Org org_SAMPLE0001 · manufacturing · region eu-central-1 · policy v7.
Data coverage: 2026-05-27T00:00:00.000Z to 2026-08-25T00:00:00.000Z. Reports are derived reads of current org data (no snapshot storage in v1 — ADR-0011).
8 AI tools attributed to this org in the coverage window. Host-level telemetry only — never prompt content or page data.
| Host | Category | Risk | Posture | Events | Devices |
|---|---|---|---|---|---|
| chat.openai.com | chatgpt | high | consumer | 4210 | 38 |
| claude.ai | claude | high | consumer | 1980 | 22 |
| github.com | copilot | low | enterprise | 15630 | 41 |
| gemini.google.com | gemini | med | hybrid | 870 | 17 |
| midjourney.com | image-gen | med | consumer | 310 | 9 |
| gamma.app | deck-gen | med | consumer | 240 | 12 |
| notebooklm.google.com | research | med | hybrid | 190 | 11 |
| elevenlabs.io | voice-gen | med | consumer | 96 | 4 |
EU AI Act transparency obligations (Article 50) and GPAI obligations have been enforceable since 2 August 2026. This report evidences the organization's observable AI usage surface relevant to transparency, accountability, and auditability conversations with counsel.
The org has published 7 policy versions (23 audit entries, actor = admin identity). Enforcement activity in window: 214 blocked, 89 warned.
Score 100/100 · tier CRITICAL · rule version 1.1. Thresholds and rules are published in code (backend/src/reporting/risk.ts) — a reviewer can reproduce every finding.
| Severity | Finding | Evidence | Remediation |
|---|---|---|---|
| CRITICAL | 2 high-risk AI tools in use | host=chat.openai.com risk=high devices=38 · host=claude.ai risk=high devices=22 | Map to approved-use policy; restrict via policy block/warn + DNR enforcement. |
| HIGH | 5 consumer-tier AI tools without enterprise controls | host=chat.openai.com posture=consumer events=4210 · host=claude.ai posture=consumer events=1980 · host=midjourney.com posture=consumer events=310 · host=gamma.app posture=consumer events=240 · host=elevenlabs.io posture=consumer events=96 | Assess need; prefer enterprise-tier equivalents or add compensating controls. |
| MED | 1 agent in the registry without identity enrichment | agents=1 | Configure Entra ID / Google Workspace connectors (backend/.env) and run enrichment. |
| MED | 1 agent-enrichment connector not active | google-workspace=not-configured | Supply connector keys (owner action O-ENV) and re-run enrichment. |
| MED | 303 enforcement events (214 blocked, 89 warned) | blocked=214 · warned=89 | Review the violations feed; refine policy; run user-awareness on warned hosts. |
Gaps are reported as findings, not hidden. Where a data source is unavailable or immature (e.g., a vendor with no admin API), the report states the coverage limitation and the evidence an organization would need to supply — absence of evidence is a finding, never a silent gap.
Shadow AI Sentinel is an AI-governance tool for B2B organizations and is not itself classified under Annex III of the EU AI Act; these reports describe the organization's AI usage and evidence posture, not regulated decision-making outputs by Sentinel.
This report does not assess high-risk AI systems under Annex I/III of the EU AI Act, nor employment-decision outputs under FCRA/ADM regimes; it evidences observable AI usage and governance posture only.