CattleGrid

MD / Senior Partner / CEO

MD / Senior Partner / CEO

The stake

Your organisation is already using AI, whether or not that decision has been made formally. 71% of UK employees are using AI tools their employer has not approved, and 51% do so at least weekly (Microsoft/Censuswide UK Shadow AI Survey, October 2025, n=2,003). 83% of UK organisations have no controls over what data leaves through those tools (BlackFog/Sapio Research, November 2025, n=1,000 UK organisations). This is not a question of whether your people will adopt AI. They already have.

The financial exposure this creates is specific and quantified, not speculative. The IBM Cost of Data Breach Report 2025 puts the additional cost of a breach involving shadow AI at £498,000 over the baseline — against an average UK breach cost of £3.29 million, rising to £5.74 million in financial services. Regulatory exposure compounds it: the ICO can fine up to £17.5 million or 4% of global turnover for UK GDPR failures, and where the EU AI Act applies, penalties for the most serious violations reach €35 million or 7% of global annual turnover. None of these figures require a catastrophic incident to become relevant. A single unmanaged data flow, surfaced during a client's due-diligence review or a regulatory enquiry, is enough to put the question in front of the board.

What a board-level control actually looks like

A governance layer does not need to be complicated to be effective, and at board level it should not be described as if it were. CattleGrid sits between your organisation's applications and the AI providers they call, inspecting what leaves before it leaves. It blocks or redacts content that matches your configured rules, keeps an unalterable record of what happened, and does this on every request, not on a sample. Deployment is a change to a web address in your application configuration — not a project, not a procurement cycle, not months of integration work.

The governance record itself is the asset a board can point to. Every decision — what was sent, what was blocked, what was redacted — is written to a cryptographically verifiable audit trail, tamper-evident by design rather than by policy. If a regulator, an enterprise client's due-diligence team, or your own auditors ask what control exists, the answer is a timestamped record, not an assurance.

On sovereignty, the precise position is this: what CattleGrid knows about your organisation never touches US jurisdiction. What reaches the AI provider has already been cleaned. CattleGrid is a UK-registered company running on UK infrastructure, with no US parent entity, so the governance layer itself — your policy configuration, your audit logs, your enforcement records — sits outside CLOUD Act jurisdiction. This is not a claim that AI processing as a whole becomes sovereign: the AI providers your organisation calls remain US-domiciled companies, and inference still reaches them. What changes is that what reaches them has been governed first, and what CattleGrid holds about you never leaves UK jurisdiction.

Set against the numbers above, the cost of putting this control in place is not the board's real question. The real question is what an unmanaged AI data flow costs when it surfaces on someone else's timetable rather than yours — and that figure is already quantified, above.

What this looks like once it's in place

A board that has deployed this can answer the exposure question before it is asked, with a governance record rather than a promise. It is in a materially stronger competitive position with enterprise and public sector clients who now ask AI governance questions as standard due diligence. And it has drawn a clear, defensible line between "we govern AI use" and "we hope nothing goes wrong" — a distinction regulators and clients are increasingly testing for directly.

What CattleGrid does not do

CattleGrid is a technical control, not a substitute for governance decisions your organisation still has to make. It does not provide FCA-regulated advice of any kind, does not produce SMCR Statements of Responsibilities, and does not conduct Data Protection Impact Assessments. It does not assess the suitability of AI-generated outputs — legal, financial, or otherwise — and it does not replace the judgement of the people accountable for those outputs. What it provides is the evidence base that makes those judgements defensible.

Pricing →