AI Usage Evidence Pack
Sample Institution (fictional)
Dubai, UAE
Contents
- Executive summary 2
- Scope and method 3
- AI application inventory 4
- Account split 5
- Sensitive data events 6
- Agents and MCP servers 7
- Policy decisions 8
- Exceptions and approvals 9
- Regulator clause map, UAE 10
- Regulator clause map, Saudi Arabia and international 11
- Signed export attestation 12
Executive summary
This pack records how staff at Sample Institution (fictional) used AI tools from 01 Jul to 30 Sep 2026. It also records the controls that applied. All figures are sample data.
Findings
- AI use is wide and mostly outside approved tools. Staff used 63 AI apps. Only 3 are sanctioned. 42 are unsanctioned, including 2 unlisted LLM endpoints found by behaviour (page 4).
- Personal accounts are common. 41 of 63 apps had sessions from personal accounts. Marketing and Human Resources had the highest share (page 5).
- Regulated data left through personal and unsanctioned paths. 212 prompts carried regulated data to an unsanctioned app or a personal account. Customer PII (64), source code (42) and Emirates ID (38) led (page 6).
- Agents can change systems. 9 agents and MCP servers run on staff endpoints. 4 have write access. 2 had no named owner at discovery (page 7).
- Coaching works. SentraGuard logged 20,049 decisions: 18,402 allow, 1,207 coach, 388 redact and 52 block. Weekly coach events peaked at 190 in week 2 and fell to 47 in week 13 (page 8).
Controls now stop the most sensitive data classes. Personal-account use and write-capable agents keep the rating above Moderate.
Recommendations
- Move personal-account use of ChatGPT, Gemini and Claude to ChatGPT Enterprise and Microsoft 365 Copilot. Set Coach for 30 days, then Block for personal accounts on these apps.
- Put the 4 write-capable agents under tool-call policy. Give each one a named owner, an approver and an expiry date.
- Turn on Redact for Emirates ID, IBAN and card number on all tolerated apps. Keep Block for regulated data on unsanctioned apps.
Scope and method
Who and what was in scope
- Users 2,140 protected users in 8 business units.
- Period 01 Jul to 30 Sep 2026, 13 weeks. Times are Gulf Standard Time (UTC+4).
- Identity Users and groups come from the institution's SSO. Group membership syncs by SCIM. Every event carries a user, a role and a business unit.
- Deployment On premise. No data was sent to SOAISEC. App dictionary updates arrived as signed bundles.
Surfaces
- Browser Plugin for Chrome and Edge, pushed by Intune to all 2,140 users.
- IDE Extensions for VS Code and Cursor in Technology.
- Endpoint Agent on Windows, macOS and Linux in Technology, Treasury and Retail Banking. It sees desktop AI apps, CLI coding agents, local models and MCP servers.
Business units
| Business unit | Users | Surfaces |
|---|---|---|
| Retail Banking | 620 | Browser |
| Corporate Banking | 310 | Browser |
| Treasury | 95 | Browser, endpoint |
| Operations | 385 | Browser |
| Technology | 290 | Browser, IDE, endpoint |
| Risk and Compliance | 160 | Browser |
| Human Resources | 90 | Browser |
| Marketing | 190 | Browser |
| Total | 2,140 |
Pilot week and timeline
Method
SentraGuard matches traffic against its app dictionary. It flags unknown LLM endpoints by behaviour. It compares the signed-in account with the SSO identity to split corporate and personal use. It inspects three lanes: prompt, paste and upload. Each inspected event gets one decision: Allow, Coach, Redact or Block.
Out of scope. Mobile devices. A one-week pilot pack uses the same structure for one business unit.
