Service · Assessment
P0FlagshipAI Data Exposure Assessment.
Every business has data leaving to external AI now. Some of it is sanctioned. Most of it isn't. In two to three weeks we tell you exactly where, quantify the exposure, map it to the regulations that apply, and hand you a remediation plan that respects how your teams already work.
Outcomes
What changes when the engagement lands.
Honest exposure register
Every path your data takes to external AI — approved and unapproved — documented, sized, and understood.
Regulatory posture read
How your current AI usage sits against GCC PDPL, EU AI Act deployer obligations, and sectoral rules.
Prioritised remediation plan
The specific fixes worth doing first, ranked by risk exposure and effort.
Board-ready position paper
A document the executive team can present to the board or auditor without translation.
Deliverables
What's in the engagement.
A two- to three-week structured assessment of where your data leaves the environment via external LLMs today — sanctioned use, shadow usage, third-party tooling. Delivered as an exposure register, regulatory gap read, and remediation plan.
Exposure register
Every AI tool, integration, and workflow that sends data out. Sanctioned use and shadow use captured together.
Data category mapping
Which data categories are flowing where. PII, financial, health, IP — each traced to a destination.
Regulatory gap read
Applied against GCC PDPL, EU AI Act, and any sectoral regime relevant to your business.
Remediation plan
Prioritised fix list. What to close now, what to redirect through a gateway, what to formalise as policy.
How we deliver
Fixed scope. Named phases. Duration on the cover.
The engagement is priced against the outcome, not open-ended hours. Every phase has a duration, a named deliverable, and a check-out.
Total duration2 to 3 weeks
Sales cycle3 to 6 weeks
- 01Days 1 to 2
Access
Executive interview. Access to tooling registers, security logs, and network egress samples.
- 02Days 3 to 9
Discovery
Structured interviews across departments. Shadow-tool discovery. Data flow mapping.
- 03Days 10 to 12
Regulatory mapping
Exposure mapped against applicable regimes. Gap analysis.
- 04Days 13 to 15
Read-out
Written deliverable. Executive read-out. Board-ready position paper.
Built for
Buyers this engagement fits.
Typical buyer
CISO, CTO, Chief Data Officer, Head of Risk
CISOs whose staff use ChatGPT for work already
The tool is in the building whether policy allows it or not. The assessment tells you what's already moved through it.
Regulated businesses with an audit horizon
An external auditor is going to ask about AI data flows soon. Have the answer before the question.
Chief Data Officers under pressure to enable AI safely
The business wants speed. Risk wants control. The assessment gives you the map that lets you agree what safe looks like.
Related services
Where this leads next.
Safe LLM Gateway: Design & Pilot
Inline gateway design. PII and sensitive-entity detection. One-department pilot live.
Sovereign AI Readiness & Governance Baseline
Governance review. Model and data inventory. Control set mapped to ISO 42001. Certification roadmap.
Regulatory Readiness (EU AI Act / GCC PDPL)
Gap assessment against deployer obligations and GCC regimes. Closing roadmap.
Talk to us.
45 minutes on your operation and the engagement you have in mind. No pitch, no deck.
Lead intake
Request a briefing
A 45-minute call. No pitch, no deck. We ask the questions we'd ask a Discovery client and tell you honestly whether this is the right next move.