Cybersecurity Analytics

How a Company Took Control of Generative AI Across the Business

☰
Overview

At a Glance

A European company had seen a rapid increase in the use of generative AI across its business. Employees were using publicly available tools to draft documents, summarise information, prepare presentations, research topics and support everyday administrative work.

Some teams were also exploring more advanced uses, such as internal assistants, automated document processing and AI-supported customer services.

The company could see the potential value. Employees could complete certain tasks more quickly, find information more easily and spend less time on repetitive work. However, the use of generative AI had grown faster than the company's ability to manage it.

This raised several practical questions:

  • ?Which generative AI services were employees using?
  • ?What information was being entered into these services?
  • ?Could confidential or personal data be exposed?
  • ?Which AI use cases presented the greatest risk?
  • ?Who was responsible for approving new AI solutions?
  • ?How should suppliers and external AI services be assessed?
  • ?Were existing cybersecurity and data protection controls sufficient?
  • ?How could the company support useful AI projects without blocking innovation?

We helped the client understand how generative AI was being used, identify the areas that needed attention and introduce a practical governance process.

The work connected AI use cases with business processes, data, applications, suppliers, risks, controls and responsible owners. This gave the company a clearer basis for deciding which AI initiatives could proceed, which required additional safeguards and which should be stopped.

The Main Result
The company moved from largely uncontrolled use of generative AI to a clearer and more consistent way of managing it across the business.
Client Profile

About the Client

European Industrial Company
Confidential client · AI governance & cybersecurity engagement
Confidential
Industry
Industrial manufacturing and engineering
Company Size
Approximately 5,000 employees
Locations
Multiple production, engineering and administrative locations across Europe
IT Environment
Microsoft 365, cloud services, local infrastructure, business applications, remote access and external technology suppliers
AI Environment
Public generative AI services, approved enterprise tools, pilot AI applications and supplier-provided AI features
Relevant Requirements
Data protection, information security, contractual confidentiality, intellectual property, business continuity and internal governance requirements
Engagement context: The client is a European industrial company with operations across several countries. Its employees work in production, engineering, sales, procurement, administration and other supporting business functions. The organisation operates a mixed IT environment consisting of cloud-based services, locally managed infrastructure, business-critical applications and solutions provided by external technology suppliers. It also maintains an established information security management system.

The company's name, exact number of employees, locations and selected operational details have been withheld for confidentiality reasons.

The Problem

The Challenge

Generative AI had entered the business through several different routes.

Some employees had created accounts with publicly available services. Business teams were testing AI tools that could improve productivity. Existing software suppliers had started adding AI features to their products. The IT team was reviewing enterprise AI platforms, while individual departments were considering their own solutions.

There was no single view of this activity.

The company had security policies, data protection procedures, supplier assessments and an established ISMS. However, these processes had not yet been adapted to deal with the speed and variety of generative AI adoption.

Employees did not always know which tools were approved or what information they could enter. Managers were interested in the potential benefits but lacked a consistent way to assess proposed use cases. Security and data protection teams were often involved late, after a tool had already been tested or purchased.

The company did not want to introduce a broad ban. It wanted employees to use AI where it offered a genuine benefit, but it also needed clear limits and sensible controls.

The Core Issue

Generative AI was being adopted rapidly — without consistent oversight.

The challenge was not about stopping AI adoption but about bringing visibility, structure and accountability to a fast-moving and fragmented landscape.

01
No consistent approvalGenerative AI tools were being used without consistent approval.
02
No complete viewThe company did not have a complete view of active AI use cases.
03
Unclear data rulesEmployees were unsure which information could be entered into AI services.
04
Data exposure riskPersonal, confidential or commercially sensitive information could be exposed.
05
Duplicate effortsSimilar AI tools were being tested by different departments.
06
Embedded AI featuresNew AI features were appearing in existing business applications.
07
Late security reviewsSecurity and data protection reviews were not always completed early enough.
08
Unclear supplier rolesSupplier responsibilities were not always clear.
09
Missing business ownersBusiness owners were not consistently assigned to AI use cases.
10
Incomplete risk coverageExisting risk assessments did not fully cover AI-specific concerns.
11
Weak management visibilityManagement reporting did not provide a clear picture of AI adoption and risk.
12
Delayed useful projectsUseful AI projects could be delayed because there was no agreed approval process.

