Annotated sample

The audit report, page by page

This is a guided tour of the sample Shadow AI Audit report: what each section shows, how to read it and what to do with it. The PDF itself is open to anyone, no signup.

3 pagesfrom summary tiles to evidence statement
37 toolsfound in the sample export
14 sourcesusers and devices in the breakdown
$99the same report on your own logs, one time
Before the tour

What the sample is, and is not

The sample uses clearly labeled example data. Everything else about it is exactly what a paying customer receives.

What it is

  • A real evidence pack rendered by the same engine that produces customer reports.
  • Sample data for a fictional 400-person company, labeled "Example Industries (sample data)" on every page.
  • Real, well-known AI tools in the tool table, with plausible risk and training values.
  • The exact structure your board, auditor or client would receive.

What it is not

  • Not a real customer's data. No real organization appears in it.
  • Not a free-preview PDF. The sample shows the full report; the preview withholds most tool names.
  • Not a marketing deck. There are no screenshots or mockups, only the generated document.
  • Not a commitment of what your numbers will be. Every network surprises differently.
The map

Three pages, five jobs

Each page of the PDF answers for a different reader. Leadership stops at page one; auditors read to the end.

Page 1: The verdict

Scope line, summary tiles and the policy profile split.

Reader: the executive who has 90 seconds. The five tiles are the whole story at a glance.

Page 2: The inventory

Findings at a glance, tools by category and the full tool table.

Reader: the IT or security lead who has to triage every row into sanction, control or block.

Page 3: The evidence

The per-user breakdown and the control evidence statement.

Reader: the compliance officer filing this for an audit period, and HR when a name needs a conversation.

Section tour

Every section, annotated

Follow along with the PDF open in another tab. Each stop shows the section and what to do with it.

1. The scope line

The first paragraph states whose export was read, the format, the line count and the register size it was matched against.

  • Check the window matches the period you meant to audit.
  • Quote this line verbatim in your risk register entry. It is the report's chain of custody.
From page 1

Shadow AI Audit: evidence pack

Scope: Example Industries (sample data). AI tools observed in the supplied network export, matched against our live register of 20,399 classified AI tool domains. Export format: csv. Lines read: 4,400.

From page 1
37AI tools found
5high-risk tools
15train on user data
2abusive-purpose tools
32not on sanctioned list

2. The summary tiles

Five numbers, colored by severity. This row is what gets screenshotted into slide decks.

  • "Train on user data" counts default-training plus opt-out tools together, because both expose past prompts.
  • A non-zero abusive-purpose count is always the first conversation. In the sample it is 2.

3. The policy profile split

Three tiles sort every tool into block, allow with controls, or allow, under a named policy profile. The sample applies the General business profile.

  • Treat this as a drafted decision, not a final one. The verdicts are a starting agenda for your review meeting.
  • "Allow with controls" means enterprise tier, SSO, no-training terms and logging. It is usually the largest group.
From page 1
5to block under the profile
28allow only with controls
4allowed as is

Profile: General business. A starting point to review before deployment.

From page 2
MeasureCount
AI-native tools30
AI-enabled platforms7
Trains by default5
Training terms not stated16
High sovereignty exposure2

4. Findings at a glance

A ten-row table that decomposes the headline numbers, each with a one-line meaning.

  • Watch the AI-enabled platform count. These are SaaS products that look sanctioned but now carry AI features.
  • "Training terms not stated" is typically the biggest training row. Our analysis of 13,000+ vendor terms finds 85.5% of AI tools say nothing about training in their public terms.

5. Tools by category

The 37 sample tools fall into 11 of the register's 18 categories. Text tools lead, image and code follow.

  • Categories map to departments. Image tools cluster in marketing, code assistants in engineering.
  • Use this table to decide who joins the triage meeting. Every category with 3+ tools earns its owner a seat.
From page 2
CategoryTools
Text & Language8
Image & Visual6
Code & Development5
Agents & Automation4
Search, Knowledge & Docs3
From page 2
DomainTrainingRiskUsers
chatgpt.comOpt-out switchmedium19
github.comDoes not trainlow14
character.aiTrains by defaulthigh3
deepseek.comOpt-out switchhigh3
deepswap.aiTrains by defaulthigh1

6. The tool table

The heart of the report: every matched tool with category, risk, training verdict, policy verdict, sanctioned flag, hits and user count.

  • Read it twice. First sorted by risk for the dangers, then by users for the habits.
  • One user on a deepfake domain is an incident. Nineteen users on a chatbot is a procurement decision.
  • Training verdicts carry the date the vendor terms were checked, which is what makes them citable.

7. Endpoints and users

Page 3 lists each identity that reached AI tools, with tool counts, hits and the most-used domains.

  • The sample shows department-prefixed accounts and one bare IP. Both shapes appear in real exports.
  • Use this table for coaching, not ambushes. Most shadow AI is initiative, not malice.

This table only appears when your export carries an identity column, and only in the full report. The how-it-works page shows where that column lives per log source.

From page 3
SourceMost usedToolsHits
SALES\b.moreauchatgpt, grammarly15371
ENG\j.lindqvistgithub, cursor13344
MKT\a.okonkwocanva, midjourney11298
EXT\10.24.8.117character.ai, seaart344
From page 3

Control evidence statement

"This report is generated from the organisation's own DNS, proxy or firewall export... Each matched domain carries its category, risk rating... with the date the vendor terms were last checked."

8. The control evidence statement

A closing paragraph written for auditors: what the report is, where the data came from and how it can be filed.

