Assessment Tool

AI Vulnerability Audit

Evaluate your cross-border AI regulatory and compliance risks

1. How do employees use public generative AI tools (e.g. ChatGPT, Claude) for client or corporate data?

No official guidelines; employees use public tools freely.
Strictly blocked, or only enterprise-grade private accounts with data privacy agreements are permitted.
Allowed with basic internal guidelines, but no technical enforcement/blocking.

2. Where is your AI data processing and model hosting infrastructure located?

Hosted on standard US cloud regions without data localization or GDPR compliance layers.
Fully localized in EU data centers, or hosted on sovereign private cloud infrastructure.
Hybrid model (primary EU hosting with selective data transfer or US endpoints).

3. Have you mapped your AI deployments against the EU AI Act classification system?

No, we have not evaluated which risk tier our AI applications fall under.
Yes, we mapped all models (Prohibited, High Risk, Limited Risk) and established conformity files.
Partially; we are preparing self-assessments but haven't finalized our compliance registry.

4. Do you audit your models for algorithmic bias and compliance with US FTC/SEC guidelines?

No, we do not audit or monitor our algorithms for bias or discrimination.
Yes, we perform regular algorithmic bias testing and document all model weights and decisions.
We have basic model validation but no specific cross-border bias auditing.

5. How are your training datasets sourced and audited for intellectual property (IP) and copyright?

We scrape public data or use pre-trained third-party models without IP audits.
Every dataset is fully audited, licensed, and checked for copyright flags.
We rely on standard cloud API warranties but perform no independent audits.

6. Do you have a clear procedure for human-in-the-loop oversight and validation of AI decisions?

No, AI decisions are fully automated and deployed directly without human review.
Yes, all high-impact AI outputs are manually reviewed and signed off by qualified staff.
Only certain high-risk departments have manual review procedures; others are automated.

7. Enter your corporate email to generate your AI vulnerability risk profile

AI Compliance Risk Profile

Analyzing your AI governance maturity...