US Public Interest Law Firm
A US-based public interest law firm specializes in high-impact class actions, consumer protection, and corporate accountability. The firm focuses on establishing legal precedents a
I can provide proof to say that AI is incredibly valuable and people are using it.”
A US-based public interest law firm used Darktrace / SECURE AI™ to move from assumptions to evidence-led AI governance. As AI workflows and agents became part of everyday work, the firm needed a practical way to understand how employees were using AI tools, where sanctioned and unsanctioned activity overlapped, and how to support responsible adoption without slowing innovation.
For the firm, the challenge was not whether employees would use AI. That reality had already arrived. Claude was emerging as the firm’s primary sanctioned tool, with Microsoft Copilot right behind. But adoption did not follow a single, predictable path. Employees gravitated toward different services and needed more guidance than the firm initially expected.
That created a governance challenge. Before leaders could set effective guardrails, they needed to understand which tools employees were using, why they chose them, and what kinds of information were moving through AI-assisted workflows. Native analytics for the firm’s Claude Teams deployment did not provide the full picture, and the team wanted insight without forcing employees to change how they worked.
We have a really intuitive group of people, so we expected AI adoption to happen naturally. What we learned was that people wanted more guidance and more guardrails than we initially anticipated.”
— Systems Engineer, US-based public interest law firm
At first, the firm introduced AI office hours to help users build confidence and adopt more responsible practices. But the missing ingredient was evidence: a view of actual usage that could shape those conversations, inform policy, and help the firm distinguish between productive AI adoption and activity that required further review.
The Challenge
Innovation was moving faster than visibility
AI adoption was accelerating faster than traditional governance processes could keep up. Employees were finding new ways to use AI to complete work, answer questions, and improve productivity. But without trusted visibility, the firm could not easily confirm whether real behavior matched internal expectations.
That lack of visibility made policy harder to write and harder to enforce. Static controls and written guidance depend on knowing which tools, users, and actions need to be governed. But AI usage changes quickly, and employees often adopt tools before formal processes catch up.
For a legal services organization, that uncertainty matters. AI-assisted workflows can involve sensitive information, client-related context, internal documents, and professional judgment. The firm needed a way to understand AI activity in context so governance decisions could be based on evidence rather than assumptions.
The Approach
Start with visibility, without disrupting the work
The firm joined the Darktrace / SECURE AI early adopter program and completed deployment with minimal friction. The passive approach meant users could continue working normally while Darktrace / SECURE AI began building a view of AI activity across the environment.
The visibility helps us understand whether our approved strategy is actually aligning with employee behavior. You guys make it so easy, that’s kind of insane!”
— Systems Engineer
Darktrace / SECURE AI helped bring AI interactions into a more centralized view, giving the team a way to review activity, assess risk, and better understand how AI tools were being used across the business. That visibility supported the firm’s goal of enabling AI responsibly rather than restricting it by default.
Systems Engineer, used risk scoring, prompt review, identity relationships, and Shadow AI service discovery as an investigative layer. Rather than treating every signal as proof of misuse, the systems engineer reviewed context, learned how the platform reached its classifications, and used the findings to ask better internal questions.
That approach aligned with a larger reality of AI governance: organizations cannot secure what they cannot see. Written policies are important, but they are more useful when they reflect how people actually work. By introducing visibility first, the firm could begin shaping guidance around real behavior.
The Discovery
Shadow AI data changed the conversation
Once Shadow AI results began to populate, the firm gained a clearer view of its AI footprint. Over a 28-day view cited in the feedback session, 80% of active users were shown using Claude, which aligned with expectations. What was surprising, however, was that 17% of active users were shown using OpenAI, even though it was not an approved tool internally.
Eighty percent of our users were using Claude, which aligned with our expectations. What surprised me was seeing OpenAI usage show up as well. That immediately gave us questions we needed to answer around governance and approved tools.”
— Systems Engineer
That finding gave the team a concrete starting point for discussion. It raised questions about approved versus unapproved services, duplicate spending, employee guidance, and the risk of workflows becoming dependent on tools the firm did not formally govern.
The value was not only in identifying the presence of AI services, but in helping the team understand whether policy, licensing, and employee behavior were aligned. If employees were using approved tools as expected, the data could help validate that strategy. If employees were using unapproved tools, the data could help the firm understand why and decide whether to restrict, guide, or formally enable that usage.
That shift changed the conversation from, “Are people using AI?” to “How are people using AI, and what should we do about it?” For a firm seeking to support responsible innovation, that distinction was critical.
The Impact
From assumptions to evidence-led governance
The early value for the firm was not a single blocked event or a reduction in incidents. It was a shift from assumptions toward evidence. The firm could see that AI adoption was real, identify where behavior diverged from its approved-tool strategy, and use those insights to support more practical governance decisions.
Usage visibility helped demonstrate that employees were actively finding value in AI. Unexpected OpenAI activity highlighted a gap between sanctioned tools and actual behavior. Findings could feed AI office hours, responsible-use guidance, policy decisions, and licensing conversations.
I can provide proof with this and say, ‘Yeah, actually AI is incredibly valuable and people are using it.’”
— Systems Engineer
That sense of normalcy matters. Security teams are often asked to balance control with enablement, especially when new technology becomes part of everyday work. The firm’s experience shows how visibility can help security and IT teams support adoption with greater confidence.
Rather than becoming the team that tries to slow progress, security can help the business move forward with the right guardrails in place. Darktrace / SECURE AI gave the firm a way to understand AI activity as it happened and use that insight to guide practical, risk-aware decisions.
The Human Element
Guardrails work best when they strengthen trust
The feedback also surfaced an essential issue for any organization adopting AI monitoring: transparency. The systems engineer wanted to understand the experience from both sides, as the person responsible for oversight and as an employee whose activity could be reviewed. That perspective reinforced the need for clear internal policy, appropriate access controls, and a review process grounded in legitimate security and governance needs.
I want to put myself in a position of both a person who is being watched and a person who has the ability to watch.” — Systems Engineer
For the firm, the path forward is not simply more monitoring. It is using visibility responsibly to help people adopt AI with greater confidence, while giving leaders the evidence they need to make informed decisions.
Looking Ahead
Building a fuller picture of AI-assisted legal work
The firm identified opportunities for deeper value as coverage expands, including fuller Claude and ChatGPT visibility, better insight into AI interactions with documents, retention options for departed users, device-level context, and clearer links from identity relationships to connected resources. These are forward-looking needs, not current outcome claims.
Even at this early stage, the case is clear: AI governance becomes more practical when decisions are grounded in how people actually work. By bringing sanctioned and unsanctioned usage into view, the firm is creating a stronger foundation for responsible AI adoption.
“My managing partner is obsessed with AI. He wants to make sure we're all protected with the right guardrails as adoption continues to grow.”
— Systems Engineer
For organizations navigating AI adoption, The firm’s experience reflects a broader lesson: transformation without trust does not scale. To unlock the value of AI, businesses need visibility into how it is being used, context to understand risk, and the confidence to guide adoption without unnecessarily slowing it down.


