The client needed a way to support responsible AI adoption without creating another slow and complicated administrative process.

Objectives

What the Client Wanted to Achieve

The project had seven main goals:

1

Understand how generative AI was already being used.

2

Identify use cases involving sensitive information or important business processes.

3

Create practical rules that employees could understand.

4

Introduce a consistent assessment and approval process.

5

Assign clear responsibility for AI tools, data, risks and controls.

6

Connect AI governance with the existing ISMS, data protection and supplier-management processes.

7

Give management a clear view of AI opportunities, risks and required decisions.

Our Approach

What We Did

1

We started with how people were actually using AI

The first step was to understand the current situation.

We held discussions with representatives from IT, information security, data protection, legal, procurement, HR and selected business departments. We also reviewed existing technology inventories, supplier records, policies, risk registers and proposed AI projects.

The review covered:

  • ✓publicly available generative AI tools;
  • ✓enterprise AI services;
  • ✓AI features built into existing applications;
  • ✓department-led pilot projects;
  • ✓supplier-provided AI functions;
  • ✓planned AI assistants and automated workflows;
  • ✓the types of information used in each case;
  • ✓the business purpose of each use case;
  • ✓the people who used or managed the service;
  • ✓existing technical and organisational controls.

The aim was not to examine every individual prompt. It was to understand where AI was being used, why it was being used and what information or business activities were involved.

This gave the client an initial picture of its AI environment. It also revealed where different departments were considering similar solutions without knowing about each other's work.

2

We created a structured inventory of AI use cases

We created a common structure for recording and reviewing AI activity.

For each use case, the company could record:

  • ✓the business purpose;
  • ✓the department using it;
  • ✓the responsible business owner;
  • ✓the AI service or application;
  • ✓the service provider;
  • ✓the users or user groups;
  • ✓the information entered into the service;
  • ✓the information produced by the service;
  • ✓the systems connected to it;
  • ✓the business processes affected;
  • ✓whether personal data was involved;
  • ✓whether confidential information was involved;
  • ✓the possible effect of an incorrect output;
  • ✓applicable security and data protection controls;
  • ✓supplier and contractual considerations;
  • ✓the current approval status;
  • ✓required actions and review dates.

This helped the company distinguish between low-risk productivity uses and more sensitive cases.

Example Using an approved tool to improve the wording of a general internal announcement did not require the same level of review as using AI to process customer records, support employment decisions or provide recommendations affecting important business operations.
3

We grouped use cases by their level of risk

The company needed a simple way to decide how much attention each use case required.

We developed a proportionate assessment method based on factors such as:

  • ✓the sensitivity of the information;
  • ✓the use of personal data;
  • ✓the importance of the affected business process;
  • ✓the number and type of users;
  • ✓the level of human review;
  • ✓the possible consequences of an incorrect output;
  • ✓the degree of automation;
  • ✓integration with internal systems;
  • ✓supplier access to company information;
  • ✓retention and reuse of submitted information;
  • ✓intellectual property concerns;
  • ✓legal or contractual obligations;
  • ✓the possibility of misuse;
  • ✓existing security controls.

Use cases could then follow different routes.

A basic productivity use involving non-sensitive information could receive straightforward approval after a limited review. A use case involving sensitive data, automated decisions or important operations required a more detailed assessment and senior approval.

Some proposed activities were paused until additional safeguards were in place. Others were redesigned so that sensitive information was removed or a more suitable enterprise service was used.

4

We introduced clear rules for employees

The company already had information security and acceptable-use policies, but employees needed guidance specifically written for generative AI.

We prepared practical rules covering:

  • ✓which services employees could use;
  • ✓which services required approval;
  • ✓what information must not be entered;
  • ✓when personal data required additional review;
  • ✓how AI-generated content should be checked;
  • ✓when human approval was necessary;
  • ✓how confidential information should be handled;
  • ✓how suspected exposure should be reported;
  • ✓how copyright and intellectual property concerns should be escalated;
  • ✓where employees could request help with a new AI use case.

The guidance used examples from normal working situations rather than abstract technical language.

Employees were reminded that a confident answer from an AI service was not necessarily a correct answer. They remained responsible for checking important facts, decisions, calculations and external communications.

5

We clarified responsibilities

AI governance could not sit entirely with the security team.

