Six failures. One firm. Five found by Finance.
A European insurer, roughly £3bn gross written premium, approved its first enterprise AI budget in March 2025. In July 2026, the audit committee asked two questions: what AI do we run, and what does it cost? Neither could be answered. This is the reconstruction, in six parts. The firm is a composite and is not identifiable.
The budget was approved as a project and consumed as a utility
£24m was approved across eighteen months against a case built on pilot volumes. Consumption was not in the case because, at pilot scale, it was rounding. By month fourteen, inference and orchestration ran at £6.1m annualised against a £1.4m forecast, split across three cost centres, none of which owned the total.
A fixed approval against a variable cost removes the re-approval point. Nothing breached a threshold, because no threshold was written in the units the spend was incurred in.
What is our AI run-rate this month, and which single person is accountable for that number?
A Chief AI Officer was appointed, and no authority moved
Created in January 2026, reporting to the COO, with convening rights and no decision rights. In six months, it chaired eleven meetings and took no decision a business unit could not overturn. Asked who owned AI, four functions named the Chief AI Officer; the Chief AI Officer named the business units.
An owner without authority absorbs the question without resolving it. The appointment closed the item on the board tracker, removing the pressure that would have surfaced the gap a year earlier.
What can our AI owner decide alone, and when did they last decide it?
412 agents, 37 with a named owner
A discovery exercise in June returned 412 agents across four platforms. Thirty-seven had an identifiable owner. Ninety-one ran on credentials of people who had left or changed roles. Fourteen had no purpose anyone could describe.
A discovery tool bought eight months earlier had produced the list. Nobody was accountable for it, so it circulated and went unacted on until an external question forced action.
How many of our agents run on the credentials of someone who has left?
The approved tool took six weeks to get, and the unapproved one took ninety seconds
An internal survey found 58% of knowledge staff using tools outside the sanctioned list. The reason was not preference but latency: the approved assistant took a manager request, a security review, and a licence allocation, averaging six weeks. Staff used consumer tools in the interim.
This was a provisioning failure, not a culture failure. Three awareness campaigns ran; the six weeks did not shorten. The behaviour persisted, and the campaigns became evidence that staff had been told.
How long does it take an employee to get the approved tool, and how long does the alternative take?
Three of four tier-one vendors could change a model without telling anyone
A review of the four largest suppliers found three held platform-modification rights broad enough to swap an underlying model with no change request and no notification duty. One already had: a document-classification component became model-driven in a routine release, and the firm read about it in a release note eleven weeks later.
Third-party assessments were re-performed annually against the original service description. The service changed materially inside the cycle, and nothing was designed to notice.
Which of our tier-one contracts oblige the supplier to tell us when a model changes?
The most capable agent in the firm was built by someone with no mandate to build it
A senior claims handler built an agent that triaged the complaints queue and drafted responses. It was measurably better than the process it replaced. It also held her access: full complaints history and the ability to send externally. After four months it was, by the firm's own assessment, its best AI deployment.
It could not be switched off without service impact and could not be defended as built. That is the position to avoid: a choice between an unacceptable control gap and an unacceptable operational one, because no gate sat on her path.
If we found a valuable agent we could not defend tomorrow, what would we do with it?
37 with an owner
Against £1.4m forecast
board questions
by Finance
Five of the six were surfaced by Finance, chasing a variance. None was surfaced by the risk function, the AI programme, or the discovery tool bought to surface exactly this. That is not a criticism of Risk. It is a statement about where the signal lives: consumption billing is the only system that sees every agent, tool, and model, because everything that runs has to be paid for. A board wanting an honest AI inventory before Christmas should ask Finance.
Against the dashboard published in Issue 02 on 1 September, as revised by Decision Signals on 8 September.
Shadow AI rises because provisioning latency, not policy, is the driver, and nobody has shortened it. Run-rate visibility enters because it found five of these six.
The classification rule and the third-party register are unchanged since Issue 01. Both now have a worked case attached. Both remain unowned.
The case is an anonymised composite from advisory practice; figures are illustrative and not attributable to a named firm. Calibrated against: Cloud Security Alliance, April 2026 (82% discovered unknown agents; 21% with a decommissioning process; 15% with defined ownership for most agents). KPMG Global AI Pulse Q2 2026 (49% scaled back agents on cost; 26% with real-time AI cost visibility). Nokod Security, April 2026 (citizen builders outnumber developers 4:1). Okta, March 2026 (52% use unsanctioned AI tools). Verizon DBIR 2026; PagerDuty Shadow AI Survey 2026; FSB, October 2025, on model supply concentration. Third-party figures are reported as published and have not been independently verified.
Regulatory Radar, 22 September. Issue 03, 6 October.