SAMPLE OUTPUT · generated by the Shadow AI Sentinel engine from an anonymized demo organization (EU AI Act Evidence Pack). Deterministic and reproducible — auditors can re-derive every score.

EU AI Act — AI Usage Evidence Report

Shadow AI Sentinel · generated 2026-08-25T09:00:00.000Z · org org_SAMPLE0001 · manufacturing · region eu-central-1 · policy v7 · data coverage 2026-05-27T00:00:00.000Z → 2026-08-25T00:00:00.000Z

Organization & scope

Org org_SAMPLE0001 · manufacturing · region eu-central-1 · policy v7.

Data coverage: 2026-05-27T00:00:00.000Z to 2026-08-25T00:00:00.000Z. Reports are derived reads of current org data (no snapshot storage in v1 — ADR-0011).

Observable AI usage surface

8 AI tools attributed to this org in the coverage window. Host-level telemetry only — never prompt content or page data.

HostCategoryRiskPostureEventsDevices
chat.openai.comchatgpthighconsumer421038
claude.aiclaudehighconsumer198022
github.comcopilotlowenterprise1563041
gemini.google.comgeminimedhybrid87017
midjourney.comimage-genmedconsumer3109
gamma.appdeck-genmedconsumer24012
notebooklm.google.comresearchmedhybrid19011
elevenlabs.iovoice-genmedconsumer964

Transparency & accountability context

EU AI Act transparency obligations (Article 50) and GPAI obligations have been enforceable since 2 August 2026. This report evidences the organization's observable AI usage surface relevant to transparency, accountability, and auditability conversations with counsel.

The org has published 7 policy versions (23 audit entries, actor = admin identity). Enforcement activity in window: 214 blocked, 89 warned.

Risk posture (rule-based, reproducible)

Score 100/100 · tier CRITICAL · rule version 1.1. Thresholds and rules are published in code (backend/src/reporting/risk.ts) — a reviewer can reproduce every finding.

SeverityFindingEvidenceRemediation
CRITICAL2 high-risk AI tools in usehost=chat.openai.com risk=high devices=38 · host=claude.ai risk=high devices=22Map to approved-use policy; restrict via policy block/warn + DNR enforcement.
HIGH5 consumer-tier AI tools without enterprise controlshost=chat.openai.com posture=consumer events=4210 · host=claude.ai posture=consumer events=1980 · host=midjourney.com posture=consumer events=310 · host=gamma.app posture=consumer events=240 · host=elevenlabs.io posture=consumer events=96Assess need; prefer enterprise-tier equivalents or add compensating controls.
MED1 agent in the registry without identity enrichmentagents=1Configure Entra ID / Google Workspace connectors (backend/.env) and run enrichment.
MED1 agent-enrichment connector not activegoogle-workspace=not-configuredSupply connector keys (owner action O-ENV) and re-run enrichment.
MED303 enforcement events (214 blocked, 89 warned)blocked=214 · warned=89Review the violations feed; refine policy; run user-awareness on warned hosts.

Limitations

Gaps are reported as findings, not hidden. Where a data source is unavailable or immature (e.g., a vendor with no admin API), the report states the coverage limitation and the evidence an organization would need to supply — absence of evidence is a finding, never a silent gap.

Shadow AI Sentinel is an AI-governance tool for B2B organizations and is not itself classified under Annex III of the EU AI Act; these reports describe the organization's AI usage and evidence posture, not regulated decision-making outputs by Sentinel.

This report does not assess high-risk AI systems under Annex I/III of the EU AI Act, nor employment-decision outputs under FCRA/ADM regimes; it evidences observable AI usage and governance posture only.

Findings