AI application inventory
63 AI apps were used in the period. This page lists the 15 with the highest risk or use. The CSV export lists all 63.
| App | Class | Users | Sessions | Personal account | Data-policy note |
|---|---|---|---|---|---|
| Microsoft 365 Copilot | Sanctioned | 1,380 | 2,940 | 0% | Enterprise agreement. Reviewed by Procurement and DPO. |
| ChatGPT (consumer) | Unsanctioned | 612 | 1,870 | 100% | Consumer terms. Not reviewed. |
| ChatGPT Enterprise | Sanctioned | 240 | 1,210 | 0% | Enterprise workspace. Reviewed. |
| GitHub Copilot | Sanctioned | 146 | 1,120 | 6% | Business plan. Personal GitHub accounts seen. |
| Gemini | Tolerated | 388 | 960 | 71% | Mixed accounts. Data location not confirmed. |
| Grammarly | Tolerated | 322 | 780 | 64% | Browser extension. Vendor review pending. |
| Claude | Tolerated | 205 | 640 | 83% | Mostly personal accounts. Vendor review pending. |
| Cursor | Tolerated | 38 | 420 | 45% | Covered by exception EX-02. |
| Perplexity | Tolerated | 176 | 410 | 92% | Covered by exception EX-01. |
| Notion AI | Tolerated | 118 | 305 | 58% | Workspace AI add-on. Vendor review pending. |
| Canva AI | Tolerated | 97 | 210 | 77% | Covered by exception EX-03. |
| DeepSeek | Unsanctioned | 64 | 190 | 100% | Consumer terms. Data location outside the UAE. |
| Otter.ai | Unsanctioned | 41 | 96 | 100% | Meeting audio upload. Exception EX-04 for one series. |
| Unlisted LLM endpoint A | Unsanctioned | 9 | 58 | n/a | Detected by behaviour. Unknown operator. |
| Unlisted LLM endpoint B | Unsanctioned | 4 | 22 | n/a | Detected by behaviour. Self-hosted proxy. |
Figure 1. Sessions per app, 01 Jul to 30 Sep 2026. Sample data.
Account split: corporate and personal
41 of 63 AI apps had at least one session from a personal account.
A personal-account session is one where the account signed in to the AI app does not match the user's SSO identity. Data sent this way sits outside the institution's contracts, retention rules and audit trail.
Figure 2. Users per unit in brackets. Sample data.
What the split shows
- Marketing, 58% Staff use personal accounts for design and copy tools. Canva AI and ChatGPT lead.
- Human Resources, 47% Staff use personal accounts for meeting notes and letters. This includes candidate data.
- Risk and Compliance, 12% Most use goes through Microsoft 365 Copilot.
- Largest gap in volume Retail Banking and Operations have the most users with personal-account sessions.
Sensitive data events
212 prompts carried regulated data to an unsanctioned app or a personal account.
SentraGuard inspects three lanes: typed prompts, pastes from the clipboard, and file uploads. Each event below also appears in the policy decision log with its timestamp, user and action.
Figure 3. Prompts with regulated data, 01 Jul to 30 Sep 2026. Sample data.
| Data class | Prompt | Paste | Upload | Total |
|---|---|---|---|---|
| Emirates ID | 14 | 12 | 12 | 38 |
| IBAN | 12 | 15 | 4 | 31 |
| Card number (PAN) | 7 | 9 | 1 | 17 |
| Customer PII | 30 | 20 | 14 | 64 |
| Source code | 20 | 19 | 3 | 42 |
| API keys and secrets | 14 | 6 | 0 | 20 |
| Total | 97 | 81 | 34 | 212 |
| Action taken | Events |
|---|---|
| Allow (pilot days 0 to 2) | 24 |
| Coach | 55 |
| Redact | 99 |
| Block | 34 |
| Total | 212 |
24 events were allowed and logged on pilot days 0 to 2, before Coach, Redact and Block went live. From day 5, regulated data to unsanctioned apps was blocked.
Counting rule. One prompt counts once, under its most sensitive data class. Redact and block counts on page 8 cover all apps, including sanctioned ones, so they are higher.
Agents and MCP servers
9 agents and MCP servers were found. 4 have write access.
The endpoint agent and IDE extensions list each agent, the tools and MCP servers it can call, and the data those tools reach. Agent tool calls get the same four actions as prompts: Allow, Coach, Redact and Block.
| Agent or server | Owner group | Runtime | Tools or MCP reachable | Data reachable | Permission | Finding |
|---|---|---|---|---|---|---|
| Claude Code (CLI agent) | Technology, Payments squad | macOS endpoint | Shell, file edit, git; GitHub MCP server | Payments source repos | Write | Uses a personal API key. Move to a corporate key. |
| Cursor agent mode | Technology, Mobile squad | IDE (Cursor) | Terminal, file edit | Mobile app source code | Write | Covered by EX-02. Secrets redacted. |
| MCP server: Jira | Technology, PMO | macOS endpoint | Create and update issues | Internal tickets | Write | No named owner at discovery. Owner now assigned. |
| MCP server: email (IMAP/SMTP) | Retail Banking, Service | Windows endpoint | Read mail, send mail | Customer service mailbox | Write | Can send mail outside the domain. EX-06 under review. |
| MCP server: filesystem | Operations, Analytics | Linux endpoint | Read files | Shared drive with customer exports | Read | Reaches files with customer PII. Scope reduced. |
| MCP server: Postgres | Risk and Compliance | Linux endpoint | SQL query | Credit risk reporting replica | Read | Read-only account. Covered by EX-05. |
| Custom Python agent | Corporate Banking, Innovation | Linux VM | Web search, internal product API | Product documents | Read | No named owner at discovery. Owner now assigned. |
| Ollama (local model) | Treasury, Quant team | macOS endpoint | None | Local files loaded by user | Read | Local model not in the asset register. Added. |
| LM Studio (local model) | Marketing | macOS endpoint | None | Local files loaded by user | Read | Local model not in the asset register. Added. |
Actions taken in the period
- Owners Every agent now has a named owner group.
