EU AI Act transparency obligations are live since Aug 2, 2026 — fines up to €35M or 7%

Know every AI your company uses.
Prove it to anyone.

Shadow AI Sentinel is a free browser extension that discovers every AI tool your employees touch, enforces policy at the browser, and turns it all into auditor-ready evidence — no agents, no deployment, installed in 30 seconds.

Free forever for discovery & monitoring · No credit card · No PII collected · Opt-in telemetry only

Maps to ISO/IEC 42001 EU AI Act Art. 50 transparency evidence NIST AI RMF aligned India DPDP × EU joint reporting Insurer-ready EPC six controls SOC 2-style acquisition parity from day one
The problem

Your company runs dozens of AI tools.
Your security team can name three.

Employees paste source code into chatbots, route customer data through unvetted copilots, and connect AI agents to production systems — invisible to your SSO logs and your CASB. Regulators stopped accepting "we didn't know." So did insurers.

93%of CISOs blinded by false AI confidenceLookout / ZK Research, Jun 2026
59%of mobile AI traffic flows darkLookout / ZK Research, Jun 2026
€35M / 7%EU AI Act fine ceiling, enforcement live Aug 2026Regulation (EU) 2024/1689
Capped claimsinsurers excluding "silent AI" lossesNorton Rose Fulbright, May 2026

Discover — every AI, every tab

A curated allowlist of 142+ AI services (ChatGPT, Copilot, Gemini, Claude, Midjourney, agent platforms and more), observed at the browser with zero PII in free mode — anonymous device IDs only.

Enforce — policy at the edge

Block, warn, or allow per domain with policy-as-code: versioned, audit-trailed, signed down to the browser. A fleet-wide kill switch satisfies the insurer's first question before it's asked.

Prove — evidence, not screenshots

Deterministic, reproducible reports mapped to EU AI Act, ISO 42001, NIST AI RMF, DPDP×EU, and insurer six-controls — generated on demand with locked legal wording and a 90-day coverage window.

How it works

Thirty seconds to install. Thirty minutes to evidence.

Install the extension — nothing else

No agents, no network taps, no MDM project. The Chrome extension observes only curated AI domains via a published, versioned allowlist. Least privilege by design — never <all_urls>.

See your true AI inventory

The console shows every tool in use, its vendor posture (enterprise vs consumer), risk tier, and what policy did about it — live violations feed included.

Set policy once, enforced everywhere

Policy-as-code with version diffs and an admin-identity audit trail. Modes: enforce, monitor-only, or full off (kill switch). The extension enforces at the browser via declarative net request rules.

Export evidence regulators accept

One click produces EU AI Act transparency evidence, an insurance readiness pack naming the EPC's six controls, or a DPDP×EU joint map — JSON, print-ready HTML, or branded PDF.

The moat

The Shadow AI Sentinel Index:
benchmarks nobody else can publish.

  • Opt-in, anonymized-at-source usage signals — thresholded so no company is ever identifiable.
  • Quarterly "State of Shadow AI" benchmarks by industry and geography, published methodology.
  • "Your posture vs. industry percentile" — retention built into the product, not bolted on.
  • SSE vendors can't publish it (client confidentiality). AI vendors see one tool. GRC platforms have no traffic data. We do.

"You can't govern what you can't see — and you can't buy insurance for what you can't prove. Discovery is table stakes; evidence is the product."

Sample evidence

Real engine output. Not mockups.

These are generated by the same deterministic engine that runs in the product, from an anonymized demo organization (90-day window, enforcement mode ON, policy v7). Every score is reproducible by an auditor.

Compliance & trust

Built like the evidence matters. Because it does.

Privacy-first by architecture

No PII in free mode. Anonymous device IDs; org linkage happens server-side against hashed install keys. Index data opt-in and k-anonymized at source. Published methodology, not vibes.

Acquisition-grade engineering

Signed config (HMAC-SHA256, dual-key rotation), zero remote code, strict CSP, SBOM per release, threat model + ADRs in-repo, OpenAPI contract, wire-level tests. The repo survives diligence tomorrow.

Locked legal wording

Reports state plainly: informational evidence — not certification, not insurance advice. Findings-not-bugs: "you cannot audit X" appears as a finding with remediation, never hidden.

Get started

Find your shadow AI today.
Free, in thirty seconds.

Add the extension, browse as usual, watch your inventory build itself — then generate your first EU AI Act evidence pack before lunch.

Security teams: ask us for the broker/insurer evidence pack · security@shadowaisentinel.app