30 Tage Risikoerkennung für generative KI:Jetzt starten
Demo buchen
Kostenlose Risikobewertung für Shadow AI

Bewerten Sie Ihre Exposition gegenüber Shadow AI

Beantworten Sie sieben kurze Fragen dazu, wie Ihre Belegschaft KI heute nutzt. Wir bewerten Ihr ungovernertes KI-Risiko von 0 bis 100 und zeigen Ihnen, wo Sie anfangen sollten. Dauert etwa zwei Minuten. Keine E-Mail nötig, um Ihr Ergebnis zu sehen.

Frage 1 von 813%

Wie viele Mitarbeitende hat Ihr Unternehmen?

Mehr Menschen bedeuten mehr Angriffsfläche für nicht genehmigte KI-Nutzung.

Free audit checklist

Shadow AI Risk Assessment Checklist

Aona's free interactive Shadow AI risk assessment scores your exposure from 0 to 100. This checklist turns the same dimensions into audit questions you can work through with IT, security and compliance. Your organisation's size and industry set the context; the six areas below are the ones you can actually change.

1

Visibility and discovery

  • Inventory every AI tool in use
    Can you produce a list of every AI tool employees have used in the last 30 days, including free browser-based tools?
  • Move beyond surveys
    Is your visibility based on real usage telemetry rather than self-reporting or an annual questionnaire?
  • Map the data flows
    Do you know which AI tools receive company data via typed prompts, copy-paste or file uploads?
2

Policy and acceptable use

  • Publish a written AI policy
    Is an AI acceptable-use policy written, communicated and acknowledged by every employee?
  • Name approved tools and banned data
    Does the policy list approved tools, prohibited data categories and an approval path for new tools?
  • Enforce it technically
    Is the policy backed by controls at the point of use, rather than relying on trust alone?
3

Controls at the point of use

  • Block sensitive data in real time
    Can you stop PII, client data, credentials or source code before it reaches an AI tool?
  • Redact instead of banning
    Can you redact sensitive fields so employees keep the productivity without the exposure?
  • Cover files, not just prompts
    Do your controls inspect file uploads as well as typed text?
4

Sanctioned AI adoption

  • Offer approved alternatives
    Have you sanctioned enterprise-grade options for the ChatGPT, Copilot, Gemini and Claude use cases employees already have?
  • Retire consumer accounts
    Are enterprise tiers, with training-data opt-outs, SSO and data residency, replacing personal accounts?
  • Make approval fast
    Is there a well-known, fast route to request a new AI tool so employees do not route around IT?
5

Incident readiness

  • Have a response plan
    Is there a documented plan for an AI-related data exposure, with named owners and timelines?
  • Test your detection
    Would your monitoring actually flag sensitive data pasted into an unsanctioned AI tool today?
  • Learn from near-misses
    Are past AI incidents and near-misses reviewed for root cause and fed back into controls?
6

Device and identity foundations

  • Enrol devices
    Are endpoints under MDM or Intune so AI controls can be deployed and enforced at scale?
  • Centralise identity
    Is access to sanctioned AI tools governed through SSO, with Entra or a similar identity provider?
  • Account for unmanaged devices
    Do you know how much AI usage happens on BYOD and unmanaged devices, and is it in scope?
Download the checklist (PDF)

One A4 page, no email required. You can also print this section directly from your browser.

Go deeper

FAQ

Häufige Fragen

Jede der sieben Fragen trägt Punkte bei, basierend darauf, wie viel ungovernierte KI-Nutzung Sie haben und wie wenige Kontrollen vorhanden sind. Eine höhere Einführung, regulierte Daten und schwächere Kontrollen erhöhen die Bewertung. Die Punkte werden auf eine Skala von 0 bis 100 normalisiert und einer Stufe zugeordnet: gering, mäßig, erhöht oder kritisch.

Sehen Sie Ihre reale Exposition gegenüber Shadow AI, keine Schätzung

Lassen Sie Aona 30 Tage lang parallel zu Ihren bestehenden Tools laufen. Entdecken Sie jedes KI-Tool und jeden Agenten, belegen Sie, wohin sensible Daten fließen, und aktivieren Sie die Durchsetzung dort, wo es darauf ankommt.