Shadow AI
AI Assessment
Your staff already use AI — the question is whether you know where, with which data and at what risk. The biggest danger is rarely an external attack: it's company information pasted into a public tool with nobody deciding it could go there.
The real risks
This isn't science fiction — these are patterns we already see day to day in companies.
Shadow AI
Staff use personal accounts of AI tools to handle company data, outside any control.
Warning signs:Nobody knows which AI tools are in use, or with what information.
Data leakage
Documents, contacts or code are pasted into a public tool that may retain them or use them for training.
Warning signs:Sensitive data leaving the company with no record and no clear legal basis.
Prompt injection
An AI assistant wired into your systems is manipulated by malicious content into acting against you.
Warning signs:AI automations with access to data or actions, with no limits and no review.
What the law already requires
The AI Act's transparency rules already apply. A commercial talking point — not legal advice.
- In force2 Aug 2026
AI Act — transparency
Largely applicable since 2 August. People must be told when they are interacting with an AI system.
Where it fits: AI Assessment · Shadow AI Audit
What we deliver
A technical — not legal — assessment that gives visibility and control without blocking productivity.
- Inventory of the AI tools in use, with risk classification
- Shadow AI: personal accounts versus company accounts
- A transparency list applicable from August 2026
- A ready-to-adopt AI usage policy
Do you know what AI is circulating in your company?
We give you the map and a ready-to-use policy, without slowing down the people who work.



