AI with
adult
supervision.
Most companies do one of two things with AI: ban it, or let it run wild. I built the third option: AI under real rules, with every cost tracked to its source and a human holding every sign-off. Here is the method in plain terms. It was developed at one firm and is applied across engagements.
Banned, or running wild
When it comes to AI, most companies pick one of two bad options. Some ban it outright, then watch their competitors pull ahead while their own people quietly use it anyway. The rest let it run wild: shadow tools nobody approved, company data pasted into consumer chatbots, secrets in prompts, and no idea what any of it costs or what it touches.
The third option is to treat AI the way you treat any other powerful tool in the business: with written rules, controlled access, every cost tracked to its source, and a human accountable for every decision that matters. That is what I built.
Rules first, then real work
- Every AI use now runs under a ratified governance standard I authored: every application goes through an approved company gateway instead of dealing with AI vendors directly; applications never hold their own AI passwords or keys for a thief to steal; personal information is filtered out by default; clear rules about how sensitive each kind of data is decide what may use an outside AI service and what must stay on company hardware; anything customer-facing keeps a human in the loop; and every application's AI spend is tracked back to that application.
- Sensitive data never leaves the building: where it matters, the AI runs on company hardware with no usage fees, including the models that turn recorded speech into written text. The most private work is also the cheapest to run.
- Two changes that would have quietly weakened production backups were caught before they ran, by an AI audit I assigned to attack a cloud cost-cutting plan. That is the working method: have one set of AIs try to tear apart what another produced.
- Every feature examined in an attack-style product review turned up real problems, and every finding held up when checked by hand. The method finds real defects, not noise.
- Compliance fixes ship only after five separate AI reviewers all agree, a unanimous 5-of-5 gate: every issue cross-checked from five angles, with the human lead keeping all sign-off.
- Every proposed code change gets an AI review before any human sees it, under a hard rule that AI never approves its own work. Humans review better code, faster, and stay accountable for all of it.
- Every developer on the team has shipped a real piece of AI-assisted work: hands-on workshops ran until that was true for all of them, not until a slide deck was finished.
The discipline is the point: AI is allowed to draft, audit, and argue. It is never allowed to decide. Every gate ends at a person whose name is on the outcome.
In plain terms
Spend you can see and cap
Every application's AI usage is measured and tracked back to the application that used it, and the heaviest work runs on company hardware with zero usage fees. No surprise bill, no invisible spend.
Every developer, faster
All of them (not an enthusiastic few) ship AI-assisted work, and AI review runs ahead of human review on every code change, so work moves quicker without cutting corners.
Known tools, known data
No unapproved AI hiding in the business. Every model in use is approved, every application's access is on record, and clear data-sensitivity rules decide up front what each piece of work is allowed to touch.
Sensitive data stays home
No stored passwords or keys for a thief to steal, personal information filtered out by default, and the most sensitive work confined to AI on company hardware that never sends data outside the building.
Defects caught before they ship
Attack-style AI audits caught two silent backup risks before they ran and found real problems in every feature examined. The business can move faster because more mistakes die in review.
A standard, not a person
The rules are written down and ratified, the gates are enforced in the workflow, and a human holds every sign-off. The capability survives staff turnover, including mine.
This client, like every client here, is not named: confidentiality is part of what they pay for. Every figure comes from the engagement's own records, and a reference who'll take your call is available on request.