Enterprise AI Measurement Guide
AI Governance · Policy Enforcement
Warned Events
How many engineers are receiving AI tool usage warnings, and what does the ratio of warnings to blocks tell us about whether our governance posture is calibrated correctly?
What it shows
Warned Events counts enforcement actions where the user received a policy warning but was not prevented from accessing the tool. This represents the soft enforcement tier, the friction layer designed to create awareness and prompt behavior change without the disruption of a hard block. The count shows how actively the warn-tier policy is being triggered across the organization.
Why it matters
Warning-first enforcement is the governance design choice that balances risk management with productivity. If warned events significantly outnumber blocked events, the organization has chosen a permissive posture: it trusts employees to self-correct. If warned events are low and blocked events are high, the policy is restrictive. Neither is inherently right. The right ratio depends on the organization's risk tolerance and AI maturity. The CIO and CISO need this number to calibrate policy, and to answer the board's question about whether governance is working or just creating friction.
The Larridin angle
Warned Events is a leading indicator of shadow AI risk. A tool that generates many warnings before being blocked has a period where employees are actively trying to use it despite policy signals, which tells security teams something is meeting a real need that the approved stack is not. That signal should trigger a review of whether to approve the tool, not just escalate enforcement.