Cerberus blocks the lethal trifecta at the tool boundary — see the 525-run evidence set.

Warden · Advisory

An AI policy nobody can follow produces shadow AI, not compliance

Design and rollout of an AI policy program: acceptable use, approval routes for new AI systems, and the acknowledgement record that turns a document into a control.

Prohibition policies get routed around

A policy that bans AI tools without offering an approved path does not stop usage; it moves it onto personal accounts where you cannot see it, which is strictly worse than the thing it was written to prevent.

  1. No approved path means no visibilityPeople will use the tool that does their job and will not tell you about it.
  2. Approval routes that take weeks are ignoredIf the process is slower than the deadline, the process loses.
  3. Unacknowledged policy is not evidenceA document in a repository nobody has read will not support an enforcement decision.

How the engagement runs

1

Understand actual usage

What people are doing with AI today, so the policy addresses reality rather than an assumption.

2

Draft against a framework

Acceptable use, data handling and approval routes, mapped to ISO/IEC 42001 and NIST AI RMF so it counts as control evidence.

3

Design the approved path

A route to getting a new AI use case approved that is fast enough that people use it.

4

Roll out and record

Publish, campaign for acknowledgement, and keep the record of who accepted which version and when.

What you hold at the end

  • An AI acceptable use policy written against your actual usage patterns
  • Framework mapping so the policy stands as control evidence
  • A documented approval route for new AI use cases, with a service level
  • An acknowledgement campaign and a per-version record of who accepted what
  • A review cadence so the policy tracks the tooling rather than expiring

What runs it

A policy with a path and a record

Those two things are the difference between a governance control and a document that exists to be shown to auditors.