There is a particular moment that happens in almost every AI diagnostic engagement. It usually arrives somewhere around day eight or nine, during a debrief with a senior leadership team that came into the process quietly confident. Someone — often the Chief Risk Officer or the Head of Compliance — leans back in their chair and says some version of the same thing: *"We genuinely did not know it was this complicated."
That moment is not a failure. It is precisely what a well-executed AI diagnostic is supposed to produce. The organisations that benefit most from this kind of structured review are not the ones that already have everything figured out. They are the ones willing to look honestly at what is actually happening inside their walls, rather than what their governance documents say should be happening.
This post is a candid account of what two weeks of rigorous AI diagnostic work tends to surface in regulated environments — the patterns we see repeatedly, the findings that consistently catch leadership off guard, and the reasons why the results matter far beyond a compliance checkbox.
What a Two-Week AI Diagnostic Actually Involves
Before addressing what a diagnostic reveals, it is worth being precise about what the process actually entails. An AI diagnostic is not an audit in the traditional sense, and it is not a maturity framework assessment where an organisation scores itself against a rubric and receives a tier. Done well, it is a structured investigation combining document review, stakeholder interviews, system mapping, and observed practice — all designed to surface the gap between stated policy and lived reality.
A two-week engagement typically unfolds across three phases. The first few days focus on discovery: reviewing existing AI policies, governance frameworks, procurement records, vendor contracts, and any prior risk assessments. This phase often reveals more by what is absent than what is present. The middle portion of the engagement shifts to human intelligence — structured interviews with technology leads, legal and compliance teams, frontline practitioners, and business unit heads. These conversations are where the most important data lives. The final phase synthesises findings into a prioritised picture of risk exposure, capability gaps, and actionable recommendations.
For regulated organisations — those operating under frameworks like the EU AI Act, FCA guidance on algorithmic decision-making, NHS digital governance requirements, or sector-specific data protection obligations — the diagnostic carries additional weight. Regulatory obligations create a floor, but they do not automatically produce a functional governance culture. That distinction becomes very clear, very quickly.
Two weeks is a deliberately bounded timeframe. It creates urgency, limits the opportunity for teams to prepare curated narratives, and produces findings that reflect operational reality rather than aspirational positioning. It is long enough to go deep. It is short enough to stay honest.
The Policy Gaps That Almost Always Surface First
The first category of findings in any AI diagnostic is almost always policy — specifically, the distance between what an organisation believes its AI policy covers and what it actually covers.
Most regulated organisations have made some effort to document their approach to AI. What they tend to have is a general AI use policy, often written at a high level of abstraction, that addresses obvious risk categories like data privacy and model bias. What they tend to lack is the operational specificity that makes policy enforceable.
Consider a few recurring examples. An organisation's AI policy states that all AI tools used for decision-making must undergo a risk assessment before deployment. But the policy does not define what constitutes "AI," what qualifies as "decision-making," or who is responsible for conducting the assessment. Each of those ambiguities is a gap through which significant risk can pass unnoticed.
Or consider procurement. Many organisations have robust vendor due diligence processes for traditional software. Those processes were not designed with AI systems in mind and do not include questions about training data provenance, model drift, explainability, or the vendor's own AI governance posture. An AI diagnostic will typically map every AI-enabled tool in use across the organisation and test it against existing procurement criteria. The mismatch is almost always substantial.
Policy gaps also tend to cluster around high-risk applications. Automated credit decisioning, clinical risk stratification tools, HR screening systems — these are exactly the contexts where regulators are most likely to scrutinise AI use, and they are frequently the areas where internal policy is thinnest. This is not always negligence. It is often a function of how quickly AI capabilities have outpaced governance development. But the gap is real, and it needs to be named before it can be closed.
The discomfort here is that policy gaps are visible to anyone who looks. They exist in documents that leadership has reviewed and approved. Surfacing them is not an accusation — it is the beginning of a repair.
Shadow AI Use: The Finding Leadership Teams Least Expect
If policy gaps are the finding that arrives first, shadow AI is the finding that lands hardest.
Shadow AI refers to the use of AI tools by employees without formal organisational approval, awareness, or governance. It is the analogue of shadow IT, but with characteristics that make it considerably more consequential in regulated environments. And in two-week AI diagnostics conducted across sectors including financial services, healthcare, legal, and public sector organisations, shadow AI use is present in virtually every engagement.
The mechanics are straightforward. An employee discovers that a general-purpose AI tool — a large language model interface, an AI-powered document summariser, an automated email drafting assistant — makes their work faster or easier. They begin using it. They tell a colleague. The colleague uses it. Within weeks or months, a practice has embedded itself into operational workflows with no formal review, no data governance assessment, and no consideration of what information is being shared with external systems.
In regulated environments, the implications are serious. Client data, commercially sensitive information, legally privileged material, and special category personal data are all potentially being processed by third-party AI systems that have not been through vendor assessment, data processing agreements may not be in place, and the organisation may have no audit trail of what was shared or when.
What makes this finding particularly uncomfortable for leadership is the profile of the people involved. Shadow AI use is not primarily a behaviour of junior employees cutting corners. It is frequently concentrated among high-performing, technically capable staff who are solving genuine productivity problems. They are not acting maliciously. They are acting pragmatically, in the absence of sanctioned alternatives. The diagnostic does not treat this as a disciplinary matter. It treats it as a signal — evidence that the organisation's formal AI enablement is lagging behind employee need, and that governance frameworks have not kept pace with the reality of available tools.
Uncovering shadow AI use requires a diagnostic approach that creates psychological safety in interviews. People will not volunteer this information if they believe they are being investigated. When the environment is right, they will describe their workflows with candour that reveals the full picture. That candour is valuable data.
