FREE 10-MINUTE CHECK

Can your current AI controls see beyond the company laptop?

Ten practical questions for IT and cyber teams. This is not a maturity score and it is not a compliance assessment. It is a quick way to expose the gaps that personal devices and personal AI accounts can create.

Answer each one as Covered, Exposed or Unknown.

Nothing is submitted. Your answers stay in this browser.

THE CHECK

Do you know the answer — or are you assuming?

“Unknown” matters. If a control exists but you cannot show that it covers the scenario, treat it as unknown for this exercise.

01 Personal phones photographing company screens

Do you have a clear control or rule covering employees photographing company information and using that image with an AI tool on a personal device?

02 Personal AI accounts

Can you identify or govern the use of personal ChatGPT, Claude, Gemini or similar accounts when company information is involved?

03 Meeting recordings

Is there a clear rule for recording meetings on personal devices and uploading audio or transcripts to AI tools?

04 Copying information across environments

Do your controls address company information being copied from managed systems into an unmanaged AI session on another device?

05 Sensitive data categories

Have you made it clear which kinds of company, customer, employee or commercially sensitive information must not be placed into unmanaged AI tools?

06 Approved versus unapproved AI

Can staff easily tell the difference between approved corporate AI use and personal or unapproved AI use?

07 Exceptions and named use

Is there a practical route for staff to declare or seek approval for AI use that falls outside your normal rules?

08 Incident reporting

If someone realises they have put sensitive information into an unmanaged AI tool, do they know how to report it quickly?

09 Ownership

Is there a named owner for deciding what happens when unmanaged AI use is found — IT, cyber, data protection, HR or another role?

10 Evidence, not assumption

Could you show leadership what controls exist today for personal-device and off-network AI use, rather than simply saying that your endpoint controls are strong?