AI adoption in most organisations didn’t wait for permission. Employees started using generative tools, agents began appearing in workflows, and by the time security teams looked up, AI was already embedded in “business as usual”, a reality we explored in Governing AI After Adoption Has Already Started. The result is a governance model built for a moment that has already passed.
The scale of that blind spot is stark. CrowdStrike have found that organisations consistently underestimate their AI footprint. In one engagement a customer had catalogued 150 agents, but CrowdStrike identified more than 500 in active use. Separately, over 1,800 distinct AI applications have been detected running across customer endpoints). This isn’t a niche problem: 45% of employees admit to using AI tools without telling their manager. You cannot govern what you cannot see.
This is why policy alone has proven insufficient. An acceptable use policy tells people what they should do; it does nothing to detect what they are doing. As we argued in AI Governance Only Works When It Extends Into Operational Reality, governance has to move from a document into telemetry. This must include visibility into which tools are in use, which prompts are being submitted, and which data is leaving the organisation through them.
The threat backdrop makes this urgent: CrowdStrike’s 2026 Global Threat Report recorded an 89% year-on-year increase in attacks by AI-enabled adversaries, with 82% of detections in 2025 involving no malware at all, intrusions that blended into legitimate, trusted activity instead (CrowdStrike, 2026c). AI-driven risk and AI-enabled attack are converging on the same operational blind spot.
But visibility and enforcement tooling, on their own, still aren’t the finish line. As AI Governance Cannot Sit Solely with Security Teams sets out, even a fully instrumented environment needs shared ownership with legally defined acceptable data use, HR addressing employee AI behaviour, procurement vetting third-party AI tools, and business leaders accountable for outcomes. Security can supply the evidence; it cannot carry the governance decision alone.
How Red Helix transformed AI governance.
We enable organisations to close this loop through our Evaluate, Execute, Evolve approach. An AI risk assessment gives a view of AI use and exposure as a starting point. From there, we deploy CrowdStrike Falcon AIDR, managed through our UK-based SOC, to give real-time visibility into AI usage, prompts, and data flows, and to enforce policy at machine speed rather than relying on self-reporting. Our Security Intelligence Platform then turns that telemetry into board-level evidence, showing not just what AI is running, but how risk is changing over time, so governance can be demonstrated to regulators and stakeholders, not just claimed. If you’re unsure what AI is already running in your environment, that’s the right place to start.
