CultureAI
SaaS

Getting control of the AI embedded across a scale-up toolchain

An engineering-led company with hundreds of SaaS tools, and AI quietly switched on inside most of them. The risk was not one chatbot: it was everywhere.

Industry
B2B SaaS
Size
900 employees
Region
UK and US
0+

SaaS tools found with embedded AI features

0%

reduction in source code reaching public models

0

tools blocked outright

The challenge

The security team knew about ChatGPT and Copilot. What they could not see was the AI embedded inside the design, support, analytics and productivity tools the company already paid for, each one a new place for source code and customer data to travel.

In a company built on shipping fast, blanket blocking was culturally impossible. The security team needed precision: allow the flows that were safe, catch the ones that were not.

The approach

Discover, control, detect, prove

01

Discover

CultureAI mapped AI activity across the whole toolchain, surfacing embedded AI features in 130+ SaaS tools nobody had assessed.

02

Control

Data-aware policies distinguish a marketing draft from a source file: warn on the grey areas, block proprietary code and customer data, allow everything else.

03

Detect

Pre-trained detection recognised source code in prompts and pastes with the accuracy regex DLP never managed, from the first day.

04

Prove

Usage reporting fed straight into the company’s SOC 2 evidence base and customer security questionnaires.

The results

  • Source code reaching public models fell 96%, with engineers steered to the sanctioned coding assistant rather than cut off.
  • Not a single tool was blocked outright: policies act on the data in the interaction, not the app on a list.
  • Security reviews that used to stall enterprise deals now close faster, backed by real evidence of AI governance in practice.
app.culture.ai· Where work happensNo perimeter
SaaS apps
Cloud
BYOD
Browsers
Supply chain
Copilots
Personal accounts
Embedded AI
Shadow IT

Perimeter thinking can’t follow work this decentralised

We expected a shadow AI problem. What we actually had was an embedded AI problem, in the tools we had already approved. Nothing else we looked at could even see that.
VP of Security, B2B SaaS scale-up

Uncover hidden AI risk

Start a free 2-week AI Risk Assessment. Easy setup. Fast visibility.