30 Tage Risikoerkennung für generative KI:Jetzt starten
Zum Hauptinhalt springen

Kostenlose Risikobewertung für Shadow AI

Prüfen Sie Ihre Shadow-AI-Risiken

Beantworten Sie 8 Fragen zu KI-Nutzung und vorhandenen Kontrollen. Sehen Sie einen Orientierungswert und nächste Prüfschritte. Das Ergebnis ist ohne E-Mail verfügbar.

Diese Selbsteinschätzung basiert auf Ihren Antworten. Sie scannt keine Geräte oder KI-Konten. Der Wert ist keine gemessene Wahrscheinlichkeit eines Datenvorfalls.

Frage 1 von 813%

Wie viele Mitarbeitende hat Ihr Unternehmen?

Mehr Menschen bedeuten mehr Angriffsfläche für nicht genehmigte KI-Nutzung.

Free audit checklist

Shadow AI Risk Assessment Checklist

Aona's free interactive Shadow AI assessment provides an indicative 0 to 100 review-priority score from your answers. This checklist turns those dimensions into questions for IT, security and compliance. Record the teams, devices, AI services and review period in scope, then validate the reported controls with observed evidence and synthetic tests.

  1. Visibility and discovery

    • Build a scoped AI inventory

      For the teams, devices, client paths and review period in scope, which AI apps were observed and which areas remain unverified?

    • Move beyond surveys

      Is your visibility based on real usage telemetry rather than self-reporting or an annual questionnaire?

    • Map the data flows

      Do you know which AI tools receive company data via typed prompts, copy-paste or file uploads?

  2. Policy and acceptable use

    • Publish a written AI policy

      Is an AI acceptable-use policy written, communicated and acknowledged by every employee?

    • Name approved tools and banned data

      Does the policy list approved tools, prohibited data categories and an approval path for new tools?

    • Enforce it technically

      Is the policy backed by controls at the point of use, rather than relying on trust alone?

  3. Controls at the point of use

    • Block sensitive data in real time

      Can you stop PII, client data, credentials or source code before it reaches an AI tool?

    • Test redaction where supported

      For the chosen AI app, input and client path, does a synthetic test confirm which data is removed and whether the remaining content is permitted?

    • Cover files, not just prompts

      Do your controls inspect file uploads as well as typed text?

  4. Sanctioned AI adoption

    • Offer approved alternatives

      Have you sanctioned enterprise-grade options for the ChatGPT, Copilot, Gemini and Claude use cases employees already have?

    • Review account and service settings

      For each approved AI service and account type, have owners confirmed training use, identity, retention and processing-location settings?

    • Make approval fast

      Is there a well-known, fast route to request a new AI tool so employees do not route around IT?

  5. Incident readiness

    • Have a response plan

      Is there a documented plan for an AI-related data exposure, with named owners and timelines?

    • Test your detection

      Would your monitoring actually flag sensitive data pasted into an unsanctioned AI tool today?

    • Learn from near-misses

      Are past AI incidents and near-misses reviewed for root cause and fed back into controls?

  6. Device and identity foundations

    • Enrol devices

      Are endpoints under MDM or Intune so AI controls can be deployed and enforced at scale?

    • Centralise identity

      Is access to sanctioned AI tools governed through SSO, with Entra or a similar identity provider?

    • Account for unmanaged devices

      Do you know how much AI usage happens on BYOD and unmanaged devices, and is it in scope?

Download the checklist (PDF)

One A4 page, no email required. You can also print this section directly from your browser.

Go deeper

FAQ

Häufige Fragen

Wie wird meine Risikobewertung für Shadow AI berechnet?
Ihre Antworten ergeben gewichtete Punkte für den Kontext, die angegebene KI-Nutzung und Kontrolllücken. Die Summe wird auf 0 bis 100 normiert und einer Prüfpriorität zugeordnet. Dieser Orientierungswert misst keine Wahrscheinlichkeit eines Datenvorfalls.
Ist die Bewertung kostenlos?
Ja. Die Bewertung ist vollständig kostenlos, dauert etwa zwei Minuten und zeigt Ihre Bewertung und maßgeschneiderte Empfehlungen sofort an. Sie müssen keine E-Mail eingeben, um Ihr Ergebnis zu sehen.
Was erhalte ich am Ende?
Sie erhalten einen Orientierungswert von 0 bis 100, eine Stufe und Empfehlungen anhand Ihrer Antworten. Die Anzahl variiert. Das Ergebnis bleibt ohne E-Mail sichtbar; auf Wunsch können Sie eine Rückmeldung anfordern.
Wie unterscheidet sich das von einer Compliance- oder Reifegrad-Bewertung?
Dies ist eine Selbsteinschätzung anhand Ihrer Antworten. Sie scannt keine Geräte oder KI-Konten, misst keine aktuelle Exposition und belegt keine Compliance. Nutzen Sie sie zur Planung einer abgegrenzten Bestandsaufnahme und Kontrollprüfung.
What is a Shadow AI risk assessment?
A Shadow AI risk assessment reviews unapproved employee AI use, sensitive-data exposure and the controls in place. This page provides a self-assessment of your reported context across eight questions, plus an ungated audit checklist. Validate the answers with an observed inventory and appropriate control tests; the questionnaire itself does not measure live activity.

Prüfen Sie die Kontrollen hinter Ihren Antworten

Wählen Sie eine KI-App, den geplanten Zugriff per Browser oder Desktop-App und einen synthetischen Prompt oder eine Datei. Prüfen Sie mit Aona die Richtlinienreaktionen, Belege und Voraussetzungen für die Installation.

Shadow-AI-Risikobewertung: kostenlose Selbsteinschätzung | Aona AI