Customer evidenceFIELD STUDY · PRIVATE AI
    A regulated bank · North Africa

    How a regulated bank created a safer alternative to shadow AI

    Sensitive client work could not be shared with public AI tools. The bank needed an approved option useful enough for real workflows and controlled enough for regulated work.

    Processing
    Defined
    Knowledge
    Selected
    Actions
    Reviewed
    Usage
    Visible
    01 · THE CONSTRAINT

    The bank had approved AI. Much of the useful work still sat outside it.

    Employees could see how AI might help with document-heavy, repetitive work. Public tools were prohibited for sensitive information, while the approved assistant operated within a deliberately restricted configuration.

    The result was a practical gap. Teams still had to gather context from email, meetings, files, and internal procedures before they could draft, review, report, or follow up. National banking requirements added another layer to the bank's own security, confidentiality, and risk policies.

    Microsoft Copilot
    APPROVED · RESTRICTED CONFIGURATIONMicrosoft 365 CopilotAvailable inside the bank's environment, with customer-specific limits on what it could access and do.
    UTILITY GAP
    ChatGPTPersonal accountPROHIBITED FOR SENSITIVE WORK
    ClaudeConsumer accountPROHIBITED FOR SENSITIVE WORK
    GeminiPersonal accountPROHIBITED FOR SENSITIVE WORK
    02 · REAL WORK

    The restriction did not remove the work.

    It changed how much of that work people had to carry manually. The opportunity was clearest in workflows where context had to be found, checked, and moved between responsible people.

    Credit preparation
    OutlookExcelOneDriveWord
    WITHOUT A USEFUL APPROVED TOOL

    Find prior correspondence, supporting files, policy references, and approval history before preparing a proposal.

    WITH AUGMTD

    Prepare a grounded first draft from permitted sources, with accountable review before use.

    Client follow-through
    OutlookWord
    WITHOUT A USEFUL APPROVED TOOL

    Reconstruct commitments across email, meetings, and documents, then remember when to follow up.

    WITH AUGMTD

    Notice outstanding work, retrieve its context, and prepare the next communication for approval.

    Policy-sensitive review
    OneDriveWordOutlook
    WITHOUT A USEFUL APPROVED TOOL

    Move between internal procedures, working documents, and correspondence to check what applies.

    WITH AUGMTD

    Use selected, approved knowledge to bring relevant policy context into the work.

    Management reporting
    ExcelOutlookWord
    WITHOUT A USEFUL APPROVED TOOL

    Collect updates from several teams, reconcile formats, and assemble the same briefing repeatedly.

    WITH AUGMTD

    Prepare a recurring briefing from approved inputs while keeping delivery and sign-off explicit.

    03 · SHADOW AI

    When the approved option falls short, the risk moves out of sight.

    An employee uploading a client file, contract, financial model, or internal report to an unapproved AI service discloses that information to an external provider. The organization may not have approved the provider, processing location, retention settings, subprocessors, or terms governing that use.

    The behavior often begins with a legitimate need: summarize a long document, prepare a response, or find an answer before a deadline. Prohibition alone does not remove that demand. It can push useful AI work beyond the controls the bank can see.

    CLIENT FILE · POLICY · FINANCIAL MODEL
    ChatGPT
    Claude
    Gemini
    • Provider and account may be unapproved
    • Retention and processing terms may be unreviewed
    • The bank may have no workflow-level audit trail
    • Client confidentiality can cross an unseen boundary
    04 · THE OPERATING MODEL

    Bring approved AI into the work instead of moving the work into a public tool.

    AUGMTD was designed around a different path. The organization defines the permitted sources, processing arrangement, tools, roles, and approval points. Employees can then use connected context without copying sensitive material into a separate consumer workflow.

    Approved sourcesSelected accounts, documents, and knowledge
    Defined processingConfiguration matched to the deployment
    Accountable actionPrepared work reviewed by the right person
    PERSONAL AI PATH
    Employee finds a fileUploads it manuallyExternal account processes itBank may not see the interaction
    CONTROLLED WORK PATH
    Approved source produces a signalPermitted context is retrievedWork is prepared within the configurationResponsible person reviews it
    05 · THE CONTROL BOUNDARY

    Security became part of the workflow design.

    The relevant question was not whether AI was allowed in the abstract. It was which information a workflow could access, where it could be processed, what the system could prepare, and who remained accountable for the result.

    1Selected contextOnly approved sources enter the workflow
    2Defined boundaryProcessing follows the chosen deployment
    3Scoped capabilityTools and knowledge match the role
    4Human controlConsequential work stays reviewable
    ControlPersonal AI accountRestricted assistantAUGMTD
    Work contextUser uploads or pastes itLimited by license and configurationSelected connected sources
    Cross-tool workUser reconnects each stepDepends on enabled Microsoft contextMaintained across supported connections
    ProcessingPersonal product terms and settingsMicrosoft 365 service boundaryDefined for the customer deployment
    Consequential actionOutside the bank's workflowProduct and configuration dependentReviewable or explicitly configured
    VisibilityOften unavailable to the bankMicrosoft audit and compliance controlsVisible product activity and operations data
    06 · THE PRACTICAL OUTCOME

    A useful approved route reduces the pressure behind shadow AI.

    The engagement defined how credit preparation, policy review, client follow-through, and management reporting could begin with permitted organizational context, follow an explicit processing arrangement, and return to an accountable person before consequential use. The same operating model applies wherever client files, privileged material, or financial records should not enter unapproved tools.

    Customer identity withheld
    DEPLOYMENT PATHSKeep the AI route inside an approved boundary.
    Customer environmentOn-premise model endpoint
    OR
    Dedicated private cloudConfigured provider and region
    A
    AUGMTD software layerPrivate chat · coworkers · workflows · documents
    Public consumer AIOutside the approved work path
    The architecture, provider, processing region, and control boundary are configured for each deployment.
    MAKE APPROVED AI USEFUL

    Find the workflows driving shadow AI in your organization.

    Discuss a private AI pilot