SAMPLE OUTPUT · generated by the Shadow AI Sentinel engine from an anonymized demo organization (DPDP × EU Joint Map). Deterministic and reproducible — auditors can re-derive every score.

DPDP Act × EU AI Act — Joint AI Usage Evidence

Shadow AI Sentinel · generated 2026-08-25T09:00:00.000Z · org org_SAMPLE0001 · manufacturing · region eu-central-1 · policy v7 · data coverage 2026-05-27T00:00:00.000Z → 2026-08-25T00:00:00.000Z

Organization & scope

Org org_SAMPLE0001 · manufacturing · region eu-central-1. Coverage: 2026-05-27T00:00:00.000Z to 2026-08-25T00:00:00.000Z.

Two live regimes

EU AI Act transparency obligations (Article 50) and GPAI obligations have been enforceable since 2 August 2026. This report evidences the organization's observable AI usage surface relevant to transparency, accountability, and auditability conversations with counsel.

The DPDP Act (with rules notified 13 November 2025 and the MeitY compression timeline) applies to organizations processing Indian personal data. This report evidences AI usage relevant to DPDP record-keeping and consent discussions; legal analysis requires Indian counsel.

Indian enterprises face both regimes simultaneously; this joint artifact frames one evidence record for both conversations (broker, GC, DPO).

Obligation areaEU AI ActDPDP ActSentinel evidence
AI usage inventoryTransparency & documentation (Art. 50; GPAI documentation)Records of processing (S.17)8 tools inventoried
Purpose limitationRisk-based, purpose-bound usePurpose limitation + notice (S.5–6)Per-tool classification & posture
Risk assessmentRisk management for in-scope systemsConsent/processing basis (S.7–8)Score 100/100, 5 findings
Breach & incident responseReporting culture for AI incidentsBreach notification (S.8(6))214 blocked / 89 warned in window
AccountabilityDocumentation duty, governanceRecord-keeping (S.17)Policy v7 + 23 audit entries (admin identity)

Risk posture (rule-based, reproducible)

Score 100/100 · tier CRITICAL

SeverityFindingEvidenceRemediation
CRITICAL2 high-risk AI tools in usehost=chat.openai.com risk=high devices=38 · host=claude.ai risk=high devices=22Map to approved-use policy; restrict via policy block/warn + DNR enforcement.
HIGH5 consumer-tier AI tools without enterprise controlshost=chat.openai.com posture=consumer events=4210 · host=claude.ai posture=consumer events=1980 · host=midjourney.com posture=consumer events=310 · host=gamma.app posture=consumer events=240 · host=elevenlabs.io posture=consumer events=96Assess need; prefer enterprise-tier equivalents or add compensating controls.
MED1 agent in the registry without identity enrichmentagents=1Configure Entra ID / Google Workspace connectors (backend/.env) and run enrichment.
MED1 agent-enrichment connector not activegoogle-workspace=not-configuredSupply connector keys (owner action O-ENV) and re-run enrichment.
MED303 enforcement events (214 blocked, 89 warned)blocked=214 · warned=89Review the violations feed; refine policy; run user-awareness on warned hosts.

Limitations

Gaps are reported as findings, not hidden. Where a data source is unavailable or immature (e.g., a vendor with no admin API), the report states the coverage limitation and the evidence an organization would need to supply — absence of evidence is a finding, never a silent gap.

Shadow AI Sentinel is an AI-governance tool for B2B organizations and is not itself classified under Annex III of the EU AI Act; these reports describe the organization's AI usage and evidence posture, not regulated decision-making outputs by Sentinel.

This report does not assess high-risk AI systems under Annex I/III of the EU AI Act, nor employment-decision outputs under FCRA/ADM regimes; it evidences observable AI usage and governance posture only.

Findings