Assessment headline
61
AI Risk / 100
Lower is better
81%
AI Visibility
Higher is better
37AI systems identified
428AI users
162Sensitive-data interactions
Risk and visibility are intentionally separate. A low risk score with poor visibility does not mean the environment is safe; it may mean the organization cannot see enough of its AI activity.
AI systems detected
Microsoft 365 Copilot96SanctionedObserved
ChatGPT206UnsanctionedObserved
Google Gemini47UnsanctionedObserved
Claude31UnsanctionedObserved
Copilot Studio agents3SanctionedObserved
Custom / in-house AI apps2ReviewCorrelated
Inventory combines sanctioned AI, shadow AI, enterprise integrations, browser AI, agents and custom applications. Counts are tagged with the evidence available for each source.
Where AI is accessing corporate data
SharePoint — HR & compensation412
OneDrive — business files388
SharePoint — finance forecast240
Teams chats & meetings156
Exchange messages88
These are AI-accessed resources or AI-related data events, not a generic count of files that merely exist in Microsoft 365.
What the collector can prove
48 labelled files uploaded to consumer AI from managed endpointsObserved
312 prompts matched sensitive information types in captured AI interactionsObserved
37 confidential resources surfaced by Copilot through broad, unreviewed access pathsCorrelated
23 third-party AI apps hold persistent Microsoft 365 permissionsObserved
29% of browser activity lacks prompt-content visibility with the current configurationBlind
AI-specific findings · every finding carries an evidence class
HighCopilot surfaced Confidential HR content through an organization-wide access pathCorrelated
Copilot audit records show the labelled resources that grounded the interaction. Permission resolution shows the user inherited access through a broad organization-wide group rather than intended HR membership. Evidence: Copilot audit + SharePoint permissions + sensitivity labels. Action: review and tighten the access path, then re-test.
HighSensitive files were uploaded to consumer AI services from managed devicesObserved
Endpoint/Purview telemetry recorded labelled files moving to supported AI destinations. Action: define sanctioned AI destinations, apply AI-specific DLP controls, and investigate repeat patterns by department.
Medium21 unsanctioned AI applications are active across the organizationObserved
Cloud discovery identified active AI services, the users/devices associated with them, and usage over the assessment window. Action: classify each application as sanctioned, restricted, review, or blocked.
Medium42 of 60 Copilot licenses are inactive while 206 users rely on shadow AICorrelated
Copilot usage reporting and shadow-AI discovery show a mismatch between the governed tool being licensed and the tools employees actually use. Action: reassign licenses and target adoption to the departments already using AI.
Medium3 AI agents use application identities and require authorization-path reviewObserved
The agents authenticate using application/service-principal identities. This is not automatically unsafe, but it changes how authorization must be evaluated. Action: verify each agent's effective permissions, knowledge sources, actions and whether user-context authorization is preserved.
BlindThird-party prompt content is unavailable across part of the browser estateBlind
AI use is visible at the application level, but current endpoint/browser configuration cannot capture enough interaction detail to prove what content was entered. Action: close the visibility gap before treating the absence of incidents as evidence of low risk.
AI Visibility Coverage · 81% overall
Microsoft Copilot interactions100%Full
Copilot accessed-resource detail100%Full
Shadow AI / SaaS discovery92%Full
Third-party AI interactions81%Partial
Third-party prompt/content capture71%Partial
Endpoint AI data movement76%Partial
Agents & custom AI65%Partial
Unmanaged / personal devices0%Blind
Why this matters: NLC reports what is Observed, what is Correlated, what is only Potential, and what is Blind. A missing signal is never silently treated as zero risk.