The bank had approved AI. Much of the useful work still sat outside it.
Employees could see how AI might help with document-heavy, repetitive work. Public tools were prohibited for sensitive information, while the approved assistant operated within a deliberately restricted configuration.
The result was a practical gap. Teams still had to gather context from email, meetings, files, and internal procedures before they could draft, review, report, or follow up. National banking requirements added another layer to the bank's own security, confidentiality, and risk policies.

The restriction did not remove the work.
It changed how much of that work people had to carry manually. The opportunity was clearest in workflows where context had to be found, checked, and moved between responsible people.
Find prior correspondence, supporting files, policy references, and approval history before preparing a proposal.
Prepare a grounded first draft from permitted sources, with accountable review before use.
Reconstruct commitments across email, meetings, and documents, then remember when to follow up.
Notice outstanding work, retrieve its context, and prepare the next communication for approval.
Move between internal procedures, working documents, and correspondence to check what applies.
Use selected, approved knowledge to bring relevant policy context into the work.
Collect updates from several teams, reconcile formats, and assemble the same briefing repeatedly.
Prepare a recurring briefing from approved inputs while keeping delivery and sign-off explicit.
When the approved option falls short, the risk moves out of sight.
An employee uploading a client file, contract, financial model, or internal report to an unapproved AI service discloses that information to an external provider. The organization may not have approved the provider, processing location, retention settings, subprocessors, or terms governing that use.
The behavior often begins with a legitimate need: summarize a long document, prepare a response, or find an answer before a deadline. Prohibition alone does not remove that demand. It can push useful AI work beyond the controls the bank can see.
- Provider and account may be unapproved
- Retention and processing terms may be unreviewed
- The bank may have no workflow-level audit trail
- Client confidentiality can cross an unseen boundary
Bring approved AI into the work instead of moving the work into a public tool.
AUGMTD was designed around a different path. The organization defines the permitted sources, processing arrangement, tools, roles, and approval points. Employees can then use connected context without copying sensitive material into a separate consumer workflow.
Security became part of the workflow design.
The relevant question was not whether AI was allowed in the abstract. It was which information a workflow could access, where it could be processed, what the system could prepare, and who remained accountable for the result.
| Control | Personal AI account | Restricted assistant | AUGMTD |
|---|---|---|---|
| Work context | User uploads or pastes it | Limited by license and configuration | Selected connected sources |
| Cross-tool work | User reconnects each step | Depends on enabled Microsoft context | Maintained across supported connections |
| Processing | Personal product terms and settings | Microsoft 365 service boundary | Defined for the customer deployment |
| Consequential action | Outside the bank's workflow | Product and configuration dependent | Reviewable or explicitly configured |
| Visibility | Often unavailable to the bank | Microsoft audit and compliance controls | Visible product activity and operations data |
A useful approved route reduces the pressure behind shadow AI.
The engagement defined how credit preparation, policy review, client follow-through, and management reporting could begin with permitted organizational context, follow an explicit processing arrangement, and return to an accountable person before consequential use. The same operating model applies wherever client files, privileged material, or financial records should not enter unapproved tools.
Customer identity withheld