AI Governance
AI Governance is a billed add-on covering five related tools for managing a client's AI tool exposure and regulatory readiness. An admin turns it on via Settings → Add-ons → AI Governance (POST /api/v1/billing/aigov/checkout).
AI Inventory
Tracks which AI tools are in use, fingerprinted against a known list — Microsoft Copilot, ChatGPT, Google Gemini, Claude, GitHub Copilot, Grammarly, Midjourney, Notion AI, Jasper AI and Otter.ai — each with a vendor and risk tier. Scan (POST /api/v1/ai/inventory/scan) checks a connected Microsoft 365 tenant two ways: Copilot's own audit log operation, and — for the other tools — whether Microsoft Defender's URL scanning has actually seen traffic to that tool's domains, not just whether the domain exists. Without an M365 connection, the scan seeds the known-tools list for manual review instead of silently reporting zero. Tools can also be added or removed by hand.
Shadow AI Detection
A separate, more cautious sweep aimed specifically at unsanctioned AI use. Each detected tool gets a data-risk classification and an approval workflow (unknown → approved/rejected) rather than being added straight to inventory — tools flagged high-risk or of unknown risk are held back from auto-approval regardless of how confidently they were detected.
AI Model Bill of Materials (MBOM)
A structured record per AI tool in use: model name, model provider, inference infrastructure, training data source, data classification, and use case — exportable as CSV (GET /api/v1/ai/mbom/export) for a client's own AI risk register or a customer's due-diligence request.
EU AI Act Readiness
A short questionnaire (POST /api/v1/ai/euaiact) that produces a risk tier (minimal/limited/high/unacceptable, per the Act's own categories) based on the client's answers, stored against the client for later reference.
AI Supply Chain
Cross-references AI Inventory and MBOM entries against known vendor risk data to surface AI-specific vendor concentration and dependency risk (GET /api/v1/ai/supply-chain).
AI Regulatory Alerts
The same regulatory alert feed as Security Intelligence's Regulatory Alerts, filtered down to AI-specific items — an update only appears here if it actually concerns AI regulation (checked against the alert's full title, body and framework text, not a loose substring match that would catch unrelated words like "chain" or "again").
Compliance framework auto-assessment
Two controls are automatically marked from AI Inventory contents rather than left for manual review: ISO 42001's inventory/risk-tiering controls, and the EU AI Act's Article 6 (high-risk system classification) and NIST AI RMF's MAP 3 (risk categorisation) controls — all four carry an ⚡ AUTOMATED badge on their respective Compliance pages once AI Inventory has real data behind it.
Open in the interactive docs