How to make the AI data risk argument land and get it funded
Brian Painting, Cofounder, Cattlegrid.uk
For information security leads, IS managers, and quality professionals navigating the gap between what their organisations are doing with AI and what they have authorised.
You already know the risks. You’ve read the reports. You’ve probably written a risk register entry or two that went nowhere.
The problem is not that AI data governance lacks urgency. The problem is that most of the people who control budgets don’t feel that urgency yet. By the time they do, something will have gone wrong.
This is a brief on how to change that dynamic. Not by generating more heat around the issue, but by making the case in the language that actually gets things funded.
What Is Actually Happening in Your Organisation Right Now
Let’s start with the data, because precision matters here and vagueness is your enemy when making this argument internally.
71% of UK employees are currently using unapproved AI tools. More than half do so at least weekly. 83% of their organisations have no controls in place to manage the data those tools consume. These are not projections. They are survey findings from late 2025, drawn from samples of over a thousand UK organisations.
The information flows are not random. They cluster around the most commercially sensitive activities your organisation conducts:
- contract review,
- financial analysis,
- client relationship management,
- board papers,
- HR matters.
These are precisely the workflows where AI tools are most immediately useful, and precisely the workflows where the data involved carries the greatest confidentiality obligations, regulatory weight, and reputational consequence.
Every time an employee pastes a client document into ChatGPT or Claude to get a summary, that data has left your environment. It has gone to a server outside your jurisdiction, governed by terms of service your legal team has almost certainly not reviewed, with retention policies that are inconsistent with your standard client confidentiality commitments. You have no visibility that it happened. You receive no notification. The audit trail is blank.
410 million data loss prevention violations have been recorded via ChatGPT alone, according to Zscaler’s 2026 AI Security Report. That figure is not an extrapolation. It represents interactions that were monitored. The unmonitored interactions are, by definition, unknowable.
This is the problem.
The Threat Landscape: Three Vectors Worth Understanding
Direct data leakage through AI API interactions is the most immediate and, technically speaking, the most tractable risk. An employee submits sensitive data to a public AI service; that data is now outside your control. The financial consequence depends on what the data contains: client PII triggers data protection obligations; commercial information triggers potential breach of contract; privileged information triggers professional liability. The IBM Cost of Data Breach Report for 2025 quantifies a specific premium for shadow AI involvement: an additional £498,000 over the baseline breach cost. The UK baseline is £3.29 million. In financial services it rises to £5.74 million. The shadow AI surcharge is not theoretical.
Insider threat amplification is the second vector, and it is frequently underweighted. Internal threats; employee error, malicious action, compromised credentials;already account for 30% of all data security incidents. AI tools amplify this in both directions: a negligent employee can inadvertently exfiltrate far more data in a single interaction than through traditional means, and a malicious actor with access to AI tools can extract and package information with a sophistication that previously required specialist technical knowledge. The tool itself becomes the exfiltration mechanism.
Supply chain exposure is also worthy of consideration. 15% of UK data breaches originate from third parties, from contractors, suppliers, and yes, technology partners. In professional services environments, where client work frequently involves external advisers and contractors, the question of whether those third parties have adequate AI governance is a direct extension of your own security posture. Your enterprise clients are already asking this of you. You should be asking it of your supply chain.
The Regulatory Environment: What Changed in August 2025
The EU AI Act entered enforcement in August 2025. For organisations accustomed to thinking about GDPR-scale penalties, the Act introduces a new tier of financial exposure. Tier 1 violations carry penalties of up to €35 million or 7% of global annual turnover, whichever is higher.
These penalties operate in parallel to UK GDPR enforcement. The ICO retains powers to fine up to £17.5 million or 4% of global turnover for data protection violations. The two regimes do not cancel each other out.
Beyond the financial exposure, regulatory actions are public. An ICO enforcement notice in a professional or financial services context lands differently than a private settlement.
The reputational mathematics are not symmetric: the story of how client data was exposed is always more prominent than the story of how robust governance frameworks were in place.
ISO 27001 for information security and ISO 42001 for AI management systems are rapidly becoming the threshold requirements for enterprise procurement, insurance underwriting, and regulatory good faith.
Organisations certified to ISO 42001 benefit from a presumption of conformity with many AI Act obligations. This has direct relevance to enforcement discretion and penalty mitigation. Gartner estimates that more than 40% of enterprises will experience AI-related data incidents by 2030. The organisations in that 40% are not, in the main, cavalier about data. They are simply ones where the gap between employee behaviour and governance frameworks was not closed in time.
