Org org_SAMPLE0001 · manufacturing · region eu-central-1. Coverage: 2026-05-27T00:00:00.000Z to 2026-08-25T00:00:00.000Z.
EU AI Act transparency obligations (Article 50) and GPAI obligations have been enforceable since 2 August 2026. This report evidences the organization's observable AI usage surface relevant to transparency, accountability, and auditability conversations with counsel.
The DPDP Act (with rules notified 13 November 2025 and the MeitY compression timeline) applies to organizations processing Indian personal data. This report evidences AI usage relevant to DPDP record-keeping and consent discussions; legal analysis requires Indian counsel.
Indian enterprises face both regimes simultaneously; this joint artifact frames one evidence record for both conversations (broker, GC, DPO).
| Obligation area | EU AI Act | DPDP Act | Sentinel evidence |
|---|---|---|---|
| AI usage inventory | Transparency & documentation (Art. 50; GPAI documentation) | Records of processing (S.17) | 8 tools inventoried |
| Purpose limitation | Risk-based, purpose-bound use | Purpose limitation + notice (S.5–6) | Per-tool classification & posture |
| Risk assessment | Risk management for in-scope systems | Consent/processing basis (S.7–8) | Score 100/100, 5 findings |
| Breach & incident response | Reporting culture for AI incidents | Breach notification (S.8(6)) | 214 blocked / 89 warned in window |
| Accountability | Documentation duty, governance | Record-keeping (S.17) | Policy v7 + 23 audit entries (admin identity) |
Score 100/100 · tier CRITICAL
| Severity | Finding | Evidence | Remediation |
|---|---|---|---|
| CRITICAL | 2 high-risk AI tools in use | host=chat.openai.com risk=high devices=38 · host=claude.ai risk=high devices=22 | Map to approved-use policy; restrict via policy block/warn + DNR enforcement. |
| HIGH | 5 consumer-tier AI tools without enterprise controls | host=chat.openai.com posture=consumer events=4210 · host=claude.ai posture=consumer events=1980 · host=midjourney.com posture=consumer events=310 · host=gamma.app posture=consumer events=240 · host=elevenlabs.io posture=consumer events=96 | Assess need; prefer enterprise-tier equivalents or add compensating controls. |
| MED | 1 agent in the registry without identity enrichment | agents=1 | Configure Entra ID / Google Workspace connectors (backend/.env) and run enrichment. |
| MED | 1 agent-enrichment connector not active | google-workspace=not-configured | Supply connector keys (owner action O-ENV) and re-run enrichment. |
| MED | 303 enforcement events (214 blocked, 89 warned) | blocked=214 · warned=89 | Review the violations feed; refine policy; run user-awareness on warned hosts. |
Gaps are reported as findings, not hidden. Where a data source is unavailable or immature (e.g., a vendor with no admin API), the report states the coverage limitation and the evidence an organization would need to supply — absence of evidence is a finding, never a silent gap.
Shadow AI Sentinel is an AI-governance tool for B2B organizations and is not itself classified under Annex III of the EU AI Act; these reports describe the organization's AI usage and evidence posture, not regulated decision-making outputs by Sentinel.
This report does not assess high-risk AI systems under Annex I/III of the EU AI Act, nor employment-decision outputs under FCRA/ADM regimes; it evidences observable AI usage and governance posture only.