RESOURCES

AI governance resources

Guides, checklists and reference material for teams putting AI usage under control.

Checklist
AI Governance Compliance Checklist
Six steps across EU AI Act, SOC 2 and California AI rules — discovery, risk classification, sensitive-data detection, audit trail, pre-send policy, reporting. Mapped to deadlines with implementation guidance.
Read the full checklist →
Assessment
Shadow AI Risk Assessment
Four questions that establish whether you can see your shadow AI at all: which providers are in use, what data is going into prompts, which interactions exposed something, and whether you have an audit trail to prove it.
Start with the shadow AI guide →
Template
AI Acceptable Use Policy Template
Three-tier classification framework, monitor-coach-enforce model, department scoping. Ready to adapt for your organization.
Read the policy guide →
Framework
AI Asset Inventory Framework
Three discovery channels (workspace API audit, browser-level detection, network/DNS analysis), a two-axis risk scoring framework, and continuous discovery in place of point-in-time audits.
Read the inventory guide →
Checklist
MCP Security Checklist (OWASP Top 10)
Four MCP risks explained in depth — tool poisoning, prompt injection via tool results, context spoofing, insecure memory references — from OWASP's MCP Top 10, plus a five-step governance framework for AI coding assistants.
Read the MCP security guide →
Calculator
Shadow AI Breach Cost Calculator
Based on IBM's 2026 Cost of a Data Breach: $5.39M average when shadow AI is involved, against a $4.99M global average. Calculate your risk exposure and governance ROI.
See the breach cost analysis (2025 edition, updated for 2026) →

put it into practice

Stop reading about shadow AI and go look at yours

A read-only workspace connection gives you the inventory these guides describe, for your own organisation, in minutes.

→ nothing installed on anyone’s machine to start
→ the extension and gateway are opt-in per surface