Timing arguments are usually manufactured. This one has three components, and you can check each of them.
Twelve months ago this was harder to assemble. Twelve months from now the habits will have hardened.
Nothing here says the sky is falling. It says that the thing you would have had to build eighteen months ago is now mostly assembly, and that the alternative to deciding is not neutrality. It is an organization quietly standardizing on habits that will be more expensive to move later.
For most of the last few years, using a frontier model meant sending content to the model vendor. The vendor was the host, the account, the logging boundary and the counterparty, and a security review that asked where content went arrived at an answer no customer could govern.
That changed when the frontier labs made their models available through the major cloud providers' managed model services. Inference now runs under the controls of a cloud account your organization already owns and is billed for: your identity policy decides who can call a model, your configuration decides which regions a call may reach, and your audit settings decide what is recorded.
01
The model makers step out of the data path. Each of the three major cloud providers documents, in its own service documentation, that prompts and outputs are not used to train foundation models and are not shared with the third-party model makers whose models it serves. Reviewed against the published documentation on 20 September 2026.
02
The connection can leave the public internet. All three document private network connectivity to the model service, so the request path is a matter of your network configuration rather than an outbound call to a vendor's endpoint. On our posture tiers that is Standard and Strict. How the tiers differ.
03
Policy can be enforced where an application cannot bypass it. Because the model service is reached through cloud identity policy, a content policy can be made mandatory on every inference call as a deny rather than a setting inside an application. What is denied, and how.
What this does not mean
The model does not run inside your network. A managed model service cannot, and any supplier telling you the model sits on your hardware is describing something else. All three providers also document narrow abuse-monitoring or safety processes, so "nothing is ever retained" is not a claim we make. The supportable statements are the two above, plus this one: your data at rest stays in your account. The boundary, defined exactly.
A governed foundation is now assembly, not construction.
LAYER TWO · THE MATURITY SHIFT
The second change is less dramatic and more consequential for what something costs. Two years ago, standing up governed AI meant building identity, retrieval, policy enforcement and model plumbing yourself, then maintaining them while the market moved underneath. Most of that is now a managed building block. What remains is the part that was always the hard part: deciding how they should be configured for one organization, and holding that configuration still.
Component
Used to be
Now
Identity and sign-in
✕Built and maintained per project
✓A managed service, with the user directory in your account
Retrieval over your documents
✕A bespoke pipeline per corpus
✓Managed indexing and retrieval inside your own storage
Content policy on model calls
✕Application code, switchable by whoever owns it
✓A policy object, made mandatory by cloud identity policy
Model access
△One vendor integration at a time
✓One governed gateway over a generated catalogue
Deciding the posture
△A document nobody could enforce
△Still judgment, now committed as configuration that the build checks
Keeping it current
✕Whoever built it, if they are still here
△A deployment factory and a managed-operations subscription
The last two rows are the honest ones: what became cheap is the construction, not the deciding and not the upkeep. That is exactly why the remaining work is worth productizing rather than consulting on. The factory.
The other half of the shift
While governed foundations got cheaper, the approvals for ungoverned tools got harder. Security reviews keep stopping SaaS AI products for the same structural reason: their data flows cannot be scoped to the customer's satisfaction, because the vendor's architecture is not the customer's to configure. An analyst survey of 132 IT leaders found that concerns about data oversharing caused 40% to delay rollouts of a bundled suite copilot by three months or more, and 57% managed the risk by limiting rollout to low-risk or trusted users (Gartner survey, reported by Computerworld, 27 September 2024).
Adoption is outrunning the ability to decide.
LAYER THREE · THE DECISION GAP
The pace of AI innovation is outstripping most organizations' ability to decide, govern and implement. That gap does not stay empty. It gets filled by individual people making individual decisions with consumer tools, which is the definition of shadow adoption, and the research on it is now specific enough to quote rather than gesture at.
01
The official number and the real number differ.
"While only 40% of companies say they purchased an official LLM subscription, workers from over 90% of the companies we surveyed reported regular use of personal AI tools for work tasks." MIT's Project NANDA, "The GenAI Divide: State of AI in Business 2025", July 2025. The report calls its findings preliminary and rests on 52 organizational interviews and 153 survey responses, so read it as a direction rather than a measurement.
MIT NANDAJuly 2025
02
The people running security are doing it too.
80% of employees surveyed said they use unauthorized AI tools, and 68% of security leaders admitted to building unauthorized AI into their daily workflows. UpGuard, 10 November 2025, from surveys of 1,020 employees and 542 security leaders. Vendor-commissioned research, and worth reading precisely because of who answered it.
UpGuardNov 2025
03
Most organizations already suspect it.
