Compliance Hub

Shadow AI Compliance Guides

Map unsanctioned AI tools against the regulatory frameworks that matter to your organisation. Each guide shows exactly which controls a shadow AI audit satisfies.

Compliance Frameworks

Choose the regulation or standard your organisation must demonstrate compliance with.

EU AI Act and Shadow AI

Article 6 risk classification, Article 9 risk-management obligations, and the inventory requirement that makes shadow AI a compliance gap under the EU AI Act.

Read guide

GDPR and Shadow AI

Article 30 processing records, Article 35 DPIA triggers, lawful basis gaps, and cross-border transfer risks created by unsanctioned AI tools.

Read guide

ISO 27001 Shadow AI Evidence

Annex A control mapping, asset-inventory requirements, and the audit evidence a shadow AI scan produces for your ISMS certification or surveillance audit.

Read guide

HIPAA and Shadow AI

PHI exposure risks when clinicians and administrators use AI tools without BAAs. Technical safeguard gaps and breach-notification triggers.

Read guide

AI Governance Inventory

Build a complete AI tool inventory as the foundation for any governance programme. Map tool owners, data flows, risk levels and sanctioning decisions.

Read guide

Related Resources

Explore role-specific compliance guidance and platform-level detection guides.

Role Guide
For DPOs
GDPR Article 30 mapping and DPIA triggers.
Role Guide
For Compliance Officers
Multi-framework evidence packs.
Role Guide
For Internal Auditors
Workpaper-ready evidence and standards mapping.

Generate Compliance Evidence from Your Logs

A single DNS log export produces the AI tool inventory your auditors and regulators expect.

Start Your Free Audit
View pricing →