AI Security & Governance · ACE-01

How exposed is your organisation to shadow AI?

AI is already in use in your organisation. The only open question is whether you can see it. Staff adopted these tools because they help them work, and that initiative is an asset. The risk is not the people. It is adoption without visibility, policy or direction.

20 QUESTIONS · 15 MINUTES · INSTANT SCORE · NO EMAIL REQUIRED

Answer as the organisation stands today, not as it is planned to stand.

SCORING: Yes = 2 · Partly = 1 · No = 0 · Don't know = 0. On this topic, not knowing is the finding.

Can you see it?

Section A · Visibility
Q1
Could you produce, today, a current list of every AI tool in use across the organisation, including free browser tools and personal accounts?
Most organisations can name their sanctioned tools. Almost none can name the other forty.
Q2
Do you know which teams are entering client, employee or commercially sensitive information into public AI tools?
Usage concentrates where the workload is heaviest, which is rarely where anyone is looking.
Q3
Have AI-enabled browser extensions and connected apps that touch corporate data been identified and reviewed?
Extensions read what is on the screen. That includes the CRM, the inbox and the contract.
Q4
If an employee connected an AI agent to a corporate system this afternoon, would anything detect it?
Agentic tools act with the permissions of the person who connects them.

Who governs it?

Section B · Policy and ownership
Q5
Do you have a current, executive-endorsed AI use policy that staff can find and understand?
A policy nobody can locate governs nobody.
Q6
Does that policy name approved tools and prohibited uses, rather than advising staff to "use good judgement"?
Ambiguity is read as permission at exactly the moments that matter.
Q7
Is a named executive accountable for AI risk across the organisation?
Shared accountability for a fast-moving risk is unowned accountability.
Q8
Does AI use appear on your enterprise risk register with an owner, a rating and a review date?
If it is not on the register, it is not being managed. It is being hoped about.

What is leaving?

Section C · Data exposure
Q9
Do staff know, in plain language, which information must never enter a public AI tool?
Classification schemes do not transfer. "Client names and draft contracts" does.
Q10
Have the data retention and model training terms of the AI tools staff actually use been reviewed?
Free-tier terms commonly permit training on your inputs. Paid tiers often differ.
Q11
Are AI features inside your existing platforms, such as Microsoft 365 Copilot and CRM assistants, covered by your data governance?
Copilot inherits every over-broad permission you already have.
Q12
If a client or regulator asked whether their data had been entered into an AI system, could you answer with evidence?
This question is now appearing in contracts, audits and incident investigations.

Where is this going?

Section D · Safe adoption and roadmap
Q13
Do you have an AI roadmap linking specific use cases to value and risk, or is adoption happening by default?
No roadmap does not mean no adoption. It means unmanaged adoption.
Q14
For the tasks people use unsanctioned AI to complete, is there a sanctioned alternative that is actually good enough?
Shadow AI is a requirements document written by your own staff.
Q15
Is there a defined path to evaluate and approve a new AI tool in weeks rather than quarters?
When the front door is slow, the side door gets used.
Q16
Have staff been shown how to use AI safely in their actual workflows, beyond an annual compliance module?
People follow guidance that helps them work. They route around guidance that does not.

Could you respond?

Section E · Readiness and evidence
Q17
Would a staff member who pasted sensitive data into an AI tool report it without fear of blame?
You cannot respond to what people are afraid to tell you. Amnesty is a control.
Q18
Is there a defined response for sensitive data being disclosed to an AI service?
This is a data incident with its own containment steps. Improvising it is expensive.
Q19
Do procurement and vendor reviews ask how suppliers use AI on your data?
Your data is entering AI systems through suppliers whether or not your own staff touch a tool.
Q20
Could you evidence your AI governance to a client, auditor or regulator today, referencing a recognised framework such as ISO 42001 or the NIST AI RMF?
Assurance questionnaires have already started asking. "In progress" ages quickly.
0 of 20 answered

Your result

0 / 40

Want the gap summary and a 90-day starting plan?

Enter your details and Leon Hutcheson will personally send a short summary of your weakest areas and a prioritised 90-day starting plan. No automation, no sequence emails.

Your answers are emailed to Aceline only. They are not stored in any marketing platform and you will not be added to a list.