Schedule 15 Minute Ai Risk Review

Every One of These Is the Same Chain, Cut at a Different Point

Underneath all five is one chain with four links. An AI resource exists. It runs as an identity. That identity reaches data. And something either records the sequence or it does not. Shadow AI is the chain when nobody registered the first link. Agent and MCP security is the chain when that link acts on its own. Identity is the second link, data leakage the third, governance the fourth, and governance is the only one judged by an outsider rather than by you.

The middle is where it breaks. Among organisations that experienced an AI related breach, 92 percent lacked proper AI access controls, according to IBM's 2026 Cost of a Data Breach Report, based on 602 breached organisations across 17 industries and 16 countries. That is the breached subset, not everyone, so the planning figure is the companion one: the same 2026 IBM report found only 40 percent of organisations reported using access controls on AI models and data at all.

Where to start

Read the Left Column. The Row You Recognise Is Your Page.

One sentence per risk, written the way security leaders say it. If more than one is true, the next section says which comes first.

What you keep saying
The risk type
What is missing
Read it here
We do not know what our people signed up for.
Shadow AI
An inventory with an owner
Every unsanctioned AI tool, extension, and agent
Something here is taking actions nobody reviewed.
AI Agent and MCP Security
A trust score per agent, MCP server, and skill
The AI that acts on its own
We do not know what our AI is allowed to reach.
AI Identity Security
The link from each AI resource to its account
Which identity each AI runs as
We do not know what has already left.
AI Data Leakage Prevention
Inspection that judges the destination
Sensitive data at the moment it is shared
We cannot prove this to a board or a regulator.
AI Governance and Compliance
Continuous evidence, not assembled on request
Meeting the dates with evidence already made

If Three of These Are True, Which Comes First?

Four of the five produce a queue. One produces a deadline. Governance obligations arrive on dates set by regulation rather than by your backlog, so governance is scheduled and the other four are ranked. Putting a dated obligation into a priority argument is how the date gets missed.

For the four that are ranked, the sort key is reach, not volume.

1
What reaches the most sensitive data, through the widest identity

The inventory says what exists. The identity says what it costs you if that thing is wrong.

2
What acts without a person in the path

A tool call turns a permission into an event with nobody deciding to use it.

Popularity is a poor sort key. Across the top 100 most used generative AI SaaS applications, 82 percent are classified as medium, high, or critical risk, according to Cyberhaven Labs' 2026 AI Adoption and Risk Report. Ranking by how many people use a tool returns nearly the same list as ranking by risk, and says nothing about reach.

See the A to F risk grade

One Object, Five Queues, Five Owners

A developer installs an MCP server on a Tuesday afternoon to save an hour. Nothing in that sentence is unusual and nothing in it is malicious. Read the same object five times.

Nobody registered it, so it is a shadow AI finding. It acts by making tool calls rather than answering questions, so it is an agent and MCP finding. It runs as a service account created years ago for something else and reviewed by nobody since, so it is an identity finding. That account reads a customer database, so it is a data leakage finding. None of those sentences exists in writing anywhere, so it is a governance finding.

One object, five queues, five owners, and five tools that each report a fragment and none of which say it is the same thing.

Deployment

Your AI Inventory. Ready in 24 Hours.

Getting started takes minutes, not months. AIBound connects to your existing environment in a single click.

Agentless Architecture
No software to install, no agents to manage
One-Click Integrations
100+ out-of-the-box integrations
First Insights in Hours
Complete AI inventory in 24 hours
Zero Production Risk
Read-only by design, no performance impact
GitHub
Slack
JAMF
CrowdStrike
Splunk
AWS
GCP
Azure
GitHub
Slack
JAMF
CrowdStrike
Splunk
AWS
GCP
Azure

Questions This Page Answers

Which of the five solutions should we start with?

Start with the risk whose failure would reach your most sensitive data, not the one with the most users. In practice that means mapping AI resources to the identities they run as first, because the identity decides how far a mistake travels. Governance is the exception, its dates are set by regulation, so it is scheduled rather than ranked.

Are these five separate products?

No. They are five views of one connected platform, organised by the risk a security team is answering for rather than by the capability that answers it. The same resource appears in more than one view when it carries more than one kind of risk. One record underneath, not five.

What is the difference between the Solutions pages and the Platform pages?

The Solutions pages are organised by risk type and answer, which of these is my problem. The Platform pages are organised by capability and answer, how does the product do it. A reader who knows which risk is keeping them awake starts here and follows one row. A reader evaluating the mechanism starts on the platform overview.

Can one AI tool appear under more than one of these five risks?

Yes, and the ones that matter usually do. An unregistered MCP server running as an over-permissioned service account is at once a shadow AI finding, an agent finding, an identity finding, and a data leakage finding once that account reaches regulated data. The categories say which question you asked, not which object you found.

We already run CASB, DLP, and an identity platform. Which of these five is not already covered?

The parts that live in a prompt, a tool call, or an inherited identity rather than in an account, a file, or a device. Those controls enumerate accounts, inspect artefacts, and govern principals, and AI exposure happens between all three. Each page names the gap in its own control category rather than calling that category obsolete.

Do we have to deploy anything before we can tell which of these applies to us?

No. Discovery is agentless and read-only by design, which is the deployment model stated across this site, so nothing is installed on endpoints and nothing sits in the path of production traffic. That is what lets you find which of the five risks you have before committing anyone to a programme of work.

Your AI Inventory Is Already Out There. Let's Map It.

See exactly which AI tools are running across your organization, scored, categorized, and ready for governance, in under 24 hours.