The business department proposing a use case needed to explain its purpose, expected benefit and operational impact. IT needed to understand the technical service and integrations. Security assessed relevant cyber risks. Data protection and legal teams reviewed cases within their areas of responsibility. Procurement covered supplier and contractual requirements.

We documented responsibility for:

  • ✓proposing an AI use case;
  • ✓approving its business purpose;
  • ✓identifying the information involved;
  • ✓completing security and data protection reviews;
  • ✓assessing the supplier;
  • ✓approving technical integration;
  • ✓defining required controls;
  • ✓training users;
  • ✓reviewing AI-generated output;
  • ✓monitoring ongoing use;
  • ✓recording incidents or problems;
  • ✓reviewing or withdrawing approval.

Each approved use case had a named business owner. This person was responsible for making sure the use case remained appropriate and that the agreed controls continued to operate.

6

We connected AI governance with the existing ISMS

The company did not need a completely separate management system for AI.

Instead, we connected AI use cases with the processes already used to manage cybersecurity and information risk.

An AI use case could be linked to:

  • ✓the relevant business process;
  • ✓the supporting application;
  • ✓the information being processed;
  • ✓the supplier providing the service;
  • ✓the responsible owner;
  • ✓identified threats and risks;
  • ✓applicable security controls;
  • ✓data protection assessments;
  • ✓contractual requirements;
  • ✓incidents and audit findings;
  • ✓improvement actions;
  • ✓review dates and supporting evidence.

This allowed AI-related risks to be managed through the established ISMS rather than through another independent spreadsheet or register.

It also made it easier to see whether one issue affected several areas. For example, a supplier change could affect an approved AI use case, the data protection assessment, contractual safeguards and the company's overall risk position.

7

We assessed suppliers and embedded AI features

Not every AI service had been purchased as a separate product. In some cases, AI capabilities had appeared as new features within systems the company already used.

We therefore included AI questions in the supplier-review process.

The review considered:

  • ✓what information the supplier received;
  • ✓where the information was processed;
  • ✓whether submitted information could be retained;
  • ✓whether it could be used to improve the supplier's models or services;
  • ✓which subcontractors were involved;
  • ✓what security measures applied;
  • ✓how access was controlled;
  • ✓how incidents would be reported;
  • ✓what happened to information when the service ended;
  • ✓whether the company could disable unwanted AI features;
  • ✓how significant changes to the service would be communicated.

Where the available information was incomplete, the company recorded the uncertainty and decided whether additional safeguards or contractual clarification were required.

8

We improved management reporting

Management needed a concise view of AI adoption, not a technical description of every model or service.

The reporting structure focused on:

  • ✓approved and proposed AI use cases;
  • ✓use cases involving sensitive information;
  • ✓higher-risk activities awaiting a decision;
  • ✓tools being used without approval;
  • ✓overdue security or data protection actions;
  • ✓supplier concerns;
  • ✓incidents or suspected information exposure;
  • ✓repeated issues;
  • ✓controls that were missing or not working;
  • ✓expected business benefits;
  • ✓decisions required from management.

For each significant issue, the report showed the business context, responsible owner, main risk, planned action, deadline and decision required.

This helped management consider opportunity and risk together.

Deliverables

What We Delivered

The client received:

  • ✓a structured inventory of generative AI use cases;
  • ✓a practical AI risk-assessment method;
  • ✓clear approval routes for different levels of risk;
  • ✓employee guidance for the safe use of generative AI;
  • ✓defined roles and responsibilities;
  • ✓a process for reviewing suppliers and embedded AI features;
  • ✓links between AI use cases, data, systems, suppliers, risks and controls;
  • ✓management reporting templates;
  • ✓an escalation process for unapproved or higher-risk activity;
  • ✓practical guidance for regular reviews;
  • ✓a process for withdrawing or changing approvals;
  • ✓a structure for recording evidence and improvement actions.

The work did not create a separate governance system that competed with the client's existing processes. It brought AI into the company's established approach to risk, security, data protection and supplier management.