Accountability Blind Spots Hidden in Plain Sight
Governance frameworks are built on accountability structures. Someone is responsible for AI risk. Someone approves AI deployments. Someone monitors model performance over time. These assignments look clear on paper. In practice, they frequently dissolve under examination.
AI diagnostic work consistently surfaces what might be called accountability diffusion — a condition where responsibility for AI governance is nominally assigned but functionally distributed so broadly that no single person or team has the authority, resource, or information to act on it.
A common pattern looks like this. The Chief Data Officer is named as accountable for AI governance in the organisation's framework document. The CISO owns AI-related security risks. Legal and Compliance own regulatory obligations. Business unit heads own the tools deployed in their areas. IT owns the infrastructure. In isolation, each of these assignments is defensible. Collectively, they create a situation where a material AI risk — say, a third-party model used in customer-facing processes beginning to drift in ways that affect outcome quality — might be visible to no one, because everyone assumes it is someone else's problem.
Accountability blind spots also emerge around the AI system lifecycle. Many organisations have reasonable processes for approving new AI deployments. Very few have equivalent processes for ongoing monitoring, performance review, or decommissioning. A model approved two years ago may have been retrained by its vendor, applied to new use cases, or become subject to new regulatory expectations — with no internal trigger to review its continued appropriateness.
The diagnostic maps accountability against reality, not intention. It asks not who is named as responsible, but what that responsibility actually enables them to do, what information they receive, and whether they have exercised that accountability in practice. The answers are frequently illuminating — and they point directly to the structural changes needed to make governance functional rather than nominal.
Why Cultural Resistance Outlasts Any Governance Framework
Policy gaps can be closed. Shadow AI can be addressed through enablement and clearer guidance. Accountability structures can be redesigned. These are solvable problems, and two weeks of diagnostic work can map a credible path to solving them.
Cultural resistance is different. It is the hardest finding to document, the hardest to present to leadership, and the one most likely to undermine everything else if it is not addressed honestly.
Cultural resistance to AI governance takes several forms. The most common is what might be called governance fatigue — a widespread sense among staff that AI-related policies are another layer of compliance overhead imposed by people who do not understand the operational context. This is particularly acute in organisations that have already absorbed significant regulatory change in recent years. When governance feels like friction rather than enablement, it gets worked around.
A second form is what diagnostics tend to surface through interview data as scepticism about AI risk — not a principled objection, but a quiet disbelief that the risks being discussed are real or relevant to the organisation's specific situation. Senior practitioners who have been doing their jobs competently for years without an AI governance framework are understandably inclined to question whether one is necessary now. That scepticism is not irrational. It needs to be engaged with rather than dismissed.
A third, more structural form of cultural resistance comes from leadership itself. AI governance initiatives frequently stall because they lack genuine senior sponsorship — not formal endorsement, but the kind of visible, consistent prioritisation that signals to the organisation that this matters. When the C-suite is supportive in principle but absent in practice, the message received at every level below is that governance is optional.
The diagnostic surfaces these dynamics through patterns in interview responses, through the questions that people ask when they think they are not being formally assessed, and through the observable gap between what governance documentation says and how decisions are actually made. Naming cultural resistance clearly — without blame — is a prerequisite for addressing it. Organisations that receive findings only about policies and processes, without an honest account of the cultural environment those structures will operate in, are being given an incomplete picture.
What Organisations Should Do With the Results
A two-week AI diagnostic produces a findings report. What organisations do with that report is the only thing that actually matters.
The first and most important step is distinguishing between findings that require immediate action and findings that require strategic planning. Not every gap revealed by a diagnostic is equally urgent. An organisation operating an approved AI tool without a documented review cycle is in a different position from an organisation processing special category data through an unapproved third-party AI system with no data processing agreement. Prioritisation is not complacency — it is the basis for an actionable remediation plan.
The second step is treating the diagnostic as the beginning of a governance development process, not the end of it. Organisations sometimes commission a diagnostic with the implicit expectation that it will confirm they are broadly on track, with a handful of minor items to address. When the findings are more substantial — as they usually are — there can be a temptation to manage the report rather than act on it. This is where senior advisory support is most valuable: providing the continuity between findings and implementation that prevents the diagnostic from becoming a document that ages in a shared drive.
Third, shadow AI findings specifically require a response that pairs governance with enablement. If the diagnostic reveals widespread use of unapproved AI tools, the answer is not simply to prohibit that use. Prohibition without alternative provision drives behaviour underground rather than eliminating it. Organisations need a clear, accessible pathway for staff to request and access AI tools that have been properly assessed — and that pathway needs to be fast enough to be credible.
Fourth, accountability redesign should follow diagnostic findings rather than precede them. Many organisations make the mistake of building governance structures in the abstract before they understand where their actual accountability gaps sit. The diagnostic inverts this sequence: it reveals where accountability is failing in practice, and that evidence base informs a more durable structural design.
Finally, the cultural findings deserve dedicated attention — ideally in a leadership conversation separate from the technical and policy findings. Cultural resistance does not respond to the same interventions as policy gaps. It responds to visible leadership behaviour, to governance that visibly enables rather than obstructs good work, and to honest acknowledgement that the organisation is navigating genuinely new territory. Organisations that treat AI governance as a cultural and leadership challenge, not just a compliance exercise, are the ones that make lasting progress.
The two weeks of diagnostic work are, in a sense, the easy part. The results are uncomfortable precisely because they are accurate. What follows is a choice about whether to act on that accuracy — and in regulated environments, that choice has consequences that extend well beyond internal governance into regulatory exposure, operational risk, and organisational trust. The organisations that make the most of a diagnostic are the ones that were ready to be surprised by what they found.