Security & Assurance/AI Exposure Assessment
We help organisations find which AI tools are being used, what company information they can access, and what that exposes the organisation to.
Agile Labs starts with identity records to find AI services connected to company accounts, then compares them with endpoint, network and expense records to uncover other AI use.
For each tool, we establish who is using it, whether it is approved, which account tier it is on, what company information it can access, and what systems or agents it connects to.
We bring this into a single AI inventory showing what is being used and what each use exposes the organisation to.
OneSystems
Mid to high priority vulnerabilities found and closed in mission-critical software already running in production.
Read the OneSystems story →
We compare the records that show how AI is actually being used, then investigate the differences to establish what company information each tool can access and which exposures need attention.
Identity records show which AI applications are connected to organisational accounts and who has access to them. We compare this with what employees report using to establish the first view of AI use.
We compare identity with network, expense and endpoint records. Network traffic shows which services are being reached, expenses show what is being paid for, and endpoints reveal installed tools and browser extensions.
The records rarely agree. A tool used by employees but missing from the approved register, traffic to something nobody declared, or an account with no known owner becomes something we investigate.
For each relevant tool, we establish the account tier, what company information it can access, what contractual terms apply and what it connects to. We test approved assistants where necessary and rank findings by consequence.
From finding the AI in use to delivering a complete AI exposure assessment.
Build the AI inventory from identity, network, expense and endpoint records.
Confirm which AI tools are in use, who uses them and what company information they can access.
Test whether approved AI assistants can access sensitive information.
Combine the evidence into one register and rank the exposures that need attention.
Keep the register current as AI tools, owners and exposure change.
What organisations need to know about their AI exposure.
Around two-thirds of workplace AI use runs on personal accounts that never appear on a company card. The expense ledger finds the smallest part of it, and the identity provider finds the rest.
Read more →An assistant with a search index inherits every permission mistake of the last decade. It does not leak. It faithfully returns what the asking person could already open, which is usually more than anyone realised.
Read more →Not every finding is a breach. Under the PDPA some are, on a clock. What separates the two is the data class and who could reach it, not the tool it went through.
Read more →Find where AI creates risks your existing security controls were not built for.