Why the Governance Case Usually Fails — and How to Fix It
Here is the honest diagnosis: most AI governance proposals fail to get funded because they make the wrong argument to the wrong people in the wrong language.
Boards do not fund governance. They fund protection and growth.They look to mitigate risk in the context of the bottom line. If your internal case is built around “we need better controls” or “we need to understand our AI usage profile,” you are describing a cost centre. That is not what gets the budget released.
The cases that get funded are built differently. They follow a logic that connects governance to outcomes the board already cares about.
Step one is identifying a material risk with a money figure attached to it. Not “our AI data controls are weak.” The average UK data breach costs £3.29 million. Shadow AI involvement adds £498,000 to that. If your organisation has 200 employees and 71% of them are using unapproved AI tools, the expected breach exposure is not hypothetical but a quantifiable probability-weighted cost that belongs on a risk register alongside a sterling figure.
Step two is connecting that risk to a business outcome. Outcomes that look like:
- Revenue at risk from a client data breach.
- Contractual liability from a confidentiality failure.
- ICO enforcement action.
- Loss of enterprise procurement eligibility if ISO certification is not achieved.
These are the levers that translate governance into something the CFO can model.
Step three is connecting the risk and the value lever to a specific governance design. This is where most proposals come unstack You need to show not just what the risk is and why it matters, but how a specific control architecture actually prevents the loss.
- Who owns the data classification policy?
- Who approves AI tool procurement?
- Who investigates a policy violation?
- What does the audit trail look like, and to whom is it reported?
Without decision authority mapped to the governance structure, you have a risk report without a control. The board has no reason to fund it.
Step four is decision authority. This is the operating condition that makes speed safe rather than a compliance checkbox that slows everything down. Named owners a defined change approval and documented escalation paths. Without this, governance remains a cost centre. With it, it is a risk management function with a calculable return.
The Practical Starting Point
For most IS and quality managers, the immediate challenge is not knowing the answer it is knowing where to begin.
The most defensible first step is visibility. You cannot govern what you cannot see. An audit of actual AI tool usage across the organisation, including consumer tools used outside IT procurement, is the foundation on which everything else rests. Until you know the shape of the shadow AI problem in your specific environment, you are building governance on estimates.
The second step is technical control at the point of greatest exposure. The moment at which sensitive data crosses the boundary between your organisation and an AI API is the moment at which you lose control of it. A governance layer that intercepts that boundary; a layer inspecting content against data classification policies before it reaches an external model provides both the immediate protection and the audit trail that ISO 42001 and EU AI Act compliance requires.
CattleGrid operates at exactly that boundary. It sits between your applications and the AI providers and applies your organisation’s data policies in real time. Clean requests pass through with negligible latency. Sensitive data is blocked, the employee is notified, and the event is logged. Nothing is written to disc. It is hosted on European infrastructure, outside the scope of the US CLOUD Act which matters for financial services and professional services organisations with client data jurisdiction obligations.
This is not the whole answer. The whole answer requires ISO 27001, ISO 42001, and the executive commitment those programmes demand. The certification pathway runs to nine to twelve months. CattleGrid is what you deploy on the journey a tactical control that limits your exposure whilst the strategic frameworks are built, and that provides the audit evidence those frameworks need.
The Question Worth Putting to Your Leadership This Week
If someone in your organisation experienced a significant AI-related data breach this quarter, could you demonstrate that adequate controls were in place? Could you show an ICO investigator the audit trail? Could you evidence that the organisation had identified the risk, put governance in place, and was working toward the ISO certification baseline?
If the honest answer is no or not yet the gap between where you are and where you need to be is the governance programme that needs funding.
The organisations that close that gap proactively are the ones that avoid making it to a case study.
CattleGrid is accepting a limited number of UK enterprises into its founding access programme. Financial services and professional services organisations of 50 or more employees are prioritised for the first cohort. Founding participants receive preferential terms, direct access to the product team, and a role in shaping the roadmap.
To arrange a briefing or discuss your specific AI governance situation: hello@cattlegrid.uk | cattlegrid.uk/early-access
CattleGrid Ltd is registered in England and Wales. Company Number: 17020793. Statistics cited are drawn from primary sources including IBM Cost of Data Breach Report 2025, Microsoft/Censuswide UK Shadow AI Survey 2025, BlackFog/Sapio Research 2025, Zscaler AI Security Report 2026, and DSIT AI Adoption Research January 2026. Full source list at cattlegrid.uk/whitepaper-sources.

