Stalled in review
Pilots sit in security review for months. There is no policy an auditor would accept.
The CEO says go. Compliance says no. Employees use AI anyway.
Pilots sit in security review for months. There is no policy an auditor would accept.
Staff paste customer data into tools nobody approved.
Licenses get bought. Then most people quietly stop using them.
Nobody can tell the board who uses it, what it saved, or why people quit.
Count the AI already in use. Then write the policy, the approved tool list and the data rules from what people actually do.
Put approved tools in the hands of one or two pilot teams in operations, finance, support or compliance. Training, a champion in each team, weekly office hours.
Track who uses it, what it saves and why people stop. Turn that into a report the board can read.
Regulated companies, about 50 to 500 people.
Two weeks, fixed scope. If nothing is worth doing, I will say so.
Govern, Enable, Measure with one or two pilot teams.
Monthly report, policy updates, tool reviews.
What I don't touch: your product AI and engineering roadmap. Those stay with your CTO.
I'm usually the person who says no. That's why I can get you to yes.
Who it's for: Fintech, payments, healthcare-adjacent and insurance companies with PCI, HIPAA or SOC 2 in scope. Usually sponsored by the CEO or COO.