SAMPLE OUTPUT · generated by the Shadow AI Sentinel engine from an anonymized demo organization (Insurance Readiness (EPC Six Controls)). Deterministic and reproducible — auditors can re-derive every score.

AI Insurance Readiness — Six-Controls Evidence Package

Shadow AI Sentinel · generated 2026-08-25T09:00:00.000Z · org org_SAMPLE0001 · manufacturing · region eu-central-1 · policy v7 · data coverage 2026-05-27T00:00:00.000Z → 2026-08-25T00:00:00.000Z

Organization & scope

Org org_SAMPLE0001 · manufacturing · region eu-central-1. Coverage: 2026-05-27T00:00:00.000Z to 2026-08-25T00:00:00.000Z.

Mapping is referenced to the published 'Six Controls Carriers Now Require' framework (EPC Group, 2026) and the standards underwriters reference: NIST AI RMF, ISO/IEC 42001, and AIUC-1. Reference to a framework is for evidence structuring, not an endorsement or guarantee of coverage.

The Six Controls Carriers Now Require — evidence status

Each control references a standard underwriters recognize (EPC Group, 2026): NIST AI RMF, ISO/IEC 42001, and AIUC-1. Status reflects Sentinel-derived evidence; org-supplied items are flagged as findings when missing.

ControlStatusSentinel evidenceOrg-supplied evidence
01 · Documented Human Kill SwitchPARTIALPolicy changes are signed by a named admin identity (audit trail, 23 entries).Kill-switch runbook + named approver + a recent test record (org-supplied).
02 · Human-in-the-Loop AI InventoryEVIDENCED8 AI tools inventoried from browser telemetry. 3 agent registry entries (override owner = policy audit actor).
03 · Data Provenance & ClassificationPARTIALPer-tool classification: category, risk tier, vendor posture (enterprise/consumer/hybrid).Data-flow provenance for tools handling customer/employee/financial data (org-supplied).
04 · Named Accountable AI ExecutivePARTIALPolicy is published by a named admin identity (audit actor recorded per change).Named accountable AI executive + sign-off attestation (org-supplied).
05 · Deepfake-Resistant AuthenticationGAPOut-of-band verification for workflows AI agents touch: email/video are no longer proof of identity (org-supplied).
06 · Microsoft-Stack Enforcement EvidencePARTIALDNR enforcement is live: policy v7; 214 blocked / 89 warned events in window (audit-grade feed).Entra workload identity · Purview grounding enforcement · Defender/M365 audit exports (org-supplied).

Supporting risk posture

Score 100/100 · tier CRITICAL (rule version 1.1).

SeverityFindingEvidenceRemediation
CRITICAL2 high-risk AI tools in usehost=chat.openai.com risk=high devices=38 · host=claude.ai risk=high devices=22Map to approved-use policy; restrict via policy block/warn + DNR enforcement.
HIGH5 consumer-tier AI tools without enterprise controlshost=chat.openai.com posture=consumer events=4210 · host=claude.ai posture=consumer events=1980 · host=midjourney.com posture=consumer events=310 · host=gamma.app posture=consumer events=240 · host=elevenlabs.io posture=consumer events=96Assess need; prefer enterprise-tier equivalents or add compensating controls.
MED1 agent in the registry without identity enrichmentagents=1Configure Entra ID / Google Workspace connectors (backend/.env) and run enrichment.
MED1 agent-enrichment connector not activegoogle-workspace=not-configuredSupply connector keys (owner action O-ENV) and re-run enrichment.
MED303 enforcement events (214 blocked, 89 warned)blocked=214 · warned=89Review the violations feed; refine policy; run user-awareness on warned hosts.

Limitations

Gaps are reported as findings, not hidden. Where a data source is unavailable or immature (e.g., a vendor with no admin API), the report states the coverage limitation and the evidence an organization would need to supply — absence of evidence is a finding, never a silent gap.

This report does not assess high-risk AI systems under Annex I/III of the EU AI Act, nor employment-decision outputs under FCRA/ADM regimes; it evidences observable AI usage and governance posture only.

Findings