Shadow AI Enterprise Risk: Govern the AI Your Staff Already Use
Shadow AI enterprise risk is not a future threat. It is happening inside your firm this morning. While your policy committee debates an acceptable-use memo, an associate is pasting a draft settlement into a public chatbot to "tidy up the language." A junior analyst is feeding a confidential mandate into a model to summarise it before the partner meeting. You did not approve this. You cannot see it. And the work it produces is already shaping the advice your clients pay for. The exposure is not coming. It has arrived.
Your audit trail ends at the paste
You have spent a decade building controls. Access logs. Encryption at rest. Data-loss prevention on email and endpoint. Retention schedules a regulator could read in their sleep. Every system of record inside your perimeter writes a line you can later defend.
Then a member of staff opens a browser tab, pastes in a clause from a live deal, and presses return. At that instant your audit trail ends. There is no log. There is no retention policy. There is no chain of custody you could ever hand to a court. The reasoning that produced the next draft happened somewhere you cannot reach, on infrastructure you do not own, governed by terms you did not sign.
The CISO knows. The General Counsel knows. They have known for a year. The honest difficulty is that every enforcement option they have been offered carries a tax. Block the domains and the work routes around you through a phone. Issue a stern policy and you have created a paper defence, not a real one. Productivity has already chosen its tools.
The problem is not that your people are reckless. Many of them are your best. The problem is not ignorance. It is architecture. You are trying to govern an act that, by design, leaves no record where you can find it.
Shadow IT had a perimeter. Shadow AI does not.
We have been here before, and that memory is misleading you.
When staff smuggled work onto personal Dropbox accounts or a private Slack, security teams treated it as containment. The data had left the building, yes — but it had left as a file. A file can be located. It sits on a server in a known jurisdiction. It can be subpoenaed, deleted, recovered. The breach had edges. You could draw a line around it and say: this much, and no more.
Shadow AI has no edges. When your analyst pastes a memo into a frontier model, the document itself may never be retained at all. That is not the exposure. The exposure is subtler and far worse. The intelligence built from that document — the patterns, the structure of your firm's reasoning, the shape of how your best people think about a problem — passes into a training pipeline you will never audit. The file can be deleted. The learning cannot.
This is the inversion most explainers miss. With shadow IT, your data moved and your thinking stayed home. With shadow AI, your data may stay home while your thinking moves — permanently, irreversibly, into someone else's model, to be served back to your competitors as a generic capability. You did not lose a document. You donated an edge.
You cannot ban your way out of this
The instinct is prohibition. It will fail, and you already suspect why.
A ban does not remove the demand. It removes your visibility into how the demand is being met. Staff who cannot use the sanctioned tool will use an unsanctioned one on a device you do not manage, and now you have less insight than before, not more.
Enterprise ChatGPT seats are sold as the grown-up answer. They are an improvement on access and on contractual posture. They are not an answer on provenance. Microsoft still sits in the path of every prompt. Your reasoning still leaves your perimeter; you have merely chosen a more reputable destination for it. SaaS data-loss tools flag exposure after the words have already crossed the wire — a smoke alarm that rings once the room is alight.
Every one of these is a control bolted onto an architecture that was never built to keep the inference at home. The only durable fix is structural: bring the model inside the perimeter, so the prompt has nowhere to travel.
Sanction the capability. Govern the trail.
This is what Third ARK is for. Not to forbid the capability your people clearly need — to bring it home and put it under governance.
The model runs locally, on hardware the institution owns and controls. The inference happens inside your walls. No prompt leaves the perimeter, because there is no remote endpoint for it to reach. The question your associate asks and the answer the model returns both stay where your other privileged material stays: under your roof, under your control, inside the boundary your regulator already recognises.
Around that local model sits the VAULT. Every piece of intelligence the system reasons from is held there as a node — sourced, dated, traceable. Nothing enters the reasoning chain anonymously. When the model draws a conclusion, the material it drew from is recorded, not inferred after the fact.
The Gospel Protocol governs what may change. Any node the Operator marks as bedrock — a binding contract term, a regulatory definition, a finding of fact — is locked. The AI may cite it. The AI may reason from it. The AI cannot overwrite it. Your settled truths stay settled, immune to the quiet drift that makes generative systems untrustworthy in regulated work.
And every output the system publishes carries an Atomic Passport: a hash-sealed chain running from the final claim back through every node to the source document beneath it. When the regulator asks what your AI reasoned from, you do not reach for assurances. You hand them the chain.
The Atomic Passport: proof, not promises
Most enterprise AI vendors sell you data residency. They tell you where the data lives and ask you to trust the diagram. Residency is a promise. Promises are audited by lawyers and broken by incidents.
The Atomic Passport is not a promise. It is a hash. Each output carries a cryptographic seal binding the published claim to the exact chain of sources that produced it. Alter one node and the seal breaks — visibly, mathematically, with no opinion required. You are not asked to trust Third ARK. You are not asked to trust the Operator. You are asked to trust arithmetic, which has never once been persuaded to look the other way.
This is the difference between a vendor saying "we kept your data safe" and a document proving it of itself. One is a position you defend under questioning. The other is a fact you present and stand back from. In a deposition, in an audit, in front of a board, that distinction is the entire game.
Frequently asked questions
Q: Does this require internet connectivity to function? A: No. The model and the Vault run entirely on local hardware. Inference, retrieval and sealing all happen offline. Connectivity is needed only for updates you choose to apply on your own schedule — never for the act of reasoning itself. A Third ARK deployment works in an air-gapped room.
Q: What happens if an employee tries to override a locked node? A: They cannot. A node sealed under the Gospel Protocol is immutable to the AI and to ordinary users alike. The system will cite it and reason from it but refuses any write that would alter its body. Unlocking is restricted to the designated owner and is itself recorded — so even a legitimate change leaves a defensible trail.
Q: How does this interact with our existing DLP and SIEM tools? A: It complements them rather than competing. Because inference stays local, there is no outbound prompt for your DLP to chase. The Vault's provenance records and lock events export as structured logs your SIEM can ingest, giving your security team something most AI controls never produce: a clean, queryable trail of what the AI did and what it drew from.
Q: Can we run this in our own data centre rather than on a Mac? A: The reference deployment runs on Apple hardware, which suits a single Operator or small desk. For an institution, the architecture ports to your own server estate. We scope the target environment during the Sounding and the blueprint specifies it precisely.
Q: What does a 90-day pilot look like? A: A bounded deployment against one real domain — a practice group, a deal team, a casework unit. We install locally, seal an initial Vault, and run live work through it. At ninety days you hold the provenance trail, the lock history and a measured view of adoption. No production data ever leaves your control during the trial.
Book a Sounding
Begin with a Sounding. It is a paid half-day in which the Chairman reads your domain in earnest — your obligations, your exposure, the shape of your work — and returns two things: a Vault blueprint built for your firm, and a fixed quote with no moving parts.
The fee is £750. It is credited in full against a commissioned Genesis, so the institution that proceeds pays nothing twice. You will receive a personal reply, not a pipeline. There is no sales process, no qualification call, no procurement theatre. The Chairman takes one institution at a time, in order, and reads each one properly.
The flood is rising. Everyone else is selling swimming lessons.