- Write tools Tool calls that write or send now run under Coach. Calls that send regulated data outside the domain are blocked.
- Register Both local models were added to the asset register.
Policy decisions
SentraGuard logged 20,049 policy decisions in the period.
Figure 4. Two scales: Allow on the top panel, the other actions below. Sample data.
Coach to sanctioned path
Coach shows a banner that points the user to the approved app. Coach events peaked at 190 in week 2, the first full week with Coach live. They fell to 47 in week 13, a fall of 75%. Allow volume stayed level over the same weeks. This shows that users moved to sanctioned apps and did not stop using AI.
Redact and Block
Redact removed the identifier and let the prompt continue. Most redactions were IBAN and Emirates ID in tolerated apps. Block stopped 52 events. All 52 were regulated data sent to unsanctioned apps or through write-capable agent tools.
Each decision in the log has a timestamp, user, role, business unit, app, account type, lane, data class and action. The log streams to the institution's SIEM (Microsoft Sentinel in this sample).
Exceptions and approvals register
6 exceptions were in force at the end of the period.
An exception lets a named group use an app or tool outside its default class. Each exception has a scope, a reason, an approver and an expiry date. SentraGuard applies the exception by user group and returns to the default policy on expiry.
| Id | Requester group | App or tool | Scope | Reason | Approver role | Expiry | Status |
|---|---|---|---|---|---|---|---|
| EX-01 | Treasury research (6 users) | Perplexity | Public market research only. Redact stays on for all regulated data. | Research tool with no sanctioned equivalent. | Head of Market Risk | 31 Dec 2026 | Active |
| EX-02 | Technology, Mobile squad (38 users) | Cursor | Source code in the squad workspace. Secrets redacted. | Pilot of AI coding tools before a licence decision. | CISO | 31 Oct 2026 | Active |
| EX-03 | Marketing (24 users) | Canva AI | Corporate accounts only. No customer data. | Brand design work. | Head of Marketing and DPO | 30 Nov 2026 | Active |
| EX-04 | Human Resources (1 meeting series) | Otter.ai | One external panel series. Recordings deleted after 30 days. | Panel member requires transcripts. | DPO | 15 Oct 2026 | Active |
| EX-05 | Risk and Compliance, Analytics | MCP server: Postgres | Read-only account on the reporting replica. | Analyst queries on risk data. | Head of Data Governance | 31 Dec 2026 | Active |
| EX-06 | Retail Banking, Service | MCP server: email | Send limited to the institution's domain. | Draft replies for the service queue. | CISO | 31 Oct 2026 | Under review |
Register controls
- Expiry No exception runs longer than 6 months. Owners get a reminder 14 days before expiry.
- Review EX-06 is under review because the tool can send mail. It stays limited to the institution's domain until the CISO decides.
- Evidence Every decision made under an exception carries the exception id in the decision log.
Regulator clause map: UAE
This map links UAE regulatory expectations to the evidence in this pack.
| Regulator or law | Expectation (general) | Evidence item | Page |
|---|---|---|---|
| CBUAE | Outsourcing and third-party controls | AI app inventory with class and data-policy status | 4 |
| CBUAE | Consumer data protection | Sensitive data events; redact and block decisions | 6, 8 |
| CBUAE | Incident reporting | Timestamped decision log; signed export | 8, 12 |
| UAE Information Assurance Regulation | Asset inventory | AI app inventory; agents and MCP servers | 4, 7 |
| UAE Information Assurance Regulation | Data classification | Events by data class and lane | 6 |
| UAE Information Assurance Regulation | Monitoring and logging | Decision log and weekly trend; SIEM feed | 8 |
| UAE PDPL (Federal Decree-Law 45 of 2021) | Lawful processing of personal data | Personal data events; account split | 5, 6 |
| UAE PDPL (Federal Decree-Law 45 of 2021) | Processor obligations | Inventory data-policy notes; exceptions register | 4, 9 |
| UAE PDPL (Federal Decree-Law 45 of 2021) | Cross-border transfers | Apps with data outside the UAE | 4 |
| DIFC Data Protection Law 2020 | Processor obligations and transfers | Inventory; exceptions with approver and expiry | 4, 9 |
| ADGM Data Protection Regulations 2021 | Lawful processing, processors, transfers | Inventory; sensitive data events; exceptions | 4, 6, 9 |
How to read this map. The map shows where this pack holds evidence that supports a control area. It uses general terms, not clause numbers. It is not legal advice or a compliance opinion. The institution's compliance team decides which rules apply.
