UK Infrastructure Services Company
A UK-based infrastructure services company, the organization delivers essential services across the country and is committed to innovation, efficiency, and operational resilience.
ご覧になりませんか?
We didn’t know what people were using, and you can’t always trust people to tell you.”
Building governance faster than it could be verified
The company faced a challenge familiar to many organizations moving quickly with AI: demand for new tools was growing faster than the organization's ability to see and govern how they were being used. Marketing teams were especially eager to experiment, while bespoke tools emerged elsewhere in the business. The organization had clear guidance for responsible AI use, including what information could be shared with AI systems. However, IT still had limited visibility into which AI tools employees were actually using, making self-reporting an unreliable way to understand AI adoption across the business.
So, the company’s security team built a controlled model of its own. Direct access to AI websites was restricted and approved services whitelisted, with an approved single multi-model interface selected so governance could be applied once, at the point of access, rather than chased across every tool an employee might discover. Exceptions ran through a formal authorization path, advanced capabilities were released only as training and maturity increased, and an AI Champions network helped the business spot useful opportunities without duplicating effort.
While this was a sophisticated and mature response, the team still needed proof. Every control assumed employees were coming through the front door, and nothing in the model could confirm whether that assumption held — or reveal what was happening at the edges, on personal devices, through browsers, or across services IT had never heard of.
Shadow AI was our biggest concern... it is difficult to identify.”
– IT Service Manager, UK-based infrastructure services company
That was the gap the company needed to close: not more policy, and not more blocking, but visibility and proof.
From gatekeeping to enabling AI
What the governance model could not do on its own was prove itself. Darktrace / SECURE AI gave the company a way to validate whether the model reflects what is actually happening across the organization. The team saw clear value in AI usage visibility to inform access decisions, allocate paid licenses, identify duplicate subscriptions, and understand where approved access ended and unmanaged AI use began.
Visibility changed what the security team could offer the business. Instead of approving or refusing requests on instinct, the team could answer questions the organization actually cared about: who genuinely needs a paid license, where subscriptions overlap, and which teams are ready for more. Security stopped being the function that slowed AI down and became the one that told the business where to accelerate.
Darktrace enabled the company to:
- See what's really being used — surface AI activity beyond the approved list, so decisions rest on evidence rather than self-reporting.
- Put budget where the demand is — direct paid licenses to the people already using them, and recover spend on subscriptions that overlap or sit idle.
- Say yes with confidence — extend access by role, reflecting the different legitimate needs of marketing, leadership and more restricted functions.
- Time the next step — judge when teams are ready for advanced capabilities, rather than holding everyone back to the pace of the least prepared.
The reality of shadow AI
The company recognized early that block-and-whitelist strategies have limits. Employees can use personal devices, new services appear quickly, and browser-based access creates gaps that a blocklist will always trail behind. Broader visibility across network, endpoint, email and browser activity is what allows the organization to see where policies are working and where additional controls are needed — which is the gap Darktrace / SECURE AI now fills.
The team has shown particular interest in browser and email-based shadow AI detection. Browser visibility helps on managed devices, while email signals can reveal employees using company details to subscribe to services elsewhere. Department-aware policies help distinguish expected experimentation in marketing from activity that would be unusual in a more restricted function.
Building a practical foundation for responsible scaling
The most valuable outcome for the company is the operating model now taking shape. The organization is not pursuing unrestricted adoption or a blanket ban. It centralizes access where possible, requires authorization for exceptions, controls advanced capabilities through training, and has the visibility needed to validate that the policy is being followed.
Darktrace / SECURE AI serves as the evidence layer beneath decisions the organization is already making: which platforms to approve, which users need paid access, where shadow AI remains, and when advanced agentic features can be introduced safely.
The company’s direction is clear. Secure adoption requires more than access to AI. It requires an approved path, differentiated controls, training, visibility, and a way to make exceptions without losing governance. By combining staged enablement with the visibility Darktrace / SECURE AI provides, the company is moving from policy on paper to governance in practice — and building a responsible path from AI experimentation to adoption at scale.












