Your security lead reviews last week's access logs and finds three Jupyter instances calling external LLMs that never appeared on the approved vendor list. The queries touched customer pricing data.
Each model returned a different output format. One adjusted discount thresholds without recording the input parameters or the version deployed that day.
When finance flags the margin distortion, the incident review has no line item showing which endpoint produced the faulty recommendation. The team that ran the notebook has already moved on.
Procurement never saw the usage because the calls routed through personal API keys billed to a marketing cost centre. Residency rules were never checked against the training data sources.
Board packs still list only the sanctioned platforms. The shadow instances sit outside every override log and every model card the risk committee demanded last quarter.
Fixing this requires forcing every runtime to declare its model identifier and training snapshot before the first token is generated. Anything else leaves accountability as a manual chase after the fact.
Australian firms that treat model discovery as an annual audit exercise will keep missing the daily drift. The next pricing mistake or regulatory query will arrive with the same blank space in the timeline.