As the organisation embraced new digital tools, its AI landscape grew faster than anyone expected. What began as a handful of helpful applications soon expanded into a complex mix of platforms, agents, data flows and user behaviours. With cyber teams stretched and governance slipping between the cracks, the estate needed someone who could bring clarity, structure and safety to an environment that was becoming increasingly difficult to manage.
That responsibility fell to me.

The first step was establishing control. AI tools were appearing across the organisation, some declared, some not, and a few purchased without any governance review at all. One shadow AI tool had even been deployed directly into the business development workflow, touching sensitive information without oversight. Rather than escalate panic, I quietly enrolled it into SSO, locked it down and brought it under governance before any risk could materialise.
With the estate stabilised, I turned my attention to people. AI only works when people understand it, trust it and feel confident using it. Over the following months, more than five hundred staff attended my training sessions. I ran eight full workshops, each two hours long, followed by more than fifty drop‑in sessions and countless one‑to‑one conversations. The aim was simple: make AI understandable. Not hype, not fear, not “AI is safe, don’t worry,” but real clarity. I taught the basics, explained AI security, and reframed AI as a helper rather than a threat.
One moment stood out. A staff member who spent two weeks every cycle combining sensitive statistics in Excel joined a session. I showed her how to create a OneDrive link, paste it into Copilot and use prompt engineering to guide the output. Copilot completed her two‑week task in seconds. She cried — not because of the technology, but because the burden she had carried for years finally lifted.
As confidence grew, so did innovation. Together with a few enthusiastic early adopters, we co‑developed chatbots, automations and even a frontline AI recording and case‑support tool. That assistant alone returned thirty‑six percent of frontline time back to staff, giving them more space to focus on the people they support.

But governance remained essential. When Agent365 launched, it arrived with one hundred and fifty‑seven agents all set to “Everybody,” creating a serious exposure risk. I audited every agent, rebuilt the access model and enforced least‑privileged defaults so new agents were safe from the moment they were created. The portal went from risky to reliable.
The biggest challenge came from the estate’s legacy content. More than four million files were untagged, unclassified and invisible to DLP. Without classification, governance couldn’t function. I deployed DLP AI auto‑classification across the entire estate, marking all four million files as organisational. Overnight, DLP became fit for purpose, Purview gained visibility and Copilot could finally respect sensitivity boundaries.
From there, the system matured. I continued deploying recommended policies, monitoring the platform and keeping pace with NIST guidance. By the time the estate settled into Business as Usual, the entire environment was effectively ISO 42001‑ready — the only missing piece was documentation, a natural challenge when one person is doing the work of an entire governance team.
With auditing in place, visibility improved. We could see who did what, when and from where. The system tuned itself further, safeguarding strengthened and the organisation’s young people were fully protected across every AI‑enabled workflow.

What began as a scattered collection of tools and risks became a safe, structured and friendly AI environment. Staff felt confident, frontline teams gained time back, governance held firm and the organisation could move forward knowing its digital estate was secure, understandable and ready for the future.