Impact

The Results

Within six months, the client achieved:

0
of identified AI use cases recorded in a central inventory
0
of identified AI use cases assigned to named business owners
0
of higher-risk use cases reviewed by security, data protection or legal teams
0
of relevant employees provided with practical guidance on responsible AI use
0
fewer unapproved AI tools identified during follow-up reviews
0
less time required to assess standard, low-risk AI use cases
0
of identified critical AI suppliers reviewed against agreed requirements
0
of approved AI use cases linked to business processes, assets, risks and controls

The company also gained a clearer understanding of where generative AI was being used, what information was involved and which business processes could be affected.

AI use cases involving sensitive information, important operations or greater levels of automation received more detailed reviews. Lower-risk productivity use cases could follow a shorter and more proportionate approval route.

Employees received practical guidance on approved tools, restricted information, human review and the reporting of suspected information exposure. Business teams also gained a defined process for proposing new AI initiatives.

Most importantly, AI governance became part of the company's established ISMS, data protection, procurement and supplier-management processes rather than a separate administrative system.

Transformation

What Changed for the Client

Clearer Decisions
Business teams knew how to propose an AI use case and what information was required for approval.
Better Visibility
The company could see which AI services were being used, who owned them and what information they handled.
Safer Use of Information
Employees had clearer guidance about personal, confidential and commercially sensitive information.
More Proportionate Reviews
Simple uses did not have to follow the same process as sensitive or highly automated applications.
Better Accountability
Approved use cases had named owners, review dates and agreed controls.
Stronger Supplier Oversight
The company could examine how external AI providers handled its information and where additional safeguards were needed.
A More Practical ISMS
AI-related risks became part of the company's normal security and risk-management processes.
Insights

What We Learned

Start with Real Use, Not Policy Wording
A useful governance process begins with understanding how employees and departments are actually using AI.
Not Every AI Use Case Carries the Same Risk
The level of review should reflect the information involved, the degree of automation and the possible consequences.
Clear Guidance Is More Useful Than a General Warning
Employees need specific examples of what they may and may not do.
Every Use Case Needs a Business Owner
Security can advise on risk, but the business must remain responsible for the purpose and operation of the use case.
Existing Governance Processes Still Matter
AI can be brought into established security, privacy, procurement and supplier-management processes. A completely separate system is rarely helpful.
Approval Is Not the End of the Process
AI services, suppliers, integrations and business uses can change. Approved use cases therefore need regular review.
Testimonial

Client Comment

"

"Generative AI was already being used in different parts of the business, but we did not have a clear view of where it was being used or what information was involved. The new process gave employees a practical route for proposing useful ideas while helping us identify the cases that needed stronger controls."

— [Client representative]

The quotation above must only be used after client approval. If an approved quotation is not available, this section should be removed.

Summary

Conclusion

The client did not need to choose between using generative AI and managing risk properly.

The real problem was the lack of visibility, ownership and consistent decision-making. Different teams were exploring AI, but the company did not have a shared way to assess the business purpose, information involved, supplier risk or required controls.

By creating an inventory of use cases and connecting it with data, systems, suppliers, risks and owners, the company established a more practical approach.

Employees received clearer guidance. Business teams had a route for proposing new ideas. Security and data protection specialists could focus their attention on sensitive and higher-risk uses. Management gained a better view of where AI offered value and where additional safeguards were needed.

Most importantly, generative AI became part of the company's normal approach to business risk rather than an issue managed through isolated policies and individual decisions.

Get Started

Are You Facing a Similar Problem?

Generative AI often enters an organisation through public services, employee experimentation, supplier products and new features within existing applications.

Cybersecurity Analytics can help you:

  • ✓understand how generative AI is being used;
  • ✓identify which information and business processes are involved;
  • ✓assess AI-related cybersecurity and data protection risks;
  • ✓create clear rules for employees;
  • ✓introduce proportionate approval processes;
  • ✓review AI suppliers and embedded features;
  • ✓assign accountable owners;
  • ✓connect AI governance with your existing ISMS;
  • ✓give management a clearer view of AI opportunities and risks.
Cybersecurity & AI Advisory

Introduce and manage generative AI with clearer oversight and practical controls.

Contact us to discuss how your organisation can introduce and manage generative AI with clearer oversight and practical controls.

How we can help
01
AI use case inventory
Map where generative AI is being used and what information is involved.
02
Risk-based assessment
Introduce proportionate review and approval routes for AI initiatives.
03
Employee guidance
Create practical rules that support responsible and productive AI use.
04
ISMS integration
Connect AI governance with your existing security and risk processes.