RB-003 High
Mass adoption of unsanctioned AI tool (> 50 users)
DET-MS-SEN-003 (or platform equivalent) fires for an unsanctioned AI service exceeding the program's user-count threshold. Also triggered by DET-MS-MCAS-001 / -MANUAL-001 surfacing a new viral app.
Triggers
Immediate response (first hours)
- AI Governance triage: Confirm the detection. Pull user / department breakdown. Identify what business need the tool is serving (often a productivity workflow not yet covered by sanctioned tools).
- AI Governance lead: Convene rapid-review with Security and the affected business unit(s). Goal: decide within 5 business days whether to: (a) fast-track sanction, (b) block with comms, (c) interim pilot, or (d) parallel sanctioned alternative.
Short-term response (within days)
- AI Governance triage: Execute the decision: update sanction status in Defender for Cloud Apps / SWG; update inventory in Governance Toolkit; issue org-wide comms (comms/department-level-briefing). (Within 10 business days)
- Procurement + Legal: If sanctioning: initiate vendor due diligence using the Vendor Questionnaire (AI Governance Toolkit). Capture risk-tier decision before contract finalization. (Within 30 days)
- AI Governance triage: Stand up an approved-tool pilot for the underlying need (if no sanctioned alternative exists). Migrate users from unsanctioned to sanctioned path.
Long-term response (weeks+)
- AI Governance Committee: Post-mortem: how did this become viral without earlier detection? Adjust monitoring thresholds / sanctioning cadence accordingly.
- AI Governance triage (quarterly): Track migration completion. Goal: < 10% of original user base still on unsanctioned tool 90 days post-decision.
Decision tree
- Does the tool serve a genuine business need not currently covered?
- Yes → Fast-track sanction or stand up approved alternative.
- No → Block with comms; redirect to existing sanctioned tools.
- Is there an enterprise-tier offering with acceptable data terms?
- Yes → Sanction the enterprise tier; communicate migration path.
- No → Block consumer use; consider whether to pursue a custom contract or alternative vendor.
RACI
- Responsible: AI Governance triage lead
- Accountable: AI Governance lead
- Consulted: Affected business unit head, Procurement, Legal, Security architecture
- Informed: AI Governance Committee, CISO
Metrics to capture
- Time from detection to decision (target: ≤ 5 business days)
- Time from decision to action (target: ≤ 10 business days)
- User migration rate at 30 / 60 / 90 days
- Number of fast-tracked sanctions per quarter (trend signal — high rate may indicate program-level coverage gaps)
Comms templates
comms-department-level-briefingcomms-approved-tool-announcementcomms-mass-adoption-program-update
Framework mappings
- NIST AI RMF: GOVERN-4.1, MANAGE-2.2, MANAGE-4.1
- ISO/IEC 42001: 8.2, 8.4, 10.2
- NIST CSF: DE.AE-2, RS.AN-1