Large government entity: on-premises deployment, strict ban history
An entity that issued a full ban on AI use for legitimate security reasons: usage continued outside the official framework and the evidence went with it. Now seeking an official alternative that keeps data on-premises and gives the review committee the evidence it asks for.
- Context
- Formal ban decision for security reasons: actual usage continues outside the framework
- Decision
- An official framework easier than shadow use, keeping data on-premises by design
- Deployment home
- On-premises: data does not leave the building
- Stations
- Architecture review, internal security assessment, pilot enablement for one department, first register review, gradual expansion
- What the register writes
- Every conversation with the account identity, every out-of-permission request with its reason, every role change with its named decision
New conversation: planning, within permissions, on-premises
Request outside role scope: stopped at the gate, reason recorded
Illustrative entries, not from a real deployment.
- What do entities like this expect to measure? Did usage through the official framework rise? Does the review committee now have a readable register? Did observed shadow usage decrease?