MJB Consulting
AI Exposure Diagnostic

AI governance is a hot topic right now but it's a growth question, not just a risk one

AI is accelerating growth in every business willing to use it. It's also introducing exposure most leadership teams haven't measured yet, and investors are starting to ask about.

Two questions about AI being asked the most

Question one

Is AI actually delivering the growth and return we expected?

Question two

Are we fully aware of the exposure it's introducing along the way?

Most businesses can answer the first with confidence. Very few can answer the second.

The gap, measured

43%
of breached organisations experienced an incident involving Shadow AI this year, more than double last year's 20 percent.

68 percent of the businesses breached had no policy in place to manage AI use at all, and 92 percent of those hit by an AI related breach lacked basic access controls. This isn't about AI being dangerous, it's about AI adoption running well ahead of governance.

SOURCE: IBM COST OF A DATA BREACH REPORT, 2026, WITH THE PONEMON INSTITUTE

Regulation is catching up

The EU AI Act's requirement for staff AI literacy comes into force from August 2026, and financial services regulators are increasingly treating AI oversight as an extension of existing risk and compliance obligations, not a separate, optional concern.

What this looks like when it goes wrong

Air Canada

A tribunal held the airline liable after its website chatbot invented a bereavement fare discount policy that didn't exist. Air Canada argued the chatbot was a separate legal actor responsible for its own statements, an argument the tribunal rejected outright. Whatever your AI says to a customer, the business owns it.

Samsung

Engineers accidentally leaked confidential source code and internal meeting notes by pasting them into ChatGPT prompts. No attack, no malice, just employees trying to work faster with a tool nobody had assessed, the exact human behaviour behind Shadow AI.

What the diagnostic actually gives you

Discovery

Built from direct conversations across a cross section of the team, not leadership's view alone. Combined with a review of relevant controls, policies and records in existence.

Scoring

A repeatable, risk based methodology across multiple dimensions, including Acceptance, Resilience, and Governance, combined into a single benchmark score and rating. Simple enough to explain in a boardroom, and simple enough to re-run later to track genuine movement.

Dashboard

A one-page executive leave behind, the score and findings at a glance, the highest priority risks named clearly, and a roadmap of short, medium and long term actions built to move the score forward.

Fifteen minutes is usually enough to know if there's a genuine fit.

BOOK A CONVERSATION โ†’