# Exposure/Custody Diagnostic: map where your team's AI use actually sits

**Faraz Rizvi · SpinUp Forge**

*Companion kit to [What Happens After You Press Enter](/thinking/exposure-custody.html).*

---

> **Note.** These prompts are designed to sharpen your thinking, not replace it. LLM outputs vary with the model, the inputs, and the context. Treat every output as a first draft for your own review, not a finished deliverable. Nothing here constitutes legal advice, and nothing in the prompt's output does either.

## What this kit is

The piece argues that AI use is not one question with a safe answer in the middle. It is two independent questions — exposure and custody — and the two answers resolve into four distinct postures, not points on a single scale. A personal chat account with no policy and no habit of capture lands in the worst cell on both counts at once, by construction, and it is also the setup that feels the most productive from the inside. This kit turns that argument into three short prompts: list every place AI touches the company's work, score each workflow against the piece's two questions, and produce one dated, two-week move for anything that lands in the two flagged postures. The output is a map and a short action list, not a policy.

**Run this without creating the exposure it diagnoses.** The first prompt asks you to describe every place AI touches your company's work. Describe it at the level of the tool, the role using it, and the category of material involved — "ChatGPT Plus, personal account, used by the two founders to tidy grant-application prose" — never the material itself. Do not paste source code, a formulation, a draft patent claim, an unfiled invention disclosure, or a customer or investor list into any of these prompts, or into any chat tool, while you are running this diagnostic. A kit about exposure that induces exposure has failed at its first step. If naming even the category feels too close for comfort on a given workflow, run this kit on an account whose terms exclude training by default, or on a locally run model — it produces the same read either way.

**This kit is written for a UK academic spinout founder, roughly the first eighteen months after a licence, running on informal AI tools with no written policy, holding IP not yet protected by a filed patent.** It reads the same way for a startup founder outside the university system carrying the same gap without the licence-specific stakes — the two test questions do not change.

Neither this kit nor any of the three prompts below needs your bank position, your runway in months, named funding instruments or amounts, patent numbers or families, your cap table, or contractor clauses — the read does not depend on any of them, and none of the three prompts will ask. The only thing this kit needs that the piece's own argument does not already give you is an honest list of where AI touches the work, described in categories, not content.

## How to use this kit

Run the three prompts in sequence, in one conversation, pasting each prompt's output into the next. If your list of AI-touched workflows is short — half a dozen or fewer — the whole kit takes about twenty-five minutes. If it is longer, or you would rather check the inventory against what your team actually does before scoring it, split it: run Prompt 1 alone, then come back for Prompts 2 and 3 together.

Prompt 2 will tell you, honestly, if nothing in your inventory lands in the two flagged postures. If that happens, skip Prompt 3 — there is nothing for it to do, and the discipline from here is keeping the inventory current as you adopt new tools, not building anything further.

---

## Prompt 1: List where AI touches the work

Most exposure does not arrive as one reckless paste. It arrives as the fifth ordinary use of the week — the one nobody thought to name because it felt too routine to count. This prompt makes that list visible before judging any of it; scoring is a separate step, in Prompt 2.

```prompt
You are an operations reviewer who has sat inside the practical side of
university technology transfer and spinout support — someone who reads a
team's day-to-day AI use the way a diligence process eventually will: by
what actually left the building and what came back, not by what the team
intended. You are on the founder's side. Your job here is to make the
invisible list visible, not to alarm anyone about it.

The reframe before you ask me anything: most exposure does not come from
one careless paste. It comes from the fifth ordinary use of the week —
the tool that has become so routine nobody thinks to name it as AI use at
all. This prompt is a factual inventory only. It does not judge or score
anything yet; that is a separate step.

I am a founder of a UK academic spinout, roughly the first eighteen
months after licensing. My team uses AI tools informally, with no
written policy.

A rule for how I answer: describe everything below at the level of the
tool, the account type, the role, and the category of material — never
the actual content. I will not paste source code, a formulation, a draft
patent claim, an invention disclosure, or a customer or investor list
into this conversation. If a workflow feels too sensitive to name even at
category level, I will say so and move on, and you should not press for
more.

I do not need to give you, and you should not ask for, bank positions,
funding amounts, patent numbers, cap-table detail, or contractor clauses
— none of that changes this list.

What you'll give me: a plain inventory table of every place AI currently
touches the company's work — nothing scored, nothing judged.

What you'll ask: one open batch, not a series of separate questions.

Ask me this: for every place AI touches your company's work right now,
give me — which tool, and roughly which account or tier (personal free,
personal paid, a business or institutional account, or not sure); who
uses it, by role, not name (founder, co-founder, postdoc, contractor,
other); what kind of material typically goes through it, as a category,
not a description (drafting or editing prose, code, research or lab
data, customer or investor communication, something else); and roughly
how often (daily, weekly, occasionally). List as many as come to mind —
three or fifteen, whatever is real. (Why: the point of this prompt is
completeness, not depth; a short list that misses the routine tool is
worse than a long one that includes it.)

If I only name one or two and you suspect there are more — most teams
run at least one AI feature bundled into something else that nobody
counts as "an AI tool" (an editor's built-in assistant, a transcription
add-on, a workspace's rewrite feature) — ask once, gently, whether
there's anything bundled in that I haven't counted. Do not push further
than that.

When you have my list, give me:

## Workflow inventory

A table, one row per workflow:

| Workflow | Tool + account/tier | Who (role) | Data category | Frequency |

Every field comes from what I told you. If I was vague on account or
tier, write "not sure" rather than guessing which one I meant.

A few rules for you: do not invent a workflow I did not name; do not
guess an account tier I did not state — write "not sure" instead; do not
score exposure or custody here, that is a later step; do not ask me to
describe or paste any actual content, only categories.

This is a first draft of the list, not a final record — I will check it
against what my team actually uses before moving to the next prompt.
Self-check before you give me the table: every row names a tool, a role,
and a data category (none left blank or marked "various"), and no row
contains anything beyond a category-level description.

Begin by asking me for the list in one go.
```

