{"ok":true,"engine":"aicost.msp-shadow-ai-governance","inputs":{"employees":500,"pctUsingUnsanctionedAi":60,"pctShadowUsersSharingSensitive":30,"promptsPerUserPerWeek":10,"annualBreachProbabilityPct":20,"baseBreachCostUsd":4880000,"shadowPremiumUsd":670000,"governanceProgramMonthlyUsd":4000,"riskReductionPct":70,"targetMarginPct":50},"result":{"monthlyUsd":4000,"annualUsd":48000,"shadowUsers":300,"sensitiveUsers":90,"sensitivePromptsPerMonth":3897,"expectedAnnualLossUsd":1110000,"expectedLossAvoidedUsd":777000,"governanceAnnualUsd":48000,"netBenefitUsd":729000,"roiPct":1518.75,"paybackMonths":0.7413127413127414,"exposureLevel":"critical","verdict":"HIGH EXPOSURE","isInferred":true,"inferredFields":["promptsPerUserPerWeek","governanceProgramMonthlyUsd","riskReductionPct"],"breakdown":["300 shadow-AI users (60% of 500 staff)","90 sharing sensitive data → ~3,897 risky prompts/mo","Expected annual loss $1,110,000 (20% × $5,550,000 shadow-involved breach)","Governance program $48,000/yr avoids ~$777,000 *","Net benefit $729,000/yr — GOVERN NOW — expected loss avoided exceeds program cost"],"_model":"shadow-ai-exposure","serviceFeeMonthlyUsd":8000,"clientNetMonthlyUsd":56750,"decision":"SELL GOVERNANCE NOW","decisionDetail":"300 employees on unsanctioned AI, 3897/mo prompts carrying sensitive data — exposure math says the governance program at $8000/mo pays for itself in avoided expected loss. This is the easiest security conversation of 2026: the client already suspects it.","verdictReason":"300 shadow-AI users, 90 sharing sensitive data (3897 prompts/mo); expected annual loss $1,110,000 → governance ROI 1518.75%.","memo":"Exposure and expected-loss math come from the fleet Shadow-AI Exposure brain — identical numbers to the public calculator by design. The MSP layer prices the governance program as a recurring white-label service via cost ÷ (1 − margin). Expected-loss figures are probabilistic estimates*, not predictions, and running the program does NOT make the client legally compliant — sell it as risk reduction plus evidence, which is what it is. Pairs with the Managed AI Service Pricing calculator (its governance floors) and the platform’s shadow-AI discovery (S15 roadmap).","questions":["What does a discovery scan actually find? Run one before quoting — the real shadow-user count sells the program.","Which regulated data classes are in play? That sets the risk tier in the AI service pricing calculator.","Who owns AI policy at the client today? \"Nobody\" is your opening slide."],"assumptions":["Breach probabilities and costs are industry-typical* inputs — replace with the client’s insurer figures where available."]}}