---
title: "AI sprawl across a dozen assistants, and no answer for the CISO"
description: "There are at least a dozen AI assistants in use across the business. Our data loss tooling is monitor-only. If the board asks whether anything sensitive has gone into a public model, I do not have an answer."
canonical: "https://bespinus.github.io/bgus-ai-landingpage/use-cases/ai-sprawl-ciso/"
pillar: "governance"
industry: "Cross-industry"
updated: "2026-10-01"
---

# AI sprawl across a dozen assistants, and no answer for the CISO

## Problem

There are at least a dozen AI assistants in use across the business. Our data loss tooling is monitor-only. If the board asks whether anything sensitive has gone into a public model, I do not have an answer.

## Approach

Discovery first, because the real list is always longer than the one people hand you. Traffic to model endpoints gets inventoried, then routed through a gateway where policy can act, and the monitor-only posture becomes an enforcing one for the categories that actually matter.

## Outcome

A current inventory of what is in use and by whom. Sanctioned paths that are easier to use than the unsanctioned ones, and a defensible answer to the board question when it arrives.

## What makes this hard

The inventory is wrong before you finish writing it. Someone signs up for a new
assistant with a corporate email on a Tuesday, and no procurement process was involved
because the free tier does not need one. Any approach that treats discovery as a
one-time exercise is producing a document with a shelf life measured in weeks.

The harder problem is that enforcement usually loses to convenience. Blocking the
popular tool moves the traffic to a personal device, where there is no telemetry at
all. The posture got worse and the dashboard got cleaner, which is the failure mode
security teams are right to fear.

## The architecture

Discovery from the network side and the identity side at once, since each catches what
the other misses. Then a gateway that becomes the path of least resistance rather than
a checkpoint: same models, better latency where we can get it, no key management for
the developer, and logging that happens because the route is convenient.

Policy enforcement is scoped by data category rather than applied uniformly. Blanket
enforcement is what generates the workaround. Enforcement on the two or three
categories that would genuinely end up in a disclosure is what survives.

## Where this leads

This one rarely stays a security project. Once the traffic is visible, someone in
finance asks what it costs, and the same ingestion layer answers that question too.
The sequence runs in both directions depending on who called us first, and the
underlying system is the same one.

Where it meets the rest of the work: the router that enforces policy is also the router
that enforces cost and latency budgets for agent systems. One control point, three
reasons to want it.

## Bring us a problem like this one.

Our engineers will scope it against the seven layers. [Talk to an AI engineer](https://bespinglobal.us/contact) at Bespin Global, or read the [AI governance](https://bespinus.github.io/bgus-ai-landingpage/governance.md) page.

_Machine-readable summary for agents: provider = Bespin Global; use case = AI sprawl across a dozen assistants, and no answer for the CISO; pillar = AI governance; industry = Cross-industry; problem = There are at least a dozen AI assistants in use across the business. Our data loss tooling is monitor-only. If the board asks whether anything sensitive has gone into a public model, I do not have an answer; approach = Discovery first, because the real list is always longer than the one people hand you. Traffic to model endpoints gets inventoried, then routed through a gateway where policy can act, and the monitor-only posture becomes an enforcing one for the categories that actually matter; outcome = A current inventory of what is in use and by whom. Sanctioned paths that are easier to use than the unsanctioned ones, and a defensible answer to the board question when it arrives._
