Learn · TrustedAIGov® Enterprise Knowledge Platform
Informational Fresh portal_guide: PRD-110

AI Discovery Assessment

What it is. The engagement most customers start with: a short, read-only, out-of-band assessment that finds the AI your organisation actually runs — including the AI nobody declared — and grades your exposure against the obligations that bind you.

Who it's for. Organisations that cannot yet answer "how much AI do we run, and how exposed are we?" — which, honestly, is most organisations.

Features and what they mean

Feature What it means
AI inventory sweep Builds the first defensible inventory of AI systems in scope — declared and discovered.
Shadow-AI signals Detects ungoverned AI usage from proxy logs, code manifests and dependency signatures, with explainable confidence scoring — never a black-box verdict.
Exposure grading Each finding is graded against the frameworks that bind you (EU AI Act tiering first), so the output ranks what matters.
Read-only, out-of-band No production access, no agents installed — the assessment works from artefacts you export to it.

What you put in, what you get out

You put in You get out
Scope agreement and exported artefacts (logs, manifests) A graded AI inventory with discovered shadow AI
A conversation about your obligations An exposure assessment ranked by regulatory weight
48–72 hours of elapsed time The report — yours to keep, whatever you decide next

Your first session

  1. Agree scope with the TrustedAIGov team (what's in, what's out — the assessment says so either way).
  2. Provide the artefacts — nothing touches production.
  3. Receive the assessment and walk the ranked findings.
  4. If you continue, the inventory imports into the Governance Platform as your starting AI Estate — nothing is re-keyed.

Honest limits

It is a point-in-time assessment, not monitoring — continuous discovery is what the platform's Discovery capability does after onboarding.

Access: the AI_DISCOVERY_ASSESSMENT SKU — typically the first commercial step.