Shadow AI Risk Assessment
Questions about how AI is actually being used in your business — not how you hope it is being used. You get a risk score, a separate measure of how much of your AI footprint you can actually see, your three most important actions, and the full list of what produced the result.
This assessment runs entirely inside your browser. There is no account, no sign-up, and no server receiving your answers. Nothing you enter is transmitted, logged or stored — close the tab and it is gone. You can confirm that by disconnecting from the internet before you start; the assessment will still work either way.
One thing we will not gloss over: other pages on this site run a live chat widget, and that widget sets its own cookies for the site as a whole. This page does not load it. The assessment sets no cookie of its own, reads none, and sends nothing to it — but if you check your browser after visiting an article here, you will find the site’s cookies rather than none at all. We would rather tell you that than have you find it.
Your result
We review these for businesses running multiple locations — usually alongside the network and phone systems, because that is where the data actually moves. The button below opens an email with your result summary already written into it. Nothing is sent until you press send, and you can delete anything you would rather not share.
Email my result to USA Telecom
Or call (888) 989-4872. The PDF is produced by your own browser's print dialogue — choose “Save as PDF” as the destination. Nothing is uploaded to produce it.
Related articles
- AI agent security for business: 12 safeguards — the agent-access pillar; run this assessment when you cannot yet name what is connected.
- How to build an enterprise AI inventory — the living list this score is asking whether you have.
- What does AI data governance actually require in 2026? — shadow AI is one of four problems; this is the rest of the map.
- AI text watermarking, and the difference between AI-detected and AI-authored — why “was AI used?” is the wrong question, including the policy distinctions this assessment scores.
- ChatGPT can now read and send your Apple Messages — a concrete channel where unapproved AI use becomes a data-transfer problem.
What this measures, and what it does not
"Shadow AI" means AI tools being used for work without the business knowing. Not maliciously, in almost every case — somebody had a deadline and a chatbot was faster. The risk is not that they used AI. It is that nobody can say what went into it, under whose account, or whether it is still there.
This assessment is a structured way of finding out what you do and do not know. It is not an audit, it does not scan your network, and it cannot see anything you do not tell it. A high score means you have gaps worth closing, not that something bad has already happened. A low score means your controls are probably sound — it does not prove nothing has leaked.
If you want the reasoning behind the questions, start with What is Shadow AI and how do you find it? — definition, discovery methods, and intake. The 40-control checklist is the program around this assessment; the acceptable-use policy article is the document the score is asking whether you have. AI agent security for business is the twelve-safeguard pillar when something can act, not only answer. The AI watermarking article covers why “was AI used?” is the wrong question and what to ask instead, including the policy distinctions this assessment scores you against.
Managed network and communications services, SDVOSB. We build this kind of thing because the answer to "where is our data going?" usually turns out to be a network question. Support: (888) 989-4872 · support@adampulse.us