← Managed AI Security
FIELD NOTE / CASE STUDY

We found 34 AI services. We approved two.

How a nonprofit organization moved from scattered AI use to Copilot by default, licensed ChatGPT by exception, and everything else blocked until reviewed.

~300managed users
34AI domains found
2approved platforms
<8 weeksto turn it around
Conceptual illustration of AI services passing through a controlled security gateway

THE OUTCOME

In less than eight weeks: a safe default for everyday work, a real exception path when somebody needs more, and observed unauthorized AI use reduced to almost nothing.

THE SITUATION

AI adoption was moving faster than AI governance.

A nonprofit organization with approximately 300 managed users needed a way to let people use AI without allowing every new AI website to become an unreviewed destination for company information.

The users include employees, managers, contractors, and other authorized organizational users. The count does not include the people the nonprofit serves. Company work happens on company-managed devices.

People had legitimate reasons to experiment. But every new tool raised the same questions: Who operates it? What does it retain? Could submitted information be used for model training? Can access be shut off centrally?

The initial turnaround from discovery to a governed operating model took less than eight weeks.

WHAT WE FOUND

The approved list had two platforms. The environment had 34 AI-related domains.

The review surfaced 34 AI-related domains. Only Microsoft Copilot and licensed ChatGPT were approved. The other 32 were blocked unless and until a documented exception was granted.

Sixteen of the 34 raised additional concerns in our review and were also identified as risky by Microsoft Defender. We are not publishing individual historical scores because we do not have the evidence in front of us to quote them precisely.

Blocked does not automatically mean malicious. It means not yet approved.
34 AI-related domains found
2approved
32blocked by default

A point-in-time finding, not a permanent inventory.

THE APPROVED PATH

Do not make people choose between getting work done and following the rules.

Give them a safe default. Make exceptions possible. Keep unknown tools closed until somebody has looked at them.

01 STANDARD

Copilot in the Microsoft tenant

The standard approved environment for general business use. People work inside the organization's managed Microsoft boundary.

02 BY EXCEPTION

Licensed ChatGPT

Available to people with a legitimate business need. Approved users are placed in a dedicated security group instead of receiving access by default.

03 REVIEW REQUIRED

Everything else

A user can request another service. The business purpose, vendor, account controls, security posture, and data handling get reviewed before access is allowed.

THE CONTROL LAYERS

Software can enforce a boundary. It cannot make the decisions for you.

MICROSOFT PURVIEW

Label the data. See the Copilot activity.

Purview supports the program through data labeling and visibility into Copilot conversations. It helps the organization understand how information moves inside the approved environment.

DEFENDER FOR CLOUD APPS

Find the services. Enforce the block.

Defender helps identify cloud applications, supplies risk information, and supports blocking against AI services the organization has not approved.

tekRESCUE REVIEW

Look beyond the catalog.

Recurring reviews of company-managed devices and authorized endpoint and browser signals help find AI activity that platform controls may miss. Experimental scripts are extending that visibility, but this is still developing work, not a magic detector.

THE HUMAN LAYER

A block list is not an AI governance program.

People need to know what they can use, what they cannot do, and how to ask for something different. Otherwise the policy loses to the deadline.

  1. 01
    AI governance plan

    Who owns the decisions, how tools are reviewed, and how the program changes over time.

  2. 02
    Formal policies

    Clear acceptable-use rules, data boundaries, and responsibilities for employees and contractors.

  3. 03
    Exception process

    A legitimate path for a person who needs a tool beyond the standard approved environment.

  4. 04
    One-page desk aids

    The short version people can actually use while they are working.

  5. 05
    User acknowledgment

    Users acknowledge the applicable technology terms and receive policies as they roll out.

THE HONEST LIMIT

No static block list stays complete for long.

New AI services appear constantly. A new domain may not be categorized immediately, and somebody may reach it before a recurring review finds it. Nobody can honestly promise otherwise.

The job is to make new services visible, evaluate them consistently, block what does not belong, and create a controlled path for tools the business actually needs.

WHAT CHANGED

In less than eight weeks, scattered AI use became a program people could follow.

BEFORE

New tools appeared without review. Leadership could not make a responsible decision about services it did not know people were using.

AFTER

Copilot became the safe default. Licensed ChatGPT had a controlled exception. Everything else started blocked, with a real process for legitimate requests.

Observed unauthorized AI use fell to almost nothing. We are describing that result directionally because we are not attaching a manufactured percentage to evidence that was not collected as a formal study.

WHAT OTHER ORGANIZATIONS CAN USE

Five lessons from the work.

01

You cannot govern the AI services you cannot see.

02

An approved default works better than a policy that only says no.

03

Licensed access should follow business need, not curiosity.

04

Unknown does not mean malicious. It does mean review it before company data goes in.

05

Detection, approval, blocking, policy, and training have to operate as one system.

MANAGED AI SECURITY

Your people are already using AI. Let's find out what that means.

You do not have to choose between banning AI and letting every new tool through the door. We help you establish a safe default and build a review process for everything else.

Last reviewed September 3, 2026