See which AI tools your team uses.
Most teams cannot say which AI tools are running in their org. BeeSensible shows each one as it appears, counted anonymously, with a risk assessment and a suggested policy already attached. You decide what is allowed without starting from a blank page.
The method
The same four steps, now for your AI tools.
Every BeeSensible module follows this cycle. Here is what it looks like for managing AI tools.
Which AI actually runs
Every AI tool your people open shows up, counted anonymously, including the ones nobody ever requested.
Your decision at the moment of work
When someone opens a tool you decided on, they see that decision, with the approved alternative leading.
What the policy delivers
The share of AI use through approved tools, the tools still missing a decision, and the trend behind it.
and again How the cycle works
New tools land in an inbox.
The moment a new AI tool shows up in your org, it waits for a decision: allow it, allow it within a condition you set, disallow it, or decide later. Every tool starts with no decision, and nothing comes pre-selected. Confirm one at a time or decide a whole batch at once; the organisation always calls it, never BeeSensible.
700+ AI tools, already assessed.
The catalog holds more than 700 AI tools, each scored for risk by BeeSensible: from Low to Critical, with the vendor, its country, and certifications on the row. Filter on what matters to you, select a range, and set policy on many tools in one go. Tools your people have never opened are covered before anyone tries them.
And it keeps growing. Tools discovered in organisations and in BeeSensible's own research land in a review queue, get assessed, and join the catalog with the full fact sheet, so keeping track is no longer your job. New arrivals carry a badge in the catalog for 30 days.
Risk assessment
How a tool gets its score.
Every tool in the catalog is scored on six dimensions, each from 1 to 5, where higher means more risk. The dimensions do not weigh the same: what the vendor does with your data counts heaviest.
Data governance
Weight 6How the vendor handles your data: whether it trains on your input, offers a processing agreement, and where data is stored.
Jurisdiction
Weight 4Legal risk from where the vendor and its data live. Countries allowing state access or lacking GDPR adequacy score higher.
Compliance
Weight 3Alignment with GDPR and the EU AI Act, plus recognised certifications such as ISO 27001 and SOC 2.
Incidents
Weight 3History of breaches, leaks or misuse tied to this tool. More or more serious documented incidents score higher.
Integration scope
Weight 2How much access the tool asks for: from a standalone chat box up to connectors and actions inside your own systems.
Vendor trust
Weight 2Transparency about ownership and the underlying model, track record and maturity of the company.
From score to risk band
DeepSeek
Critical 86/100DeepSeek · China
Why this assessment
- · Trains on your input by default.
- · Vendor jurisdiction (CN) allows state access; no GDPR adequacy.
- · No data-processing agreement (DPA) available.
Incidents, with a source
- 2025 · Public share links indexed by search engines source
- 2025 · Regulator blocked the app over data transfers to China source
Where a tool has a history, that history is listed with a link to the source. When a verified source is missing, the product says so in as many words. That keeps it a fact rather than a rumour.
EU AI Act
Every tool classified under the AI Act as well.
Next to our own risk assessment, every tool gets a classification under the EU AI Act. We keep those two apart on purpose: the risk score is our reading, the classification is about the duties the law attaches to a use.
Falls under a high-risk category of the EU AI Act (Annex III).
Transparency duty (Art. 50): must disclose it is AI, or label generated content.
No specific EU AI Act duties for this use.
The classification depends on which feature you use.
Infrastructure with no use of its own. Classification depends on what runs on it.
Not legal advice; based on the vendor's documented intended use.
What high risk covers (Annex III)
Where a tool lands on high risk, the product names the category that applies.
- 1 Biometric identification and categorisation
- 2 Critical infrastructure
- 3 Education and vocational training (exams, admission, assessment)
- 4 Recruitment, selection and workforce management
- 5 Access to essential services, such as creditworthiness and insurance underwriting
- 6 Law enforcement
- 7 Migration, asylum and border control
- 8 Administration of justice and democratic processes
The full assessment, on one screen.
Open a tool and you see it all together: the score with its per-dimension breakdown, why the assessment lands where it does, the EU AI Act classification next to it, and the documented incidents with their source. At the bottom you set the policy, and that decision is yours.
Why this assessment
Risk breakdown
Higher = more risk (5 = worst)
EU AI Act
Limited riskTransparency duty (Art. 50): must disclose it's AI, or label generated content.
Not legal advice; based on the vendor's documented intended use.
Incidents
What your people see.
Turn on coaching and opening a tool that is not approved shows a notice from BeeSensible, right in the page. It leads with the approved alternative: one click on "Open Claude" and the person is working in a tool you stand behind. The safer options come from the catalog, but you decide which one is offered first. Continuing is always possible, never by reflex: for a not-allowed tool it takes a deliberate press-and-hold. Try both versions below.
Grok is not allowed here
Your organisation does not allow this tool for work. Use an allowed alternative.
Discovered, never traced to a person
When someone opens an AI tool, only the website's domain is counted, added up across the team. No names, no content, no individual tracking.
A recommendation for every tool
Every tool in the catalog comes with a suggested policy based on its risk. You confirm or override it. Your own decision always wins, on every screen and in the extension.
A nudge, not a block
Open a tool that is not approved and a gentle notice appears in the browser, leading with the approved alternative. People can still continue.
See whether your decision lands.
Every notice is counted with what happened next: the alternative opened, or continued anyway. Per decision you see those outcomes side by side, in counts and never per person. If a not-allowed tool stays busy, that is not a verdict on your people but a question for your policy: is the alternative good enough, or was the line drawn in the wrong place?
The watchful view, for the DPO and CISO.
Adoption is the positive story; Risk is the one that flags what needs your attention: disallowed tools still in use, undecided tools with real activity, and tools growing fast. A policy-compliance figure shows the share of AI use that runs through approved tools, and its trend, so you can see whether the gap is closing.
See your shadow AI as it happens.
Roll out the extension and watch the list of AI tools fill in, with no agent rollout and no log collection.