note · Jan 2026

Where AI already lives in your enterprise — and what you can't prove about it

Before you govern enterprise AI, you have to find it. It's rarely where the org chart says — and most of it is running today with no record anyone could show an auditor.

Nobody deployed most of your AI

Ask where AI touches your business and the first answer is usually a short, tidy list: the licensed copilot, a chatbot on the website, maybe a model in one flagship project. Then someone actually looks. A model is summarizing contracts inside the legal team's document tool. An enrichment step in the CRM is calling an external API on every new lead. A finance macro routes invoices through a service no one put through review. A support queue auto-drafts replies from customer history.

None of that was a decision. It accumulated — one convenient feature at a time — and it's running right now. Gartner's read of the field is blunt about the consequence: roughly 80% of unauthorized AI events are ordinary internal policy violations, not attacks. The risk isn't a hacker. It's your own systems, doing their jobs, in ways no one can currently see end to end.

The question that exposes the gap

Here's the test that turns vague unease into something concrete. Pick any one of those workflows and ask: what data reached the model, and can you prove none of it left your walls? For most enterprises today the honest answer is a shrug — not because the team is careless, but because there is no record. The action ran; nothing wrote down what it did.

That gap is why "just add a policy" or "buy another AI tool" doesn't land. You can't put rules around what you can't see, and you can't prove what you never recorded.

Recognize first, govern second

The useful first move isn't a control — it's a look. See where AI actually sits in the work, what it touches, and what would happen if it were wrong, before you change anything. That's the entire premise of starting in Watch mode: observe a real workflow at zero risk and produce the record you don't have yet. Recognition comes first; governance is what you do once you can finally see.

The pieces that follow take single workflows — a claims process, a clinical record, a procurement reconciliation — and walk through exactly what was hiding in each, and what an Inspector caught.

Related

← All notes