The output is a plain table, nothing more. Read it against what your team actually does before you move on — a workflow you use daily that didn't make the list is more useful to catch now than after scoring. Eval check for this prompt: every row names a tool, a role, and a data category; a row that reads "various" or is missing a field has not been finished, and you should send it back before treating the inventory as complete.

---

## Prompt 2: Score each workflow — exposure and custody

Exposure and custody are independent questions. A workflow can fail one, both, or neither, and the two failures do not average into a middle score — they land in one of four distinct postures, and the posture that feels the most productive day to day is usually the one where both answers are the worst.

```prompt
You are the same operations reviewer from the first prompt, now applying
the two-question test a careful diligence reviewer would apply to each
workflow before signing off on it. You are on the founder's side — the
point of scoring is to find the one or two workflows worth fixing, not
to make every workflow sound risky.

The reframe before you score anything: exposure and custody are
independent. A workflow can fail one, both, or neither, and the answers
resolve into four distinct postures, not a single scale from safe to
risky.

Paste your Prompt 1 workflow inventory below. As before: describe
workflows in categories, and do not paste actual sensitive content into
this conversation while we score it. I do not need to give you, and you
should not ask for, bank positions, funding amounts, patent numbers,
cap-table detail, or contractor clauses.

What you'll give me: the same table, with two questions answered and a
named posture for every row — nothing invented, nothing averaged.

What you'll ask: two questions per workflow, asked together as a pair,
two or three workflows at a time — not the whole list at once and not
one question at a time.

For each workflow, ask me both of these together:

Exposure — does this workflow send sensitive, unfiled or confidential
material outside a boundary you control, to a party under no obligation
to protect it? A yes or no is a complete answer. (Why: this is the
piece's exposure test, word for word — it does not matter how useful
the workflow is if the answer is yes.)

Custody — does what the interaction teaches — the correction, the
judgment call, the awkward edge case — end up inside something the
company owns, or does it evaporate, or accrue to somebody else's model?
A yes or no is a complete answer. (Why: this is the piece's custody
test, word for word, independent of exposure, and the one most teams
have never been asked.)

If I answer "sort of" or "depends" on either question, ask one gentle
follow-up naming what it depends on, then move to the next pair.
Otherwise, take my yes or no and move on.

When you have both answers for every row, give me:

## Scored inventory

The same table, with two columns added, plus the posture, derived only
by this rule, applied mechanically, no judgement:

- Low exposure, low custody -> Dormant
- Low exposure, high custody -> Owned
- High exposure, low custody -> Renting it out
- High exposure, high custody -> Financing the competition

| Workflow | Tool + account/tier | Exposure | Custody | Posture |

Then give me:

## Where your team actually sits

Three or four plain sentences naming the posture most of your workflows
actually land in, and whether that matches what it feels like day to day
— the piece's argument is that the highest-activity posture and the
worst-scoring one are usually the same cell.

A few rules for you: the posture in every row must follow the mapping
above exactly, no row gets a posture that doesn't match its two
answers; do not invent or soften an exposure or custody answer I gave
you; do not drop a row from the Prompt 1 list; if I said "not sure" on
account or tier back in Prompt 1, ask me directly now, since it usually
decides the exposure answer.

This is a first read, not a verdict — I will check every posture against
the two answers I actually gave before treating any row as settled.
Self-check before you give me the table: every row has both an exposure
answer and a custody answer, neither left blank, and every posture
matches its row's two answers under the mapping rule above, with no
exceptions.

Begin by asking me about the first two or three workflows.
```

The output is the same table with a posture attached to every row, plus a short read of where your team actually sits. Eval check for this prompt: pick any two rows and check the posture against the mapping table yourself — high exposure and low custody must read "Renting it out", not anything softer. A posture that doesn't follow the stated mapping is a mechanical error, not a judgement call, and should be corrected in the same conversation before you move to Prompt 3.

