MIKE NANTO
Case file 06 · full record · AI strategy & governance

AI with
adult
supervision.

Most companies do one of two things with AI: ban it, or let it run wild. I built the third option: AI under real rules, with every cost tracked to its source and a human holding every sign-off. Here is the method in plain terms. It was developed at one firm and is applied across engagements.

0usage fees on the AI that runs on company hardware. Sensitive data never leaves the building
2hidden risks to production backups caught before they ran, by AI assigned to attack the plan
5-of-5AI reviewers must all agree before compliance work moves. A human keeps sign-off
100%of developers shipped real AI-assisted work after hands-on workshops
§1 · The situation

Banned, or running wild

When it comes to AI, most companies pick one of two bad options. Some ban it outright, then watch their competitors pull ahead while their own people quietly use it anyway. The rest let it run wild: shadow tools nobody approved, company data pasted into consumer chatbots, secrets in prompts, and no idea what any of it costs or what it touches.

The third option is to treat AI the way you treat any other powerful tool in the business: with written rules, controlled access, every cost tracked to its source, and a human accountable for every decision that matters. That is what I built.

§2 · What was done

Rules first, then real work

  • Every AI use now runs under a ratified governance standard I authored: every application goes through an approved company gateway instead of dealing with AI vendors directly; applications never hold their own AI passwords or keys for a thief to steal; personal information is filtered out by default; clear rules about how sensitive each kind of data is decide what may use an outside AI service and what must stay on company hardware; anything customer-facing keeps a human in the loop; and every application's AI spend is tracked back to that application.
  • Sensitive data never leaves the building: where it matters, the AI runs on company hardware with no usage fees, including the models that turn recorded speech into written text. The most private work is also the cheapest to run.
  • Two changes that would have quietly weakened production backups were caught before they ran, by an AI audit I assigned to attack a cloud cost-cutting plan. That is the working method: have one set of AIs try to tear apart what another produced.
  • Every feature examined in an attack-style product review turned up real problems, and every finding held up when checked by hand. The method finds real defects, not noise.
  • Compliance fixes ship only after five separate AI reviewers all agree, a unanimous 5-of-5 gate: every issue cross-checked from five angles, with the human lead keeping all sign-off.
  • Every proposed code change gets an AI review before any human sees it, under a hard rule that AI never approves its own work. Humans review better code, faster, and stay accountable for all of it.
  • Every developer on the team has shipped a real piece of AI-assisted work: hands-on workshops ran until that was true for all of them, not until a slide deck was finished.

The discipline is the point: AI is allowed to draft, audit, and argue. It is never allowed to decide. Every gate ends at a person whose name is on the outcome.

§3 · What the client gained

In plain terms

Cost

Spend you can see and cap

Every application's AI usage is measured and tracked back to the application that used it, and the heaviest work runs on company hardware with zero usage fees. No surprise bill, no invisible spend.

Speed

Every developer, faster

All of them (not an enthusiastic few) ship AI-assisted work, and AI review runs ahead of human review on every code change, so work moves quicker without cutting corners.

Visibility

Known tools, known data

No unapproved AI hiding in the business. Every model in use is approved, every application's access is on record, and clear data-sensitivity rules decide up front what each piece of work is allowed to touch.

Security

Sensitive data stays home

No stored passwords or keys for a thief to steal, personal information filtered out by default, and the most sensitive work confined to AI on company hardware that never sends data outside the building.

Growth

Defects caught before they ship

Attack-style AI audits caught two silent backup risks before they ran and found real problems in every feature examined. The business can move faster because more mistakes die in review.

Continuity

A standard, not a person

The rules are written down and ratified, the gates are enforced in the workflow, and a human holds every sign-off. The capability survives staff turnover, including mine.

§4 · A note on names

This client, like every client here, is not named: confidentiality is part of what they pay for. Every figure comes from the engagement's own records, and a reference who'll take your call is available on request.

Using AI with no idea what it costs or touches?

Thirty minutes is enough for me to tell you honestly where the risk sits, and what a governed version would look like for your business.