  • File the PDF unedited with the audit period it covers. The statement is worded to stand on its own.
  • ISO and internal auditors ask "how do you know?". This page is the answer, dated.

The export behind any report is read once and discarded. Reports stay in the account for 90 days and can be deleted earlier. Nothing else is retained.

Preview vs full

How the free preview differs from this sample

The sample shows the full report. The free preview is the same engine with most names withheld.

SectionFree previewFull report (the sample)
Summary tilesIncluded, full totalsIncluded, full totals
Tools by categoryIncludedIncluded
Tool tableA fifth of tools named, at least five; the rest as withheld rowsEvery tool named
Per-user breakdownNot includedIncluded when identities exist
Sanctioned splitCounts onlyFull split against your approved list
CSV exportNoYes
Shareable PDFYes, preview packYes, evidence pack

The withheld rows are drawn in the preview one per hidden tool, so you can count exactly what you are not seeing. Details on the free audit page.

Flip through the real thing before you upload anything

Three pages, sample data, no signup. If the format works for your board or your client, the same document is one log export away.

Open the sample report
Reproduce it

Getting this report on your own network

The sample took a 4,400-line CSV. Yours will take whatever your console exports this afternoon.

1

Export a window

30 days of DNS, proxy or firewall logs, with the identity column if you have one. The four-step walkthrough covers every console.

2

Run the free preview

Totals and the top tools, free, in minutes. Enough to know whether the full report is worth $99 to you.

3

Unlock the full report

One-time purchase, no subscription. Packs of 3 and 5 drop the per-report price, see pricing.

Label glossary

Every verdict label, decoded

The report uses a fixed vocabulary. Here is what each label commits to, and what it does not.

LabelIt meansIt does not mean
Trains by defaultThe vendor's consumer terms state or imply training on user content unless a higher tier changes it.That your specific plan trains. Enterprise tiers often carve it out.
Trains unless opted outA switch exists and defaults to on. Past prompts may already be in a training set.That anyone in your org has flipped the switch.
Does not trainThe vendor states it does not train on customer data, as of the checked date.That the terms cannot change next quarter. The date matters.
Not statedThe public terms do not answer the training question at all.That the tool is safe. Silence is the most common finding, at 85.5% in our analysis.
BlockUnder the applied policy profile, this tool would be denied.That anything has been blocked. The report is read-only evidence.
Allow with controlsAcceptable on an enterprise tier with SSO, no-training terms and logging.That the free tier your staff currently use qualifies.
Distribution

Who to hand each page to

The fastest way to waste a good report is sending all three pages to everyone. Split it by reader.

Executives

Page 1 only, plus one sentence of context. The tiles and the profile split carry the message alone. The CISO page covers the board framing.

IT and security

Page 2 and the CSV. They own the row-by-row triage into sanction, control and block.

Compliance

Page 3 and the scope line. The evidence statement is written to be filed, not summarized.

Department heads

Their category rows only. Marketing gets the image tools, engineering gets the code assistants.

For service providers

The sample as a sales document

MSPs and consultants use the sample to sell the assessment before running one. It answers the "what do I get" question without a meeting.

a

Attach it to the proposal

The deliverable stops being abstract. The client sees the exact document their engagement produces, with sample data.

b

Walk page 1 in the pitch

Five tiles, three verdicts, ninety seconds. Then ask what they think their own tile row looks like. Nobody knows, and that is the engagement.

c

Price against the pack

At the 5-pack rate a report costs $60. The MSP page and consultant page cover the per-engagement economics.

MSP plan reports carry the client name you enter, so each deliverable reads as the client's own document, not a shared template.

Context numbers

Three register numbers behind every report

The sample's verdicts are drawn from the same research layer as every customer report.

85.5%of AI tools say nothing about training in their public terms, across 13,000+ vendor terms reviewed in our analysis.
700+tools train on customer data by default. When one appears in your report, the verdict column flags it in red.
3,900+tools mapped to the model provider actually behind them, which is how the report catches rebranded wrappers.
Reading pitfalls

Four ways teams misread their first report

All four are avoidable once you know they exist.

Treating hits as people

  • Hits count log lines, not employees. One busy automation can outscore a whole department.
  • Read hits together with the user count column, never alone.

Panicking at the total

  • 37 tools sounds like chaos, but most land in "allow with controls".
  • The block list is usually short. Work it first and the total stops mattering.

Ignoring AI-enabled platforms

  • The tools nobody flags are sanctioned SaaS that quietly added AI features.
  • They passed procurement before the AI existed. The report is often the first place that gap becomes visible.

Skipping the dates

  • A training verdict without its checked date is an opinion. With the date it is evidence.
  • When you re-run the audit, changed verdicts between runs are findings in themselves.
FAQ

Sample report questions

Is the sample report real data?

No. It is sample data for a fictional company, labeled as such on every page. The document structure and rendering engine are the real product.

Will my report look exactly like this?

Same sections, same order. Row counts differ, and the per-user table only appears if your export carries identities.

Can I share the sample with my team?

Yes, the PDF is public and needs no account. Most teams circulate it before the first run to agree on who reads which page.

Does the full report come as anything besides PDF?

Yes, a CSV of the tool table ships with every full report, for your risk register or spreadsheet work.

How current are the training verdicts in a real report?

Each verdict carries the date the vendor's terms were last checked. The register behind it is maintained daily.

What does a real report cost?

$99 one time for one report, $199 for three, $299 for five. No subscription, and several plans include monthly audits, see pricing.

Your network, this document, today

Run the free preview first. If the numbers surprise you, the full evidence pack is one click and $99 away.

Start the free audit