AgileLabs

Security & Assurance · AI Exposure Assessment

AI Exposure Assessment

Which AI is in use, what company information has reached it, and what becomes notifiable if that exposure becomes public.

SPECIMEN. This is a layout sample showing the form of the report an assessment produces. The client, the tools, the accounts and every figure in it are invented. It is not a record of work performed for anyone, and nothing in it may be cited as evidence.
Client
xxxxxxxxxxxxxxxxxx · professional services, Singapore · 840 staff
Requested by
The audit committee, after a customer security questionnaire asked who approves AI tools
Scope
Two entities, Singapore and Malaysia. All staff. Contractors excluded by agreement
Window
4–28 August 2026 · four weeks, fixed scope
Sources
Identity provider, network egress, twelve months of card and subscription spend, endpoint inventory
Interviews
Nineteen, under the sponsor’s written no-discipline commitment
Classification
Confidential · the board version is separate and carries no exploitable detail

1  Scope, and what was deliberately excluded

Exclusions are what a regulator reads first, so they are written as exclusions.

In scope. Every AI application reachable from a managed device or a corporate identity, whether approved or not. The data those applications can read. The contractual posture of each, by account tier. AI features inside tools already sanctioned. AI agents and their tool connections.

Out of scope, by agreement. Contractor and agency devices. The Malaysian entity’s finance system, which is on a separate tenancy. Personal devices not enrolled in management, where nothing is measurable and nothing is claimed.

Stated in the scope and repeated here. Interviews ran under a written commitment that nothing disclosed would be used for employee discipline. Contract reading states a posture; it is not legal advice and the client’s counsel owns the conclusion. Probe testing surfaces real sensitive data and was handled inside the client environment only.

2  What the four records showed

No single source shows how AI is actually being used. The disagreements are the findings.

SourceAI applications seenWhat it missed
Identity provider34Anything used without an OAuth grant against a corporate account
Network egress61Use on cellular, and anything inside an already-sanctioned tool
Expense records9Everything on a free or personal tier, which is most of it
Endpoint inventory27Browser-based tools leaving no installed artefact
Reconciled register73

Nine applications appeared in exactly one source. Every one of those nine was investigated, and three of them produced findings in section 4. The expense ledger, which the previous year’s review had used as its primary source, saw nine of the seventy-three.

Fifty-one of the seventy-three run on personal or free-tier accounts against which the organisation holds no contract, no retention position and no deletion right.

3  The register

The asset this engagement produces. Twelve of seventy-three rows shown; the full register is delivered as a spreadsheet the client owns.

ToolOwnerAccount tierData observedContract postureBand
General assistant AFirm-wideEnterpriseClient documentsNo training on inputs; 30-day retentionAccepted
General assistant Axxxxxxx, advisoryPersonal freeClient documents, draft filingsConsumer terms; trains on inputs by defaultImmediate
Code assistantEngineeringBusinessPrivate repositoriesNo training; enterprise agreement in placeAccepted
Code assistant BUnattributedPersonal freePrivate repository contentsConsumer termsImmediate
Meeting transcriberxxxxxxx, partnersPersonal paidClient calls, including privileged mattersRetains recordings indefinitelyImmediate
Translation toolOperationsFreeContracts in draftNo deletion rightPlanned
Design assistantMarketingTeamUnpublished campaign materialStandard terms; acceptableAccepted
Assistant inside the CRMSalesBundled, switched onFull customer recordCovered by the CRM agreementPlanned
Assistant inside the document storeFirm-wideBundled, switched onEverything the asker can openCoveredImmediate
Note-taking agentxxxxxxx, financePersonal freeBoard papersConsumer termsImmediate
Research agent, three tool connectionsAdvisoryTeamReaches mailbox and driveConnections never reviewedPlanned
Grammar checkerFirm-wideFreeOutbound email textConsumer termsAccepted

The band is set by consequence, not by count. Two hundred people using a grammar checker is accepted; one person putting board papers into a free account is not.

4  The findings worth acting on

Ten in the full report. Three shown, each with a fix, a named owner and its PDPA position.

ImmediateFinding 1

The document-store assistant returns everything the asker can already open

The assistant was switched on across the firm as part of an existing licence. It enforces existing permissions correctly, which is the problem: a decade of sharing has left 2,140 documents open to all staff, including two folders of partner compensation and one containing draft redundancy plans. A plain question returns them.

The evidence

Probe run from a low-privilege account, xx xxxxxx xxxx:

  "what changes are planned to headcount this year"
  -> returned 3 documents, incl. draft redundancy plan, xxxxxxxx team

  "what does a senior manager earn here"
  -> returned the current compensation band sheet

The assistant did not leak anything. It faithfully surfaced permissions that were already wrong, which is why this is a permissions finding rather than an AI finding.

Fix, owner, PDPA

Restrict the two worst site collections this week, then run the permission remediation across the tenancy. Owner: xxxxxxxxx, head of IT. Notifiable if public: yes for the compensation data, on the PDPC clock, as it identifies individuals.

ImmediateFinding 2

Private repository contents went into a consumer-tier code assistant

An engineer used a free-tier assistant against two private repositories for roughly four months. The consumer tier of that product trains on inputs by default and the account has no enterprise agreement behind it. Source code is the most common data type to leave this way, and this is the ordinary version of it rather than an unusual one.

Fix, owner, PDPA

Provide the approved assistant on the business tier, block the consumer domain, and rotate any credential that appeared in the affected repositories. Owner: xxxxxxxxx, engineering lead. Notifiable if public: no personal data identified; commercially material.

ImmediateFinding 3

Board papers went through a personal free-tier note-taking agent

One account in finance connected a note-taking agent to a personal mailbox holding forwarded board papers. The agent holds a live connection to that mailbox and to a drive folder. No approval exists and no contract does.

Fix, owner, PDPA

Revoke the OAuth grant, request deletion under the consumer terms and record the response, and add the tool to the blocked list. Owner: xxxxxxxxx, CISO. Notifiable if public: assessable, as the papers name individuals in a redundancy context.

5  Against the published base rates

Benchmarked so the board sees the organisation against the industry rather than in isolation.

MeasureThis organisationPublished rate
AI use on personal accounts70% of applications foundAround two-thirds
Most common data type leavingSource codeSource code, by a wide margin
Overshared sites in the tenancy184150 to 300 in a typical tenant

On every measure the organisation sits inside the published range. That is the useful finding for a board: this is the ordinary condition of a firm this size that has not looked before, and it is not evidence of unusual negligence.

6  The board version

One page, forwardable, carrying no detail an attacker could use. Reproduced here in full.

For the audit committee · 28 August 2026

What we found

  1. Seventy-three AI applications are in use. Nine were previously known.
  2. Seventy per cent run on personal or free accounts the organisation holds no contract over. This is in line with published rates for firms of this size.
  3. Three exposures need action this month. Two involve information that would be assessable as a data breach if it became public.
  4. The largest single exposure is not an unapproved tool. It is an approved assistant correctly enforcing permissions that were already wrong.
  5. A register now exists, with an owner named against every entry. It is the baseline for anything that follows.

The decision this asks for: approve the permission remediation programme, and decide whether an approved assistant is provided on a business tier. Nothing else on this list is stable while staff have no sanctioned option.

7  Evidence appendix

What a regulator or a customer’s auditor reads.

The full report carries the verbatim probe prompts and their outputs, hashes and timestamps for every log extract, the OAuth grant export with dates, the twelve-month spend extract, and the interview record in anonymised form under the no-discipline commitment. Prompts and outputs are handled as the confidential data they are and were never copied outside the client environment.

8  Limitations