AI Assessment and Shadow AI Audit
We find the AI already in use across your organisation, classify it, and turn that into decisions you can evidence.
Checked 4 October 2026. Built from the full service page.
In short: We inventory the AI in use across your organisation with EtherInsights: Microsoft Copilot, AI services in Azure, AI applications on devices, visits to AI websites and devices built to run AI locally. Each item is classified approved, restricted or not reviewed, and that becomes your policy, guardrails and evidence. Right for organisations whose clients, insurers or board have started asking what AI they use.
Who this is for
The problem
Microsoft's UK research from October 2025, a Censuswide survey of 2,003 UK employees, found that 71% have used unapproved consumer AI tools at work and 51% do so weekly. The Work Trend Index 2024 found that 78% of AI users bring their own AI tools to work, rising to 80% at small and medium-sized companies.
What we would do
If AI is in use and nobody holds a list of it, start with an inventory, not a policy. A policy written blind either bans tools people rely on or approves things nobody has checked. Find it, classify it, offer approved options for what people genuinely need, then write the policy.
- If you are a ten-person firm with one approved AI tool and nothing else in use, a short AI use policy may be all you need.
- If your only question is whether Microsoft 365 Copilot is safe to switch on, start with our Copilot and AI adoption service instead.
- If you already review generative AI apps in Defender for Cloud Apps and keep a current policy, repeat sweeps may be enough.
When we are not the answer: If you want a report that says you are compliant with the EU AI Act or certified to ISO/IEC 42001, we are the wrong provider. We find and classify AI use and prepare evidence. Certification is issued by certification bodies, and no inventory makes anyone compliant.
What is included
- Inventory of Microsoft Copilot seats, agents and connectors
- AI services deployed in Azure, including Microsoft Foundry resources and agents
- AI applications on devices, and devices reaching AI websites
- Devices with NPU or GPU hardware or local model runtimes
- Every item classified approved, restricted or not reviewed
- Approved alternatives for the tools people actually want to use
- Guardrails with Defender for Cloud Apps and Microsoft Purview
- An AI use policy and AI risk register built from the inventory
- Evidence for client and insurer questionnaires, EU AI Act scoping and ISO/IEC 42001 preparation
- A one-off assessment or repeat sweeps as new AI arrives
What the last 12 months looked like
What it costs
Scoped and quoted against your estate rather than sold from a rate card. We price what you already run, including the parts that are working and do not need replacing, and the quote itemises what is included so it can be compared line by line with anyone else’s. Managed IT support starts at £40 per user, per month if that is the wider question.
Three questions people ask
Will the assessment change anything?
No. The assessment reads inventory, configuration and usage signals and reports on them. Nothing is blocked, removed or reconfigured until you have seen the classified inventory and agreed what should change.
Can you find every AI tool in use?
No, and anyone who claims to is overselling. We cover the places most AI use leaves a trace: Copilot, Azure, managed devices and their web traffic, and local AI hardware and runtimes.
Is this about catching individual staff?
No. The inventory is about tools and data, and findings are reported as patterns: which tools, how widely, and with what data risk.
Tell us what you need
A short call to talk through how your IT works today, what your team handles, and what you need from a provider. We will tell you plainly how we would approach it.
Prefer to talk now? Call us on +44 (0)1482 770583.
