneath it produces recommendations that cannot be implemented. We ran them together.
How staff were actually using AI, sanctioned and unsanctioned. What tools were in use, what data went into them, and the level of literacy across the business.
A governance and risk assessment rather than a penetration test. Ownership, accountability, and whether the baseline could carry what was being built on it.
What existed, what was genuinely end-of-life against what could be extended, and the infrastructure preconditions that had to be met first.
The most material gaps against stated ambition, the foundational actions that had to come first, and the sequence in which to take them.
The report was structured so the board could act on it directly rather than commission further work. Every recommendation carried an internal owner — because governance that depends on a consultant to operate is not governance.
A small standing group with a chair, a reporting line and decision rights — the mechanism that had been missing when the previous strategy paper stalled.
A vetting checklist applied before practice-wide release, with a lightweight impact assessment attached, so new tools enter a controlled environment.
Extend the existing centralised licensing pattern to AI tooling, bringing client work back inside organisational terms.
Firm-controlled source-control mirrors, documented build steps, dependencies pinned and scanned, deployment surface reviewed.
Controller and processor roles established, Article 28 agreements put in place, data-residency elections made deliberately rather than by vendor default.
The specific foundational items that had to be in place before the rest of the programme could be considered defensible.
A short list of near-term opportunities, each scoped to internal data to avoid governance blockers, each pilotable inside a single project cycle, each with an owner.
The board took the recommendations forward. What made that possible was not the analysis but the shape of it — decisions rather than observations, owners rather than recommendations, and a 90-day horizon short enough that the first actions were complete before the momentum went.
We see this shape repeatedly: capable people finding real value before the organisation can explain the risks, the owners or the limits. Individuals across functions each hold a piece of the diagnosis. What is missing is ownership, and a defensible footing under activity that is already in flight.
The work is rarely about slowing adoption down. In this engagement the same assessment that identified the red-rated exposures also identified the acceleration opportunities — and the fastest of those turned out to be extending a licensing mechanism the firm was already running successfully for other software. Governance and advantage came from the same piece of work.
This case study is published in anonymised form under engagement confidentiality. Sector, location, tooling and individual details have been generalised or omitted. Cyberbase can discuss the engagement in more detail under NDA, and references are available at C-suite level.
The practice this engagement came from. AI Defensibility Reviews, readiness discovery, AI risk frameworks, secure operating model design, policy suites and fractional Information Security Officer.
Explore the practiceCyber transformation, secure architecture and privileged access delivered for FTSE 100 aviation and critical national infrastructure, plus national-scale public sector data security work.
See all resultsAdvantage, risk, control and ownership — applied to the AI activity already visible in your organisation. In a single hour with your leadership team we map your immediate exposure and show what a full review would uncover.
Arrange the briefingNo preparation required. No obligation to proceed.