Control over AI
AI Governance

See which AI tools your team uses.

Most teams cannot say which AI tools are running in their org. BeeSensible shows each one as it appears, counted anonymously, with a risk assessment and a suggested policy already attached. You decide what is allowed without starting from a blank page.

app.beesensible.eu/shadow-ai
AI tools in use
7
Newly discovered
2
ChatGPT8,124 visitsAllowed
Claude2,310 visitsAllowed
DeepSeek412 visitsNot allowed
PerplexityNew188 visitsNo decision yet

The method

The same four steps, now for your AI tools.

Every BeeSensible module follows this cycle. Here is what it looks like for managing AI tools.

1 See

Which AI actually runs

Every AI tool your people open shows up, counted anonymously, including the ones nobody ever requested.

3 Help

Your decision at the moment of work

When someone opens a tool you decided on, they see that decision, with the approved alternative leading.

4 Substantiate

What the policy delivers

The share of AI use through approved tools, the tools still missing a decision, and the trend behind it.

and again How the cycle works

app.beesensible.eu/shadow-ai/inbox
2 newly discovered AI tools await your decision
Grok
grok.com
HighAllowDisallow
Luma AI
lumalabs.ai
MediumAllowDisallow
Inbox

New tools land in an inbox.

The moment a new AI tool shows up in your org, it waits for a decision: allow it, allow it within a condition you set, disallow it, or decide later. Every tool starts with no decision, and nothing comes pre-selected. Confirm one at a time or decide a whole batch at once; the organisation always calls it, never BeeSensible.

Catalog

700+ AI tools, already assessed.

The catalog holds more than 700 AI tools, each scored for risk by BeeSensible: from Low to Critical, with the vendor, its country, and certifications on the row. Filter on what matters to you, select a range, and set policy on many tools in one go. Tools your people have never opened are covered before anyone tries them.

And it keeps growing. Tools discovered in organisations and in BeeSensible's own research land in a review queue, get assessed, and join the catalog with the full fact sheet, so keeping track is no longer your job. New arrivals carry a badge in the catalog for 30 days.

app.beesensible.eu/shadow-ai/catalog
Search tool, vendor or category…
700+ tools
ChatGPT🇺🇸
HighAllowed
Claude🇺🇸
MediumAllowed
DeepSeek🇨🇳new
CriticalNot allowed
Perplexity🇺🇸new
MediumNo decision yet
Mistral🇫🇷
LowNo decision yet
Midjourney🇺🇸
MediumNo decision yet

Risk assessment

How a tool gets its score.

Every tool in the catalog is scored on six dimensions, each from 1 to 5, where higher means more risk. The dimensions do not weigh the same: what the vendor does with your data counts heaviest.

Data governance

Weight 6

How the vendor handles your data: whether it trains on your input, offers a processing agreement, and where data is stored.

Jurisdiction

Weight 4

Legal risk from where the vendor and its data live. Countries allowing state access or lacking GDPR adequacy score higher.

Compliance

Weight 3

Alignment with GDPR and the EU AI Act, plus recognised certifications such as ISO 27001 and SOC 2.

Incidents

Weight 3

History of breaches, leaks or misuse tied to this tool. More or more serious documented incidents score higher.

Integration scope

Weight 2

How much access the tool asks for: from a standalone chat box up to connectors and actions inside your own systems.

Vendor trust

Weight 2

Transparency about ownership and the underlying model, track record and maturity of the company.

From score to risk band

Low below 40 Medium 40 to 59 High 60 to 79 Critical 80 and above

DeepSeek

Critical 86/100

DeepSeek · China

Why this assessment

  • · Trains on your input by default.
  • · Vendor jurisdiction (CN) allows state access; no GDPR adequacy.
  • · No data-processing agreement (DPA) available.

Incidents, with a source

  • 2025 · Public share links indexed by search engines source
  • 2025 · Regulator blocked the app over data transfers to China source

Where a tool has a history, that history is listed with a link to the source. When a verified source is missing, the product says so in as many words. That keeps it a fact rather than a rumour.

EU AI Act

Every tool classified under the AI Act as well.

Next to our own risk assessment, every tool gets a classification under the EU AI Act. We keep those two apart on purpose: the risk score is our reading, the classification is about the duties the law attaches to a use.

High risk

Falls under a high-risk category of the EU AI Act (Annex III).

Limited risk

Transparency duty (Art. 50): must disclose it is AI, or label generated content.

Minimal risk

No specific EU AI Act duties for this use.

Depends on use

The classification depends on which feature you use.

Not classifiable

Infrastructure with no use of its own. Classification depends on what runs on it.

Not legal advice; based on the vendor's documented intended use.

What high risk covers (Annex III)

Where a tool lands on high risk, the product names the category that applies.

