Example findings
- Shadow AI risk is often hidden because employees do not know what is approved.
- Sensitive data boundaries should be written in plain language.
- Vendor review is needed for embedded AI tools and public assistants.
- Monthly monitoring is useful because tools and workflows change quickly.