AI arrived without a plan. Eight things went wrong at once.
Each one is measured. Visibility is where the chain breaks.
The bill you can’t see
AI is now a metered bill. It compounds.
KPMG UK, 2026
Premium by default
People use the most expensive AI for everyday work.
Ramp, 2026
Accounts you don’t own
Company data leaves through personal accounts.
Microsoft UK, 2025 · vendor survey
The same work, twice
Teams build the same thing separately, then redo the output.
HBR, 2025
Skill stuck in individuals
The gains are personal. The business never sees them.
Cornerstone, 2025 · vendor survey
Spend without proof
Money went in on fear. Now someone wants the return.
PwC, 2026
Nothing to show the regulator
The rules already apply. The evidence doesn’t exist.
DSIT Cyber Security Breaches Survey, 2026
The ground keeps moving
Models are retired, re-priced and changed under you. Someone has to decide.
Anthropic model deprecations, 2026
AI does not move accountability. The regulators have now said so, one by one.
UK GDPR and the Data (Use and Access) Act already cover what your AI does with personal data. Sector regulators have gone further: a named person stays accountable for what AI produces. Only 24% of UK businesses using AI have practices that address the risk (DSIT, 2026), and the ICO issued £32.4m of penalties last year.
- Organisations “remain responsible for their use of agentic AI systems”. Clicking approve on an AI ranking without independent analysis is not meaningful human involvement.
- “UK consumer law applies whether decisions are made by people or by AI.”
- “AI has no separate legal personality; solicitors … remain accountable for their work and outputs, regardless of how that work has been prepared.”
- Model risk, including AI and vendor models, sits with a named Senior Management Function holder (SS1/23).
- AI “can enhance, but not replace human decision making”. Providers need accountability procedures for when AI causes harm.
- Auditors remain accountable for work produced with generative and agentic AI.
of organisations have had an AI agent exceed the permissions it was given.
have a named owner for most of their agents.
data protection complaints to the ICO last year, up from 42,315.
New models arrive every few weeks. Old ones are switched off. Someone has to decide.
A handful of companies and governments reshape the AI market month by month. Models are retired with weeks’ notice, change behaviour without a version change, and three vendors hold most of the enterprise market. Today that decision is made by whoever is at the keyboard.
models retired by one leading vendor in six months, on 60 days’ notice.
notice before four models were removed from ChatGPT.
use of the previous model, one month after a new release.
We watch the market, test every relevant release against your jobs in our sandbox, decide where it may and may not be used, set that as the default in the gateway, and manage every change as a controlled event with a way back. Your staff do nothing. How Change Control works
Control belongs with the board, not with whoever is using the tool.
Today, employees decide how and when they use AI. GenWA gives the decision back: what the business uses, what it costs, what it is for, and what it returns.
Usage Insight. Every tool, account, pound and breach, monthly.
The forecast: headcount, roles, and the investment they will need.
AI Strategy and Planning: where it pays, where it must not be used.
Value register and evidence pack: to shareholders, auditors, regulators.
Seven questions most boards can’t answer.
Nothing leaves this page. For the full picture, take the AI health check.
See your own numbers.
Upload your usage export. A first read in your browser now; the full report within 48 hours of your upload.
Start the check