I get it. This is where you go back to an approved set of tools, to help reduce the risk. That way, the org is also accepting some responsibility for the tool choices.
In theory, this is how FOSS adoption should also work, at least for critical systems. Unfortunately, it ends up being whack-a-mole.
AI tooling has made this worse.