Control over AI
Blog
Trust and proof 8 min read

What are all those AI metrics for? From dashboard to accountability

Detections, shadow AI, AI use per tool: the numbers are easy to collect. The question is what they get you with the GDPR, NIS2, and the AI Act. On seeing, helping, and substantiating, and why the order matters.

Loose data points flowing into a structure and emerging as ordered charts
Quick answer

Metrics about AI use are only worth something when they answer a question a supervisor, auditor, or works council actually asks. BeeSensible collects three kinds of insight: which AI tools are really in use (see), how much sensitive data got a highlight before sending and what happened to it (help), and the translation of those observations into substantiation per framework and per measure (substantiate). That supports the GDPR's accountability principle, the demonstrability the Dutch NIS2 law asks for, and the AI register under the AI Act. Always as counts, never the text, never one person.

01

Metrics only become evidence when they answer a supervisor's or auditor's question

02

See: which AI tools are really in use, at what risk, and what you decided

03

Help: every highlight is a helped moment, the numbers are the byproduct

04

Substantiate: the same observations become substantiation per framework and measure

05

Always aggregated: never the text, never one person, groups under ten not shown

Every dashboard looks impressive: 312 detections this month, fourteen AI tools in use, five newly discovered. But the most honest question any board member can ask is: what do I get out of this? Research shows why the question is urgent: 57 percent of employees hide their AI use from their employer, and nearly half sometimes put sensitive company data into public AI tools. So there is no shortage of numbers. The difference is what they let you do the moment a supervisor, auditor, or works council asks a question.

Why loose statistics prove nothing

The GDPR, the Dutch NIS2 law, and the AI Act ask for the same thing at their core: not just policy, but measures that demonstrably work. The GDPR's accountability principle wants you to be able to show you comply. The duty of care in the Cyberbeveiligingswet wants control you can substantiate. The AI Act wants you to know which AI you use and to have staff working with it responsibly.

A chart of detections answers none of those questions by itself. A chart becomes evidence when a line of reasoning is attached: this is the risk, this is the measure, and here you can see the measure working. That is exactly the movement BeeSensible connects: seeing where the risk sits, deciding which measure fits, helping people with it during their work, and substantiating that it works.

See: what actually happens, not what you hope

The first question in every framework is an inventory question. Which AI services does your organisation use, and what did you decide about them? Most organisations answer it with a spreadsheet that was outdated the day it was finished.

The dashboard answers it continuously: which AI tools are in use, how often, and at what risk, checked against a catalog of more than 700 assessed tools. New tools appear on their own, with a policy suggestion based on the risk. You decide: approve, or disallow with a pointer to the approved alternative.

For accountability, that delivers two things. A current register of AI services, with vendor, hosting, and a decision per tool. And sight of the gap between policy and practice: how much of the AI use runs through approved tools, and is that moving the right way?

Search tool, vendor or categoryโ€ฆ
700+ tools
ChatGPT๐Ÿ‡บ๐Ÿ‡ธ
HighAllowed
Claude๐Ÿ‡บ๐Ÿ‡ธ
MediumAllowed
DeepSeek๐Ÿ‡จ๐Ÿ‡ณnew
CriticalNot allowed
Perplexity๐Ÿ‡บ๐Ÿ‡ธnew
MediumNo decision yet
Mistral๐Ÿ‡ซ๐Ÿ‡ท
LowNo decision yet
Midjourney๐Ÿ‡บ๐Ÿ‡ธ
MediumNo decision yet

Every tool, scored for risk

700+ AI tools, each scored Low to Critical, with nothing pre-approved or pre-blocked until someone decides.

More about AI Tools

Help: the numbers are the byproduct, not the goal

This is where many monitoring tools go wrong: they collect numbers about employees. BeeSensible flips it. The highlight at the moment of typing is there for the employee: name and date of birth in yellow, account and card details in red, with the choice to replace, mask, or delete before sending. Nothing is blocked and nothing is stored.

Every highlight is first of all a helped moment. That a counter runs alongside is the byproduct. But a valuable one: if 86 percent of critical detections are handled before the message leaves the building, that is no longer an intention but a working measure. Exactly the kind of sentence you want to be able to write in a DPIA or an audit report.

And because the numbers are about behaviour rather than people, the conversation with the works council stays clean: counts, never the text, never one person, and no per-employee breakdown anywhere. Where that line runs is covered in can an employer monitor AI use.

