Skip to content

We took our AI platform out onto the Liffey. Here’s the actual reason why.

Every second post about AI and cybersecurity tells you that businesses are “navigating uncharted waters.” We got tired of writing it, so this week we did it literally, four currachs, eight of the Ekco team, and one very patient Jeannie Johnston tall ship watching from Custom House Quay while we tried not to go for an unplanned swim.

It made for a good photo. But the joke only works because the underlying point is real: most businesses genuinely don’t know what water they’re in when it comes to AI.

The blind spot nobody signed off on

Ask most CIOs how many AI tools are in active use across their business, and you’ll get a confident answer. Ask their employees, and the real number tends to be a lot higher. Our own research puts the typical figure at around 28 AI applications running inside a single organisation, most of them installed by individuals trying to get their job done faster, not by IT.

That gap has a name now: shadow AI. It’s not malicious, mostly it’s a marketing exec finding a tool that summarises reports in ten seconds instead of forty minutes, or a finance team member pasting a spreadsheet into a chatbot to check a formula. The problem isn’t that people are using AI. It’s that nobody can see where the data went once they did.

Why banning it doesn’t work

The obvious response is to lock it down. In practice, that rarely holds. People keep using the tools they’ve already found useful, just more quietly, which makes the blind spot worse, not better. Cian Prendergast, CEO of Ekco MSP, put it plainly: most businesses have already stopped asking whether their employees will use AI, and started asking how to stop that use becoming a risk they can’t see.

The alternative is to give people sanctioned, well-governed options, explain the rules clearly, and put real controls around the data. That’s the premise behind Ekco AI.

What Ekco AI actually does

Ekco AI is designed to give organisations visibility and control over AI use without having to ban it outright. In practical terms, it:

  • Identifies which AI applications are actually being used across the business
  • Sets guardrails and blocks applications that pose a genuine data risk
  • Reduces the chance of sensitive information ending up in an unsanctioned tool
  • Provides role-based training on tools like Microsoft Copilot and Claude, alongside broader awareness training on data protection and safe use
  • Creates an audit trail of AI activity, with reporting built for boards, auditors and regulators

That last point matters more than it might sound. Transparency obligations under the EU AI Act came into force on 2nd August, with further requirements landing in 2027 and 2028. For financial services organisations in particular, the controls Ekco AI puts in place also support compliance with NIS2 and DORA, two pieces of regulation that are no longer theoretical for most risk and compliance teams.

The upside of getting this right

There’s a commercial case here too, not just a risk one. When people trust that the AI tools available to them are safe to use, they tend to actually use them. Our data suggests that translates to genuine productivity gains, more than five hours a week per employee in some cases, which at scale is a meaningful operational saving rather than a rounding error.

As Steve MacNicholas, CEO of Ekco Ireland, put it: businesses don’t get real value from AI until their people feel comfortable enough to experiment with it. That comfort has to come from somewhere. Usually it comes from having someone else worry about the guardrails, so the people doing the work don’t have to.

Back to the boats

We’re aware that a currach isn’t the first thing that comes to mind when you think about AI governance. That’s rather the point. Most of what gets written about AI risk in this industry is abstract, hedged, and slightly frightening. We’d rather make the argument plainly, and have a laugh doing it, than lean on the kind of language everyone’s already tired of reading.

If you want the detail behind the platform, the team, or how this applies to your own organisation’s shadow AI problem, that’s a conversation worth having properly. The currachs, mercifully, are back on dry land.

P.S. Special shout out to Patrick and the team in HQ20 who facilitated us on a stunning July morning! Check them out for an corporate team building day or a family fun day with the kids, we’d thoroughly recommend!

Question?
Our specialists have the answer