---

## Prompt 3: One first move per flagged workflow

The same fix lands you in a different place depending on where you started. Fix exposure on a workflow that was Renting it out and you land in Dormant — safer, still banking nothing. Fix the same exposure gap on a workflow that was Financing the competition and you land in Owned, the target, because the custody habit was already there and only the exposure side was leaking it to a vendor. One kind of fix, two different outcomes. This prompt exists to pick the one fix each flagged workflow actually needs and put a real date on it.

```prompt
You are the same operations reviewer, now doing the part of the job most
reviews skip: turning a finding into one dated action, not a list of
things that would be nice to fix eventually.

The reframe before you plan anything: the same fix lands you in a
different place depending on where you started. Fixing exposure on a
workflow that was Renting it out lands it in Dormant. Fixing the same
exposure gap on a workflow that was Financing the competition lands it
in Owned, because custody was already in place. This prompt exists to
name the one fix each flagged workflow needs, and a real date for it.

Paste your Prompt 2 scored inventory below. Tell me today's date, so
every action gets a real deadline, not a vague "soon."

What you'll give me: exactly one action and one date for every workflow
that scored Renting it out or Financing the competition, nothing for the
rows that didn't.

What you'll ask: a quick yes/no per flagged workflow, batched two or
three at a time, then nothing else.

First, tell me today's date.

Then, for every workflow scored Renting it out or Financing the
competition, ask me: for this workflow, do you already have access to an
account or platform whose terms exclude training by default, or to a
locally run or institutional model, or would getting access to one of
those be the two-week task itself? A yes/no plus which one, if you know
it, is a complete answer. (Why: the piece's own point is that this fix is
usually a tier change or a settings change, not a rebuild, but only if
the access already exists; if it doesn't, getting it is the real first
task.)

When you have my answer for every flagged row, give me:

## First moves

One row per flagged workflow, nothing for Dormant or Owned rows:

| Workflow | Posture | First move | Target date |

"First move" is exactly one of: move this workflow onto the no-training
account or platform you already have; strip identifying details before
anything is sent, as an interim step while access is arranged; move the
workflow onto a locally run or institutional model; or, only if you told
me an exposure-side fix genuinely is not available within two weeks,
start a decision log beside this workflow as the interim step. Pick one.
Never two, never a fifth kind of action, never a generic "review AI
usage."

"Target date" is a real calendar date no more than fourteen days after
the date you gave me, not "in two weeks", an actual date.

Then give me one line: how many workflows got a first move, confirming
every one has both a named action and a date.

A few rules for you: exactly one action per flagged row, never zero and
never two; never invent a feasibility answer I did not give you; never
recommend a specific paid product or vendor by name, name the category
of fix (no-training tier, stripped-identifier interim step, local or
institutional model, decision log), not a brand; do not touch the
Dormant or Owned rows at all; do not claim to have made any change
yourself, you are naming what I should do and by when, not doing it.

This is a plan, not a policy — I will check, before I act on any row,
that the action matches what I actually told you and that the date is
real. The check that matters here: every flagged row has both a named
action and a date, and no flagged row is missing. A row with no date, or
a flagged row absent from this table entirely, means this run is not
finished; go back and close the gap before treating any of it as done.

Begin by asking me for today's date.
```

The check that matters for the whole kit, not just this prompt: every workflow in your Prompt 1 inventory carries both an exposure answer and a custody answer from Prompt 2, and every workflow that scored Renting it out or Financing the competition carries exactly one dated action item from this table. Count them yourself; it takes under five minutes. A write-up that reads well but has a flagged workflow with no date next to it, or a flagged workflow missing from the table altogether, has not passed. Go back into the same conversation and close the specific gap before you treat any of it as settled.

---

## What to do once you have run this kit

**Re-run the scoring next quarter, not once and never again.** A workflow that scored Owned in July can drift back to Renting it out by October the moment a paid seat lapses back to a personal account, and nobody has to decide that on purpose for it to happen.

**Put the flagged rows in front of whoever actually controls the account settings, this week.** A no-training tier is an admin decision, not a policy programme, and it stalls the moment it needs someone other than the founder to act on it.

**Treat the decision log, where you started one, as a habit next to the workflow, not a separate document.** A log kept apart from the work it corrects usually stops after the second entry; one kept beside the workflow, in the place the team already looks, is the one that survives.

---

## Related reading

- [What Happens After You Press Enter](/thinking/exposure-custody.html), the source argument.
- [The Bottleneck Has Moved.](/thinking/bottleneck-is-not-the-model.html), the premise this piece takes as settled — that the model is rarely the actual constraint.
- [The prompt toolkit](/toolkit/), the four-chair operational-readiness diagnostic, if the gap this kit finds turns out to be broader than AI-tool habits alone.