Detections over timeLast 30 days
12,438+18% vs the previous period
Detections by platform
ChatGPT
ChatGPT
78% adjusted
8,124
Gmail
81% adjusted
3,210
Gemini
74% adjusted
812
Most encountered data types
Name
4,212
Email address
2,930
Credit card
1,486
Account number
1,104
Diagnosis
612
SensitiveHighly sensitive
BeeSensible dashboard: aggregated detections and top sources, without monitoring individuals.

Substantiate: the same observations, every framework

The third step is the translation, and it is new for most organisations. The same set of observations answers a different question in each framework:

  • GDPR. Appropriate measures and data minimisation at the input moment, with numbers on detections and follow-up as substantiation for the accountability principle, an audit, or a DPIA.
  • NIS2 and the Cyberbeveiligingswet. A register of AI services for the supply chain, and proof that the control measure runs, as substance for the duty of care.
  • AI Act. The AI register every organisation needs, and the highlights as a working form of AI literacy: guidance at the moment it counts.

The accountability view in the dashboard makes that translation explicit, per framework and per measure. And it is honest about the boundary: what BeeSensible cannot substantiate is shown as such.

See

Which AI tools are actually in use, how often, and at what risk. Every tool scored against a catalog of more than 700.

See the AI Tools module
Decide

Every tool's status is the organisation's own call: allowed, limited, not allowed. The risk score is advice, never a verdict.

Help

That decision shows up while someone works: a notice on the tool, a highlight while you type. Never a block.

See Realtime Privacy
Substantiate

The same observations become substantiation: aggregated figures per framework and per measure. Never the text, never one person.

Dashboard ยท Accountability GDPRNIS2AI Act
  • Register of AI services

    Vendor, hosting, and a decision per tool

    Substantiated
  • AI literacy

    Highlights at the moment of typing and figures on how they were handled

    Substantiated
  • Appropriate security

    Critical data highlighted and handled before sending

    Substantiated
  • Data breach procedure

    BeeSensible provides the early signal; reporting and follow-up remain your own process

    Not substantiated
One set of observations, usable as substantiation in every framework. BeeSensible supports compliance; it does not make you compliant by itself.

What the numbers are not

Two things to keep sharp. The numbers are not a personnel file: anyone who wants to manage individual employees is in the wrong place with BeeSensible, and that is a deliberate choice. And the numbers are not a compliance stamp: BeeSensible supports compliance, it does not make you compliant by itself. The legal basis, the policy, and the responsibility stay with the organisation.

Four questions you can now actually answer

  1. Which AI do we use, and is it allowed? The register, current, with a decision per tool.
  2. Does our policy work? The share of AI use through approved tools, and the share of detections handled before sending.
  3. Where is the risk? Detections per data type and per source, so policy and training focus where it pinches.
  4. What do we show the auditor? The substantiation per framework and per measure, from the same observations.

Start with those four questions and every dashboard looks different afterwards: not a report, but the place where policy, behaviour, and evidence come together.

Further reading: the AI Act timeline after the Digital Omnibus and the Netherlands has its NIS2 law.

FAQ

Common questions

Which numbers does BeeSensible show?

Three kinds: which AI tools are in use, how often and at what risk (checked against a catalog of more than 700 assessed tools), how much sensitive data got a highlight and how it was handled, and the translation of those observations into substantiation per framework, such as the GDPR, NIS2, and the AI Act.

Can I see which employee typed something?

No. The dashboard shows aggregated counts only: never the text, never one person. There is no per-employee breakdown anywhere. Insight into patterns, not surveillance of people.

Does this count as evidence for the GDPR's accountability principle?

It supports it. The GDPR asks you to take appropriate measures and to be able to demonstrate compliance. Numbers on detections and follow-up show that a measure at the input moment exists and works. It does not replace your wider accountability; it fills it with working practice.

Does this work for NIS2 and the Dutch Cyberbeveiligingswet?

Yes, in the same way. The duty of care asks for demonstrable control of risks, including the supply chain. A current register of AI services with a decision per tool, plus numbers showing the policy is followed, are direct substantiation for that.

Does this replace a DPIA or an audit?

No. It feeds them. A DPIA describes risks and measures; the numbers show those measures actually run in practice. Auditors ask for exactly that: not just what you agreed, but whether it happens.