Regulator clause map: Saudi Arabia and international
This map is for institutions that also operate in Saudi Arabia, and for international standards.
Saudi Arabia
| Regulator or law | Expectation (general) | Evidence item | Page |
|---|---|---|---|
| SAMA Cyber Security Framework | Data leakage protection | Sensitive data events; redact and block decisions | 6, 8 |
| SAMA Cyber Security Framework | Logging and monitoring | Decision log; signed export | 8, 12 |
| SAMA Cyber Security Framework | Third-party security | AI app inventory; exceptions register | 4, 9 |
| NCA Essential Cybersecurity Controls | Asset management | AI app inventory; agents and MCP servers | 4, 7 |
| NCA Essential Cybersecurity Controls | Event logging | Decision log and SIEM feed | 8 |
| NCA Essential Cybersecurity Controls | External and cloud services | Inventory; corporate and personal account split | 4, 5 |
| Saudi PDPL | Processor controls | Inventory data-policy notes; exceptions | 4, 9 |
| Saudi PDPL | Transfer restrictions | Apps with data outside the country; data events | 4, 6 |
| Saudi PDPL | Breach notification | Timestamped events; signed export | 6, 8, 12 |
| SDAIA AI Ethics Principles | Accountability, privacy, transparency | Agent owners; data events; inventory | 4, 6, 7 |
International
| Standard | Expectation (general) | Evidence item | Page |
|---|---|---|---|
| ISO/IEC 42001 | AI management system: inventory, roles, monitoring | Inventory; agents; exceptions; decision log | 4, 7, 8, 9 |
| NIST AI RMF: Map | Know the AI systems in use | Inventory; agents and MCP servers | 4, 7 |
| NIST AI RMF: Measure | Measure use and risk | Account split; data events; decisions | 5, 6, 8 |
| NIST AI RMF: Manage | Act on risk | Policy decisions; exceptions | 8, 9 |
| NIST AI RMF: Govern | Roles, approvals, records | Exceptions register; signed export | 9, 12 |
How to read this map. The map shows where this pack holds evidence that supports a control area. It uses general terms, not clause numbers. It is not legal advice or a compliance opinion. The institution's compliance team decides which rules apply.
Signed export attestation
SentraGuard signed this export at creation. Anyone can check that the file has not changed.
- Export id
- SG-EXP-2026Q3-000417
- Document id
- SG-EP-SAMPLE-2026Q3-001
- Created
- 2026-10-01T06:00:00+04:00 (Gulf Standard Time)
- Period covered
- 01 Jul to 30 Sep 2026
- Contents
- AI app inventory, user and role attribution, policy decision log, exceptions and approvals, regulator clause map. Formats: PDF, CSV, SIEM feed.
- SHA-256 of export file
- 3f9a0c7e51b24d8a96e0f13c7b5a29d4e8c160f7a3b95d2e4c07f81a6d3b9e25c
- Signing key fingerprint
- SHA256:7Q2mX9vK4pR1tLw8eN3sB6yH0cJ5dF2gA9uZ4oV7iM1
The hash and fingerprint above are fictional. They show the format only.
How to verify
- Get the export file and its signature file from the institution's SentraGuard console or SIEM archive.
- Compute the SHA-256 hash of the export file with a standard tool, for example sha256sum on Linux or certutil -hashfile on Windows.
- Compare the result with the hash above. One changed byte gives a different hash.
- Check the signature file against the public signing key. Confirm that the key fingerprint matches the one above.
- Record the result, the date and the name of the reviewer in the audit file.
Methodology note
Data comes from the SentraGuard browser plugin, IDE extensions and endpoint agent, as described on page 3. Users and roles come from SSO and SCIM at the time of each event. Apps are matched against the SentraGuard app dictionary. Unknown LLM endpoints are flagged by behaviour. Counts on page 6 count each prompt once. Counts on page 8 count each decision once. Figures are not rounded. Times are Gulf Standard Time.