Map unsanctioned AI tools against the regulatory frameworks that matter to your organisation. Each guide shows exactly which controls a shadow AI audit satisfies.
Choose the regulation or standard your organisation must demonstrate compliance with.
Article 6 risk classification, Article 9 risk-management obligations, and the inventory requirement that makes shadow AI a compliance gap under the EU AI Act.
Read guideArticle 30 processing records, Article 35 DPIA triggers, lawful basis gaps, and cross-border transfer risks created by unsanctioned AI tools.
Read guideAnnex A control mapping, asset-inventory requirements, and the audit evidence a shadow AI scan produces for your ISMS certification or surveillance audit.
Read guidePHI exposure risks when clinicians and administrators use AI tools without BAAs. Technical safeguard gaps and breach-notification triggers.
Read guideBuild a complete AI tool inventory as the foundation for any governance programme. Map tool owners, data flows, risk levels and sanctioning decisions.
Read guideExplore role-specific compliance guidance and platform-level detection guides.
A single DNS log export produces the AI tool inventory your auditors and regulators expect.
Start Your Free Audit