All projects
Client work
Client workOngoing2026
Shadow AI Exposure Assessment
AI GovernanceCybersecurityEU AI ActPre-Sales
Built with
AI GovernanceRisk AssessmentCompliance
Client engagement. Specifics are kept confidential.
Working with a cybersecurity consultancy, I helped build a Shadow AI exposure assessment service from the ground up. It audits how employees actually use AI tools, assesses where company data is leaking, and finds the gaps in governance.
The methodology runs in four stages: discovery (mapping the AI tools in use), risk evaluation (classifying data exposure), regulatory mapping (GDPR, the EU AI Act, NIS2, DORA), and a remediation plan. It targets mid-to-large organisations in regulated industries, where the risk is real and the compliance burden is heavy.
My role sits on the pre-sales and design side: shaping the offer, the methodology, and the partner integrations that deliver it.