Zero leakage data fencing and shadow AI elimination
A risk first playbook for AI pilots in regulated financial services.
Most firms do not have an AI governance problem — they have an honour system. This paper sets out a practical architecture for stopping regulated data escaping into unapproved tools, removing the incentive for shadow AI, and protecting the AI budget as pricing based on consumption arrives.
Financial services · CX and AI advisoryJuly 20268 sections7 min read
Route every interaction through one governed gateway.
Most financial services firms do not have an AI governance problem. They have an honour system — staff trusted to choose the right model, paste the right data and exercise the right judgement, with a policy PDF as the only safety net.
Why the honour system fails
That approach survived the pilot phase because pilots are small. It will not survive scale, pricing based on consumption, or a regulator that has made individual accountability the centrepiece of its supervision.
Two connected disciplines
This paper sets out a practical architecture for zero leakage data fencing, which stops regulated data escaping into unapproved AI tools, and shadow AI elimination, which removes the incentive for staff to use those tools in the first place.
It also explains why the same control layer that closes the compliance gap is the one that protects the AI budget when subsidised pricing for each seat gives way to billing metered by usage.
Three problems usually treated separately become one problem with one fix.
FORTAY CONNECT
02The honour system is not a control framework
The honour system is not a control framework.
Ask a compliance lead how their firm governs AI usage and the honest answer, more often than not, is encouragement.
Encouragement is not a control
Staff are encouraged to use the approved tool. Encouraged to select the cheaper model. Encouraged not to paste client data into a public chatbot. Encouragement is culture, and culture matters — but it is not a control. No firm would run payments, trading access or data loss prevention on encouragement, yet that is precisely how most AI estates operate in 2026.
The pilot succeeded, the governance never started
The pattern is consistent. An AI tool is rolled out, usually to engineering first, and adoption spreads sideways. Within months the firm has enthusiastic usage, genuine productivity gains and almost no visibility of what is being asked, what data is leaving, which models are being used or what any of it costs.
If your model selection policy is a request that users pick the cheaper option, you do not have a policy. You have a suggestion.
FORTAY CONNECT
03Shadow AI: the risk you already have
Shadow AI: the risk you already have.
Shadow AI is any AI usage outside sanctioned tools and monitored channels — the analyst summarising a portfolio in a free chatbot, the developer pasting proprietary code into a browser extension, the team lead using an unapproved transcription service because the sanctioned route was slower.
01The data gravity is severe
Client identities, positions, transaction histories and complaint records are exactly the material staff want summarised, drafted around and analysed — and exactly the material that must never leave a governed boundary.
02The blast radius is regulatory, not just reputational
A leak into a consumer AI tool is a data protection event, a potential conduct event and a record keeping failure at the same time.
03Prohibition does not work
Firms that ban AI outright do not eliminate usage; they push it onto personal devices and accounts, where visibility drops to zero. Shadow AI is not a discipline problem — it is a product problem: staff route around sanctioned tools when sanctioned tools are worse.
04The regulatory position
No new rules is not no rules.
The FCA has been explicit that it will not write a bespoke AI rulebook. That has been widely misread as breathing room. It is the opposite — the regulator is applying frameworks already in force: the Consumer Duty, SM&CR, and its existing expectations on governance, systems and controls.
01Individual accountability is the enforcement mechanism
Under SM&CR, responsibility for AI systems attaches to named senior managers. When a process driven by AI produces a poor outcome, the question will not be which system failed but which senior manager owned it and what evidence of oversight exists.
02The black box defence is dead
A firm cannot discharge its obligations by pointing at a model it cannot explain. The FCA has signalled that good and poor practice on explainability, audit trails and human oversight will be published later in 2026. Firms deploying AI without decision logs are building tomorrow's enforcement exhibits.
03Data protection law has hardened underneath
The automated decision making provisions of the Data (Use and Access) Act 2025 have been in force since February 2026, sitting alongside UK GDPR. Supervisory expectations stack on top of these obligations, not in place of them.
05Zero leakage data fencing
The five properties of a real data fence.
Data fencing is often sold as a product. It is better understood as an architectural decision: no AI interaction happens except through a governed gateway the firm controls. Everything else follows from that single choice.
01One front door
Every prompt, from every user and application, passes through a single gateway. Direct access to public endpoints is blocked at the network level. If there are two routes to a model, one of them is a leak.
02Classification before transmission
Data is classified and screened at the gateway, before it leaves the boundary. Client identifiers and material nonpublic information are detected and redacted, tokenised or blocked automatically — not by asking the user to check.
03Model allowlisting
Only approved models, on approved terms, with approved data handling, are reachable. Zero data retention and UK or EU residency stop being aspirations in a policy and become properties enforced in the pipe.
04Full decision logging
Every prompt, response, model choice and routing decision is logged and retained. This turns AI usage from an unauditable behaviour into a supervisable activity — the audit trail the regulator increasingly expects.
05Egress symmetry
Outputs are screened as well as inputs. A model fed sensitive context can reproduce it somewhere it should not go. The fence works in both directions or it is not a fence.
06Shadow AI elimination
Starve shadow AI — do not chase it.
Firms usually attack shadow AI with detection: scanning traffic, blocking domains, disciplining offenders. Detection is necessary but it is the smaller half of the answer. Shadow AI persists wherever the sanctioned route is slower, weaker or more annoying. Eliminate that gap and shadow usage collapses on its own.
01Move one: discover honestly
Map actual AI usage across the firm, including the embarrassing parts, before designing the sanctioned estate. The tools staff are sneaking are a free requirements document.
02Move two: make the sanctioned route the best route
Give users faster access to better models through the governed gateway than they could get on a personal account. When the compliant option is also the superior option, enforcement becomes almost incidental.
03Move three: close the side doors
With a credible sanctioned route live, block direct access to public endpoints on corporate devices and networks. Blocking without an alternative breeds workarounds; blocking after a better alternative exists finishes the job.
07The gateway pays for itself
The same gateway pays for itself.
There is a second reason to build the governed gateway now, and it has nothing to do with compliance. The commercial model underneath enterprise AI is shifting from subsidised licensing for each seat towards billing metered by consumption and tokens.
Firms budgeted for licences, they will be billed for usage
And usage is exploding: agentic workflows can consume many multiples of the tokens of a simple chat interaction. The FinOps Foundation's State of FinOps 2026 found 73 per cent of enterprises reported AI costs exceeding their original projections, and AI cost management is now the single most sought after skill among technology spend teams. Falling token prices have not helped, because volume is growing faster than prices are falling.
The dominant cause is architectural
Most estates default every query, however trivial, to the largest frontier model available. Summarising a paragraph does not need the same machinery as multistep reasoning over a regulatory filing, yet both are routinely priced identically because nothing in the estate distinguishes them.
Governance and cost control are usually pitched as competing priorities. Route everything through one gateway and they become the same project.
FORTAY CONNECT
08What good looks like
What good looks like: a ninety day path.
None of this requires a transformation programme. The firms doing it well treat it as a focused engineering and governance exercise.
01Days 1 to 30: discovery and design
Map real AI usage, classify the data flows involved, and agree the model allowlist, data handling terms and routing policy, with risk and compliance at the table from day one.
02Days 31 to 60: build the fence
Stand up the gateway, wire in classification, redaction and logging, and connect the approved models. Migrate the highest volume use case first to prove the experience is better, not just safer.
03Days 61 to 90: eliminate and optimise
Close direct endpoint access, switch on intelligent routing, and hand risk a live dashboard: what is asked, what data was fenced, which models answered, and what it cost.