Token Leaderboards and Blind Mandates: AI's Hidden Governance Risk
A widely shared consultant's account of executives mandating AI use they've never touched themselves is a governance failure, not just a culture problem — and it leaves real gaps for security teams to close.
Key Takeaways
- A consultant's widely circulated account describes an executive who authored a $2B+ organisation's AI strategy without ever having used ChatGPT or any AI tool personally.
- Some organisations reportedly track 'token leaderboards' that reward raw AI usage volume, pushing staff toward performative prompting rather than verified output.
- The same account describes employees mislabeling human-authored work as AI output to satisfy usage mandates — which quietly destroys any audit trail an AI governance programme would depend on.
- None of this requires a technical exploit to become a real risk: ungoverned, metric-driven AI mandates create exactly the kind of undocumented shadow-AI usage that ISO 42001-style governance is meant to catch.
A post from commentator Simon Willison has been circulating widely this week, curating anecdotes from consultant Nik Suresh's essay "AI Mania Is Eviscerating Global Decision-Making". Suresh, who runs the Ludicity blog and works at the data consultancy Hermit Tech, describes patterns he says he has observed across roughly 300 client conversations. The essay is framed as opinion and anecdote, not a study — but the specific incidents it describes map cleanly onto governance failures that security and compliance teams are already supposed to be watching for.
Strategy without hands-on knowledge
The anecdote getting the most attention: an executive responsible for a business unit with more than $2 billion in revenue reportedly admitted to never having used ChatGPT or any AI tool personally, immediately after producing a technical strategy document built entirely around AI adoption. Suresh also describes organisations running internal "token leaderboards" — dashboards that reward employees for raw AI token consumption — which he says pushes staff toward performative prompting loops rather than verified, useful output.
A third detail is the more serious one for anyone thinking about governance: employees, under pressure to demonstrate AI usage, reportedly relabel work they did themselves as AI-generated output to satisfy the mandate.
Why this is a governance problem, not just a culture problem
None of this requires a jailbreak, a prompt injection, or a compromised model to cause damage. It's a provenance and accountability failure that happens entirely inside the organisation's own reporting chain:
- Strategy set without capability. Decision-makers directing AI adoption without first-hand experience of the tools' failure modes are poorly positioned to size the actual risk they're signing off on.
- Metrics that reward the wrong thing. A token-volume KPI creates an incentive to *use* AI performatively rather than to use it *correctly*, which is the opposite of what a usage-monitoring control is supposed to achieve.
- Broken provenance. If staff are mislabeling human work as AI output (or vice versa) to hit a mandate, any later audit of what an AI system actually touched — a requirement under frameworks like ISO/IEC 42001 — is built on false data from day one.
Suresh also describes a vendor-side dynamic worth noting: customer executives promoting implausible productivity gains, and vendor staff who privately doubt those figures staying quiet because contradicting a customer's narrative risks the account. That pressure loop discourages the kind of honest capability assessment that a governance programme depends on to function.
What this means for security and governance teams
None of these are hypothetical, and none of them are new failure modes — they're the same shadow-IT and unverified-metric problems security teams have chased for two decades, now wearing an AI label. The practical response is the same as it's always been: an AI usage policy that specifies what tools are approved and for what data; usage metrics that measure verified, reviewed output rather than raw volume; and a governance record — mapped to a framework like ISO 42001 — that can actually be trusted when someone asks what an AI system did and on whose authority. A mandate handed down by leadership that has never used the tools it's mandating is, on its own, a signal worth escalating.
Frequently Asked Questions
Is this report describing a specific company or security incident?
No. It's a set of anonymised anecdotes from consultant Nik Suresh, drawn from client engagements, curated in a post by commentator Simon Willison. There's no named company, breach, or CVE attached to it — treat it as a pattern worth watching for internally, not a disclosed incident.
What is a 'token leaderboard' and why is it a risk?
It's an internal dashboard some organisations reportedly use to rank employees or teams by AI token consumption, intended to drive adoption. The risk is that it measures usage volume rather than verified output quality, creating an incentive for performative or fabricated AI use rather than genuine, reviewed results.
How does ISO 42001 relate to this problem?
ISO/IEC 42001 is the AI management system standard that requires organisations to document how AI systems are used, by whom, and with what oversight. Mandates that reward raw usage over verified output — or that let staff mislabel human work as AI-generated — undermine the accurate usage records that standard depends on.
Sources
- 1AI Mania Is Eviscerating Global Decision-Making — Simon Willison
- 2AI Mania Is Eviscerating Global Decision-Making — Ludicity (Nik Suresh)