Control over AI
Documentation
AI Tools (Shadow AI)

Risk: shadow AI and policy compliance

Which AI use falls outside the lines, and what needs your attention. Anonymous, never tied to individual users.

Risk

Shadow AI and policy: which AI use falls outside the lines and what needs your attention. Anonymous, never tied to individual users.

Refresh
7 days30 days90 days
31 Jul 2026 – 30 Aug 2026
Requires action
Disallowed tools still in use, heavy use without a decision, and new tools awaiting triage.
DeepSeek is not allowed but was visited 12 timesdecided 12 days agoCriticallast seen yesterday
Poe awaits a decision and already has 14 visitsHighNo decision yetlast seen today
Grok usage is growing fast: 120% more visits than the week beforeHighNo decision yetlast seen today
Luma AI newly discovered, no decision yetReview in inbox
Policy compliance
83%
of AI use via allowed tools
Visits to disallowed tools
12
of 1,734 AI visits this period
In use without a decision
3
tools awaiting your decision
AI tools used
Every AI tool seen in this period, with your policy, its risk profile and how much it is used. Anonymous counts, never tied to individual users.
ToolStatusRiskVisitsLast seen
ChatGPT
chatgpt.com
AllowedMedium81230 Aug
Claude
claude.ai
AllowedMedium40230 Aug
Copilot
copilot.microsoft.com
Limited useMedium26830 Aug
DeepL
deepl.com
AllowedLow22930 Aug
Poe
poe.com
No decision yetHigh1430 Aug
DeepSeek
deepseek.com
Not allowedCritical1229 Aug
Grok
grok.com
No decision yetHigh630 Aug
Risk shows what falls outside policy: disallowed tools still in use, undecided tools, and policy compliance.

Where Adoption is the positive view, Risk is the watchful one: the screen for the DPO or CISO who wants to know what falls outside policy and needs attention now.

Requires action

The top of the page is a priority-ordered list of what needs a decision:

  • Disallowed tools still in use, each showing when the decision was made.
  • Undecided tools with real usage: "awaits a decision and already has this many visits".
  • Fast growers: usage climbing sharply against the week before.
  • Newly discovered tools, each with a Review in inbox link to the Inbox.

An undecided tool carries the status control right on its row, so you decide from the signal itself instead of hunting through the catalog first. When there is nothing, the list says so in as many words: "Nothing out of line in this period."

The DPO figures

Three numbers answer the questions a DPO or CISO asks first:

  • Policy compliance: the share of AI use that runs through allowed tools, with its trend against the previous period.
  • Visits to disallowed tools: how often people still reached a tool the organisation said no to.
  • In use without a decision: how many tools have real activity but no status yet.

Warnings about tools

The Warnings about tools card shows what the coaching in the browser is doing: how often a note was shown the moment someone opened a tool with no decision, or one that is limited or disallowed, and what share of those chose an alternative.

Per status you see the outcomes side by side: alternative opened, or continued anyway. On No decision yet, continuing is a single click; on Limited use and Not allowed it takes a press-and-hold, which the card counts separately as "held through". This is about the tool itself, not about what gets typed into it. Counting is at most once per tool per day, browser use only (there is no coaching in the desktop app), and always group figures, never who.

Which statuses show a note is up to you, via the coaching switches; see the catalog for what employees see per status.

Departments

With Department insights switched on (Organisation, under Organisation settings), this page also shows a Departments card, listing per department how many non-allowed tools are in use and what share of AI use runs through allowed tools. A department filter then sits next to the date picker, scoping the whole page to one department. In Standard mode, departments below the minimum size are combined and a period of at least 7 days is required.

The tool table

At the bottom sits every AI tool seen in the period, with its status, risk band, visit count, and when it was last seen. Click a tool name to open the full risk analysis, the same view as in the catalog, policy buttons included.

What stays private

Everything on this page is anonymous counts: no message content, no user id in the AI-usage figures, no individual report. The organisation can see that policy compliance is 83%, never who the other 17% were.