  1. 1 Biometric identification and categorisation
  2. 2 Critical infrastructure
  3. 3 Education and vocational training (exams, admission, assessment)
  4. 4 Recruitment, selection and workforce management
  5. 5 Access to essential services, such as creditworthiness and insurance underwriting
  6. 6 Law enforcement
  7. 7 Migration, asylum and border control
  8. 8 Administration of justice and democratic processes
Tool detail

The full assessment, on one screen.

Open a tool and you see it all together: the score with its per-dimension breakdown, why the assessment lands where it does, the EU AI Act classification next to it, and the documented incidents with their source. At the bottom you set the policy, and that decision is yours.

DeepSeek
DeepSeek· ChinaGeneralGeneral assistantdeepseek.com
Critical · 86/100

Why this assessment

·Trains on your input by default.
·Vendor jurisdiction (CN) allows state access; no GDPR adequacy.
·No data-processing agreement (DPA) available.

Risk breakdown

Higher = more risk (5 = worst)

Data governance
5/5
Jurisdiction
5/5
Compliance
4/5
Incidents
4/5
Integration scope
2/5
Vendor trust
4/5

EU AI Act

Limited risk

Transparency duty (Art. 50): must disclose it's AI, or label generated content.

Not legal advice; based on the vendor's documented intended use.

Incidents

2025 · Public share links indexed by search engines source
2025 · Regulator blocked the app over data transfers to China source
Policy: Not allowed
AllowedLimited useNo decision yetNot allowed
Coaching

What your people see.

Turn on coaching and opening a tool that is not approved shows a notice from BeeSensible, right in the page. It leads with the approved alternative: one click on "Open Claude" and the person is working in a tool you stand behind. The safer options come from the catalog, but you decide which one is offered first. Continuing is always possible, never by reflex: for a not-allowed tool it takes a deliberate press-and-hold. Try both versions below.

BeeSensiblenotice
Not allowed

Grok is not allowed here

Your organisation does not allow this tool for work. Use an allowed alternative.

Use instead
Open Claude
Also allowed: ChatGPT·Mistral Le Chat
Hold to continue anyway

Discovered, never traced to a person

When someone opens an AI tool, only the website's domain is counted, added up across the team. No names, no content, no individual tracking.

A recommendation for every tool

Every tool in the catalog comes with a suggested policy based on its risk. You confirm or override it. Your own decision always wins, on every screen and in the extension.

A nudge, not a block

Open a tool that is not approved and a gentle notice appears in the browser, leading with the approved alternative. People can still continue.

Warnings about tools
Shown the moment someone opens a tool you have not decided on, or have limited or disallowed. About the tool itself, not about what gets typed into it.
148
warnings shown
61%
chose an alternative
Not allowed52 times
38 alternative9 held through
Limited use44 times
21 alternative15 held through
No decision yet52 times
31 alternative14 clicked through
alternative openedcontinued anyway
Browser use only. Counted at most once per tool per day. Group figures only, never who.
What happens after the notice

See whether your decision lands.

Every notice is counted with what happened next: the alternative opened, or continued anyway. Per decision you see those outcomes side by side, in counts and never per person. If a not-allowed tool stays busy, that is not a verdict on your people but a question for your policy: is the alternative good enough, or was the line drawn in the wrong place?

Risk

The watchful view, for the DPO and CISO.

Adoption is the positive story; Risk is the one that flags what needs your attention: disallowed tools still in use, undecided tools with real activity, and tools growing fast. A policy-compliance figure shows the share of AI use that runs through approved tools, and its trend, so you can see whether the gap is closing.

app.beesensible.eu/shadow-ai/risk

Risk

Shadow AI and policy: which AI use falls outside the lines and what needs your attention. Anonymous, never tied to individual users.

Refresh
7 days30 days90 days
31 Jul 2026 – 30 Aug 2026
Requires action
Disallowed tools still in use, heavy use without a decision, and new tools awaiting triage.
DeepSeek is not allowed but was visited 12 timesdecided 12 days agoCriticallast seen yesterday
Poe awaits a decision and already has 14 visitsHighNo decision yetlast seen today
Grok usage is growing fast: 120% more visits than the week beforeHighNo decision yetlast seen today
Luma AI newly discovered, no decision yetReview in inbox
Policy compliance
83%
of AI use via allowed tools
Visits to disallowed tools
12
of 1,734 AI visits this period
In use without a decision
3
tools awaiting your decision
AI tools used
Every AI tool seen in this period, with your policy, its risk profile and how much it is used. Anonymous counts, never tied to individual users.
ToolStatusRiskVisitsLast seen
ChatGPT
chatgpt.com
AllowedMedium81230 Aug
Claude
claude.ai
AllowedMedium40230 Aug
Copilot
copilot.microsoft.com
Limited useMedium26830 Aug
DeepL
deepl.com
AllowedLow22930 Aug
Poe
poe.com
No decision yetHigh1430 Aug
DeepSeek
deepseek.com
Not allowedCritical1229 Aug
Grok
grok.com
No decision yetHigh630 Aug

See your shadow AI as it happens.

Roll out the extension and watch the list of AI tools fill in, with no agent rollout and no log collection.