69% of organizations suspect or have evidence that employees are using prohibited public generative AI tools, from a survey of 302 cybersecurity leaders conducted March to May 2025. Gartner also predicts that by 2030 more than 40% of enterprises will experience a security or compliance incident linked to unauthorized shadow AI. Gartner press release, 19 November 2025. The second figure is a forecast, not a finding.
GartnerNov 2025
04
And it has a price when it goes wrong.
One in five studied organizations experienced breaches linked to shadow AI, adding as much as USD 670,000 to the average breach cost, and 97% of the organizations reporting AI-related breaches said they lacked proper access controls. IBM, "Cost of a Data Breach Report 2025", summarized 12 November 2025. Vendor research built on breach study data; the access-control finding is the one that should hold your attention.
IBMNov 2025
Four different populations, four different definitions, four different methods. Do not average them into one headline number; read them as four instruments pointing the same way. Every figure here is attributed so you can check it before you repeat it.
What hardens while you decide.
THE COST OF WAITING · 04
Adaptive capacity, not subscriptions
The expensive thing about waiting is what waiting teaches your organization.
A year of unmanaged use is not a year of nothing. It is a year in which people build personal workflows around consumer tools, accumulate private prompt libraries, and keep working copies of company material in accounts you do not administer. None of that is malicious and all of it is harder to move next year than this year.
01
Habits set. The migration cost of a governed environment is mostly the cost of changing where people already go. It rises with every month of the alternative.
02
The shadow corpus grows. Material that left through a browser tab does not come back, and the inventory of what left gets less knowable over time.
03
Capability compounds elsewhere. Peers are learning how to turn this into work that gets done while the organization is still choosing tools. That gap is in learning, not in software bought, which is why buying faster later does not close it.
04
Pilots keep failing the same way. In the MIT NANDA sample, 60% of organizations evaluated enterprise-grade AI tools, 20% reached a pilot and 5% reached production, with brittle workflows and misalignment with daily operations named as the causes. Waiting for the category to settle is not the same as waiting for it to become easy.
Cheaper nowStanding up a governed environment. The building blocks are managed and the deployment is productized
Cheaper nowChanging your mind about a model. It is configuration behind an application layer
Dearer laterMoving people off tools they have already built their week around
Dearer laterReconstructing what material left, and when, without a record of it
UnchangedThe judgment: what to build, what to keep deterministic, and who signs
The asymmetry·Is the argument
The choice is not AI or no AI. It is unmanaged adoption or a governed operating capability.The decision actually on the table
Small, bounded, and yours to keep.
WHAT A FIRST STEP LOOKS LIKE · 05
None of the above argues for a large commitment. It argues for a decision to be taken deliberately rather than by default, and the smallest useful version of that is a bounded piece of work with a document at the end of it.
Read the posture questionnaire before you speak to anyone. It is published so that the residency, retention and control questions arrive in your own time rather than in a sales conversation. Then, if it is worth continuing, the assessment costs $2,500, is bounded, and leaves you holding a topology and data-flow picture of your own environment, a recommended posture with any overrides written down and reasoned, and a shortlist of first capabilities. You keep all of it whether or not you deploy anything. The gate after that is yours.
01Is this not just urgency dressed up as analysis?
Fair challenge, and the test is whether the argument would survive being wrong about timing. It would. If you start in a year, the technical layer will be easier still and the maturity layer cheaper. What will not be cheaper is unwinding a year of habits and locating a year of material. That asymmetry is the whole claim, and it does not depend on anything happening quickly.
02Our people are not using consumer AI. Does this apply?
Possibly not, and the research above is about populations rather than your organization. The cheap way to find out is to ask, in a way that does not punish an honest answer. Most organizations that run that exercise are surprised by the volume rather than the existence of it.
03We tried a pilot and it went nowhere. Why would this differ?
Failed pilots usually fail for structural reasons: no owner, no place to put the thing that was built, and no way to get from a demonstration to something governed. A client-owned environment addresses the second and third directly, because the first capability lands in production infrastructure rather than in a sandbox that has to be recreated later. The first is still yours to solve, and we ask for the names at the assessment. Building it yourself, compared.
04What if the regulatory picture changes?
It will, and the response is architectural rather than predictive. An environment where you hold the account, can pin where inference runs, can show which policy version applied, and can produce records has more answers available to it than one where you ask a vendor for a letter. We would rather be positioned to answer a question that has not been asked yet than to guess which one it will be. Our compliance posture, stated exactly.
⎯⎯ Book the strategic assessment ⎯⎯
Your private AI, inside your control ·
A bounded first step: where governed AI would create value here, what blocks it, and what a deployment would look like in your own environment.