Control over AI
Substantiate

Show that your policy works.

Policy on paper does not tell you what happens next. Substantiate shows, per measure, what the figures from BeeSensible carry: what happened with markings and notices, what share of AI use runs through approved tools, and how that lands on GDPR and NIS2. Without a single employee in view.

Accountability GDPRNIS2
  • Data minimisation at input

    Sensitive data marked and handled before sending

    Substantiated
  • Register of AI services

    Vendor, classification, and a decision per tool

    Substantiated
  • Appropriate security

    Highly sensitive data marked and handled, with figures per period

    Substantiated
  • Data breach procedure

    BeeSensible provides the early signal; reporting stays your own process

    Not substantiated

The method

The same four steps, now for your accountability.

Every BeeSensible module follows this cycle. Substantiate is the fourth step, and the start of the next round.

1 See

The figures already arrive

Markings, notices, and AI use arrive as counts: per type, per app, per period. Never per person.

2 Decide

Which frameworks count

You switch Accountability on per organisation and work with the frameworks that apply to you: GDPR and NIS2.

3 Help

The moment of work delivers the proof

Every marking that gets fixed and every notice that is followed counts. The evidence forms where the work happens.

and again How the cycle works

Warnings about tools
Shown the moment someone opens a tool you have not decided on, or have limited or disallowed. About the tool itself, not about what gets typed into it.
148
warnings shown
61%
chose an alternative
Not allowed52 times
38 alternative9 held through
Limited use44 times
21 alternative15 held through
No decision yet52 times
31 alternative14 clicked through
alternative openedcontinued anyway
Browser use only. Counted at most once per tool per day. Group figures only, never who.
AI Governance

What people did with a notice.

Every notice counts along with what happened next: the alternative opened, or continued anyway. Per decision, from not allowed to no decision yet, you see those outcomes side by side. If a disallowed tool stays busy, that is a question for your policy and not a judgement of your people.

Realtime Privacy

What happened with markings.

Of everything marked, you see which share was replaced, masked, or removed before sending, and which share was sent anyway. Highly sensitive data separately. That is data minimisation at the moment of input, in figures per period.

Sent despite warning
1,120
Detected, not adjusted, and still sent.
Critical sent despite warning
214
14% of critical detections
OutcomesLast 30 days
9,702
adjusted before sending
78% of 12,438 detections
Replaced4,318(35%)
Masked3,110(25%)
Removed2,274(18%)
Sent despite warning1,120(9%)
No action recorded1,616(13%)
Accountability

An honest status per measure.

Accountability maps the same figures onto the measures per framework. Per measure you see whether the figures carry it. So a data protection officer, CISO, or board member knows exactly what you can and cannot say.

Substantiated

The figures carry the measure: enough was measured, over a long enough period, to say something about it.

Not substantiated

The figures say nothing about this one. So that is what it says, instead of a green tick that means nothing.

Too little data

Where coverage is still thin, BeeSensible shows that, instead of presenting thin data as proof.

The frameworks

What the law asks, and what you substantiate with BeeSensible.

Three frameworks that apply at the same time in almost every organisation. Per framework: what it asks, which figures from BeeSensible contribute, and what stays with you.

GDPR

General Data Protection Regulation

What it asks

  • Data minimisation and purpose limitation (Art. 5)
  • Appropriate technical and organisational measures (Art. 32)
  • Accountability: being able to demonstrate compliance (Art. 5(2))

What BeeSensible substantiates

  • Markings handled before sending, per type and per app
  • Highly sensitive data marked and handled, per period
  • A register of AI services with vendor, classification, and your decision per tool

Stays with you: The lawful basis, the DPIA, and breach notification stay your own process. BeeSensible provides the early signal.

NIS2

In the Netherlands: the Cyberbeveiligingswet

What it asks

  • Duty of care: manage risk, supply chain included
  • Management accountability for cybersecurity
  • Reporting duty for significant incidents

What BeeSensible substantiates

  • An overview of AI services with vendor, country, processing agreement, and documented incidents
  • Policy compliance as a figure: the share of AI use via approved tools, with its trend
  • Figures the board can steer on, without monitoring people

Stays with you: Whether the law applies to you, the wider security measures, and the report itself remain your responsibility.

EU AI Act

The AI regulation

What it asks

  • Knowing which AI systems you use and which risk category they fall in
  • Transparency duties for certain uses (Art. 50)
  • AI literacy: people who work with AI need to know what it does (Art. 4)

What BeeSensible substantiates

  • An EU AI Act classification per tool in the catalog, separate from our own risk score
  • A current register of the AI tools actually in use, with your decision
  • The notice at the moment of work brings your policy to the people who work with AI

Stays with you: Accountability covers GDPR and NIS2 today. The EU AI Act sits per tool in the catalog, not as a measure list of its own.

Not legal advice. BeeSensible supports compliance with these frameworks and guarantees no compliance.

The boundaries

What Substantiate is, and what it is not.

Supports, never certifies

BeeSensible supports your compliance with privacy rules. It certifies nothing and guarantees no compliance. You remain the controller; BeeSensible is the processor.

Honest where it stops

A measure the figures do not carry shows as 'Not substantiated'. That is not a shortcoming of the dashboard but the reason to trust it.

Never per person

Every figure is added up across the organisation. There is no per-employee drill-down, and the AI-usage figures arrive without a user id.

Switched on per organisation

Accountability is off by default. You switch it on per organisation; it needs the Realtime Privacy and AI Governance modules.

Substantiate your policy with what actually happens.

Start with See: roll out BeeSensible and look at what is already happening. Switch Accountability on once the first figures are in.