Skip to main content
Shadow-AI Self-Assessment

Do you know which AI models touch your data?

20 questions · about 4 minutes · scored instantly. Built for technology, risk, and compliance leads in regulated industries.

Nothing you click leaves this page. You only share your results — name, email, company — if you choose to at the end.

0 of 20 answeredYes · Partly · No
I · Discover

Your policy says what should be running. Do you know what is?

Do you have a current list of every AI tool your people actually use?
Counts as yes when: One document, updated this quarter — tools, teams, data touched.
Have you reviewed which third-party apps can read company email or files?
Counts as yes when: OAuth/app grants in Google Workspace or Microsoft 365, reviewed in the last 90 days.
Would you spot AI spending hidden in expense reports?
Counts as yes when: A search for AI vendors — including small personal-card subscriptions — has actually been run.
Have you asked employees — without blame — what AI they really use?
Counts as yes when: An amnesty survey in the last 6 months, compared against network data.
II · Assess

Per tool: the model is not the provider.

Can you name the exact AI model behind each tool you sanction?
Counts as yes when: Model names and versions in writing — “a GPT-class model” doesn’t count.
Do you know which company runs each model — and in which country?
Counts as yes when: The same model can be served from the US, Singapore, or mainland China by different hosts.
Do you know each provider’s data retention and training policy?
Counts as yes when: Zero-retention vs 30 days vs “may train on your prompts” — looked up, not assumed.
Could you answer, in writing, “which model processed this customer record”?
Counts as yes when: For any record, within a day, with logs.
III · Contract

Most contracts pin a vendor. Pin the model.

Do your AI contracts name the model, the host, and the country — all three?
Counts as yes when: In the DPA, not in a sales deck.
Must vendors notify you before swapping models or providers?
Counts as yes when: A substitution-notice clause — model terms can change with continued use counting as acceptance.
Are AI inference providers on your sub-processor lists?
Counts as yes when: If the vendor “routes to the best model,” your sub-processor list is fiction.
Do you re-check vendor AI claims at renewal — not just at signing?
Counts as yes when: Last year’s answer may not be this year’s routing.
IV · Control

Make “which model touched this record” a query, not an investigation.

Does sanctioned AI usage flow through one gateway you can query?
Counts as yes when: One logged route, an approved-model registry behind it.
Do you enforce zero-retention / no-training routing where it’s offered?
Counts as yes when: Most gateways have the filters — they ship switched off.
Are personal AI API keys blocked on regulated data paths?
Counts as yes when: Personal accounts carry none of your settings.
Do AI agents get scoped access — never standing inbox or file access?
Counts as yes when: Scoped credentials, memory policy, action allowlist, kill switch.
V · Monitor

The most-used model changes monthly. Annual review is a snapshot.

Does someone review which AI models are gaining usage — monthly?
Counts as yes when: 15 minutes with a usage leaderboard beats an annual report.
Do you re-attest vendors’ model / provider / jurisdiction quarterly?
Counts as yes when: An email template and a spreadsheet are enough.
Would a terms-of-service change for a model you use reach you within a week?
Counts as yes when: Changelogs and terms-watch, assigned to a person.
Is there a playbook for “unapproved model touched regulated data”?
Counts as yes when: One page: contain, assess, notify, remediate.

Methodology: questions derived from provider data-policy disclosures (OpenRouter provider-logging table), first-party privacy policies, and EU AI Act / DORA obligations. Scoring favours provable answers — “we don’t know” is a finding. © 2026 Ari Nakos.