Control over AI
Documentation
AI Tools (Shadow AI)

Catalog: browse tools, review risk, set policy

Hundreds of known AI tools, each with a risk assessment. Filter, open any tool, and set policy in bulk.

Catalog

Browse every known AI tool, filter on risk and properties, and set policy in bulk.

Add your own tool
BeeSensible added 3 new platforms to the catalog.
AllShadow AI18With activity34New3
Search tool, vendor or category…
Filters8 tools
ToolSectorCountryVisitsRiskPolicy
DeepSeekNew
DeepSeek
GeneralChina412Critical · 92Not allowededited
GrokNew
xAI
GeneralUnited States96High · 74No decision yet
ChatGPT
OpenAI
GeneralUnited States8,124High · 62Allowed
PerplexityNew
Perplexity AI
ResearchUnited States188Medium · 51No decision yet
Claude
Anthropic
GeneralUnited States2,310Medium · 48Allowed
Midjourney
Midjourney
CreativeUnited States72Medium · 46No decision yet
Copilot
Microsoft
ProductivityUnited States268Medium · 44Limited use
Mistral
Mistral AI
GeneralFrance143Low · 30No decision yet
The Catalog lists every known AI tool with sector, jurisdiction, risk band, and policy, so you can filter and set policy in bulk.

The catalog holds every known AI tool: more than 700 of them, each with a risk assessment already done. It is where you decide what your organisation allows, and where you steer people towards safer options. Policy is default-deny: every tool starts at No decision yet until your organisation says otherwise, and a risk band is advice, never a decision BeeSensible makes for you.

Catalog in the dashboardUnder AI Governance in the menu; also where you add your own tools.

Browsing and filtering

Each row shows the tool with its vendor, its sector, the vendor's country, its visits in your organisation (last 30 days), its risk band with score, and its current policy. You can:

  • use the quick filters: All, Shadow AI (self-serve tools without a yes from the organisation that are being used anyway), With activity, and New; within With activity you can slice further by status
  • filter via the Filters button on risk level, sector, category, vendor country, access, tag, and certification, and search by tool, vendor, or category
  • sort on any column by clicking its header, for example by risk or by visits
  • add an internally sanctioned tool with Add your own tool; it appears with the Own badge alongside the global catalog and can be picked as an allowed alternative

The catalog is continuously curated: BeeSensible scans the web for new AI tools, assesses them, and adds them with the full fact sheet. Added tools carry a New badge for 30 days and can be found through the New quick filter; a dismissible banner at the top tells you how many arrived since your last visit.

Setting policy

Every tool has one of four statuses: Allowed, Limited use, No decision yet, or Not allowed. You set a status per row through the status control in the Policy column, or in bulk:

Select tools

Tick tools; shift-click selects a range, and the checkbox in the header selects everything your filter shows.

Pick a status in the bar at the bottom

As soon as anything is selected, a bar appears at the bottom with the four statuses. One click applies the status to the whole selection.

For Limited use: write the condition

Choosing Limited use first opens the dialog "What are the limits for this tool?", asking for the condition employees will see. The field comes pre-filled with the common rule and ready-made lines sit below it; short and concrete works best (200 characters at most). Confirm with Allow with limits.

Reviewing a tool

Click a row and you get the full detail view, built to answer one question quickly: is this tool safe enough for our people, and if not, where should they go instead? The policy buttons sit at the bottom of the view, visible on every tab.

DeepSeek
DeepSeek· ChinaGeneralGeneral assistantdeepseek.com
Critical · 86/100

Why this assessment

·Trains on your input by default.
·Vendor jurisdiction (CN) allows state access; no GDPR adequacy.
·No data-processing agreement (DPA) available.

Risk breakdown

Higher = more risk (5 = worst)

Data governance
5/5
Jurisdiction
5/5
Compliance
4/5
Incidents
4/5
Integration scope
2/5
Vendor trust
4/5

EU AI Act

Limited risk

Transparency duty (Art. 50): must disclose it's AI, or label generated content.

Not legal advice; based on the vendor's documented intended use.

Incidents

2025 · Public share links indexed by search engines source
2025 · Regulator blocked the app over data transfers to China source
Policy: Not allowed
AllowedLimited useNo decision yetNot allowed
Each tool has a full risk breakdown, sourced incidents, and safer alternatives you can recommend to staff.

Overview

The Overview tab opens with the tool's use in your own organisation (visits in the last 30 days, with a click-through to the Usage tab) and its Properties: trains on input, data residency, integration, DPA available, underlying model, access, and certifications.

Risk and compliance

The Risk & compliance tab shows the risk band with its score, and under "Why this assessment" the reasons behind it. The Risk breakdown scores the tool on six dimensions, each from 1 to 5: Data governance, Jurisdiction, Compliance, Incidents, Integration scope, and Vendor trust. Next to it sit an EU AI Act card with the tool's classification and the documented incidents, each with a source, so the assessment is not a black box. Bands run from Low to Critical.

Alternatives

The Alternatives tab lists allowed alternatives with the reason for each. Through Add an alternative you pin the one your organisation prefers; it then shows as Pinned at the top, and employees see it first in the note when they open a tool that is not allowed.

Usage

If the tool has activity, the Usage tab shows how often and when it is used and what for, so you can prioritise the tools that carry the most real exposure.

Guiding people, not blocking them

Policy is a note, not a wall; nothing in BeeSensible blocks sending or opening a tool. What employees see in the browser depends on the status:

StatusWhat employees see
AllowedNever a note.
Limited useA note with your own condition and the button "Hold to continue anyway".
No decision yetA calm note: only enter public information, with a plain "Continue anyway" button.
Not allowedA note leading with your allowed alternatives and the button "Hold to continue anyway".

Whether a status actually shows a note is your call, per status, under Organisation, in Organisation settings:

Coaching

StatusSwitchDefault
Not allowedNote with "hold to continue anyway" and an allowed alternativeOn
Limited useThe same note, with the condition you set on the toolOn
No decision yetA calm note; off by default, so new catalog tools never nudge on their ownOff
AllowedNever shows a noten/a

The layer for tools without a decision is a deliberate opt-in: switch it on and the calm note applies to everything not yet decided. How often notes are shown and what people do with them appears on Risk, under Warnings about tools.

Tips

  • Start with the Shadow AI quick filter: those are the tools in real use without a yes from the organisation. That is where your data is most exposed.
  • Leave a tool at No decision yet while you gather information; that is also where every tool starts.
  • Revisit Not allowed tools now and then. A tool may come to meet your requirements later, or a better alternative may appear.