Odds are, someone at your company uploaded a customer file to ChatGPT this week.
On a personal account. You can’t see it, you can’t delete it, and when that employee leaves, it goes with them.
Can you prove it didn’t happen?
No sales pressure. Just a candid conversation about your risks.
It isn’t just ChatGPT
AI Is Already Inside Your Business
AI notetakers
They join customer and staff calls, record them, and store the transcript on someone else’s servers.
Browser extensions
AI “assistants” that can read every page an employee opens, including the systems that hold your data.
Free document tools
Upload a contract or a spreadsheet, get a “summary.” The file now lives with a company you’ve never vetted.
Coding assistants
Source code, credentials and configuration files pasted in to get an answer faster.
We look for 260 AI services across 12 categories.
The Numbers Behind It
80%
of AI users at small and mid-sized companies bring their own AI tools to work.
Microsoft & LinkedIn, 2024 Work Trend Index
43%
of security incidents in the 2026 study involved shadow AI. That is more than double the prior year’s 20%.
IBM, Cost of a Data Breach Report 2026
68%
of breached organizations lacked AI governance to manage AI or detect shadow AI.
IBM, Cost of a Data Breach Report 2026
The Threat, Defined
Shadow AI is staff using AI tools the business never approved, on accounts the business doesn’t own. It is rarely malicious: it’s someone saving an hour on a deadline. The exposure is what happens next.
Data leaves without a record
Contracts, HR files, financials and customer data get pasted or uploaded into AI tools. No log, no alert, no record of what went where.
It can’t be recovered
A personal account has no admin, no deletion, no legal hold and no offboarding. When the employee leaves, the data goes too.
Nobody can answer the question
Insurers, auditors, regulators and major customers now ask what AI you use. Without evidence, the answer is a guess.
The AI Discovery Assessment
What You Get
A detailed AI inventory
Every AI service we observe, checked against 260 services in 12 categories: chatbots, notetakers, browser extensions, document tools, coding assistants and more.
Who is using it where your logs allow
Usage by person and device, so the fix lands on a name, not on a policy memo nobody reads.
What is leaving where your logs allow
The names of files uploaded to AI services, and where they came from: shared drives, HR folders, finance, legal.
Who owns the accounts
Whether staff use a company workspace you control, or personal accounts you can’t reach, delete from or revoke. This is usually the finding that changes the conversation.
Every finding reviewed by an analyst
Each finding is tied to the evidence behind it, plus a written statement of what our sources could and could not see.
A 30/60/90-day roadmap
Sequenced and owner-assigned, so the first thirty days establish the facts before anything irreversible happens.
How It Works
1
Authorize
You sign a scope. We agree the networks, the data sources and the collection window in writing. Nothing starts before that.
2
Observe
We ship a pre-configured sensor you plug in, or review logs you already keep. Days for a snapshot, weeks for the full picture, or months of history from existing logs.
3
Report
An analyst reviews every finding against the evidence. You get the inventory, the roadmap and a briefing in plain English.
What we need from you: a network port and a signature. No software on your endpoints, no agents, and nothing tested or changed without written authorization. Your IT team spends under an hour on it.
Built for Organizations That Answer to Someone
Defense contractors
If CUI goes into a consumer AI tool, it has left your CMMC boundary. Find out before your assessor does.
Credit unions & financial institutions
NCUA has no AI-specific rules. Existing regulations apply to AI use. You can’t oversee a tool you don’t know is in use.
Healthcare & regulated businesses
Patient, client and employee data in an AI tool nobody approved is a compliance problem waiting for an audit.
Frequently Asked Questions
Will this slow down our network or break anything?
No. The assessment is passive. We observe a copy of your traffic or read logs you already have. Nothing is installed on your computers and nothing on your network is changed.
Do you read what employees type into AI tools?
No. We see which AI services are used and by whom. Where your logs record it, we also see the names of files uploaded. We never see the contents of a file or a prompt.
How long does it take?
That’s your call. A few days gives a fast snapshot; a few weeks gives a fuller picture. If you already keep the right logs, we can review months of history right away.
We already block ChatGPT. Do we still need this?
ChatGPT is one of 260 AI services we look for. Blocks also tend to push activity to personal phones and other tools. The assessment shows whether your controls are actually holding.
Will you find every AI tool?
We’ll find the AI services our sources can see, and we’ll tell you in writing what they can’t, such as AI built into software you already use. An honest boundary is what makes the findings defensible.
What happens after the assessment?
You get a 30/60/90-day roadmap your IT team or provider can act on. If you want ongoing executive ownership of AI risk, our Fractional CISO service can lead it.
Find Out What Your Organization Is Actually Sending to AI
No sales pressure. Just a candid conversation about your risks.
Sources: Microsoft & LinkedIn, 2024 Work Trend Index (31,000 knowledge workers, 31 markets); IBM & Ponemon Institute, Cost of a Data Breach Report 2026 (602 organizations); NCUA, Artificial Intelligence (AI) compliance resources (updated April 28, 2026). Passive observation shows that a file was sent, not its contents. Independent assessment within an authorized scope; not legal or regulatory advice and not a guarantee against incidents.
