Two professionals reviewing security findings on a monitor in a navy office

Advisory review

AI security assessment: find every AI tool in use, then rank the gaps.

Most companies can list the AI tools they bought. Almost none can name the ones staff signed up for, or the AI a vendor switched on inside software you already run. We count all of it, work out what data reaches which tool, and hand you a ranked list of what to fix first.

In one sentence

We find every AI tool already in use, including the ones staff signed up for, and rank what to fix first.

  • Advisory review
  • Delivery
  • Monthly watch

One engagement, in this order. You can start at the stage that fits you.

Advisory review

What this work involves

Most companies can name the AI tools they bought. Few can name the ones staff signed up for on their own, or the assistants and add-ons that vendors switched on inside systems you already run. The AI security and governance assessment finds both. Governance here means the rules for AI use and who enforces them, so this is an AI governance assessment as much as a security one.

Each finding is measured against your AI Use Policy and ranked by what it exposes: what data is reaching which tool, under whose account, and how long it is kept. The result is a short list of gaps in priority order, not a hundred-page report.

Those priorities then decide what happens next. Which systems connect to the dashboard first, and what the AI security subscription watches from day one, both come from this list.

Who does what

You keep your team, and we take this part.

  • You — Give us access and tell us what matters most.
  • Third Shift — Find the tools, rank the gaps, and set the order.
  • Your IT firm — Fix what sits inside its own systems.
  • Software vendors — Answer for the AI they switched on.

Who it is for

A fit when

  • Leadership that suspects AI use is wider than the license count
  • Firms holding client, patient, or financial data under regulation
  • IT teams that want an outside read before AI is connected to live systems

Scope

What it is not

  • Not a penetration test or a general security audit
  • Not a replacement for your IT firm's security tools. It reads the AI layer on top of them
  • Not a one-time snapshot. The AI security subscription keeps it current

Where this has run

Profiles using this work.

All case studies

Who buys this

Industries that start here.

All industries

The order

Part of the sequence, not the whole of it.

In the method this work usually leads into Applications assessment (Assessment). Nothing obliges you to buy it: the order is how the work is delivered, not what you have to purchase.

Every service listing · How the method works

Questions

Questions about ai security & governance assessment

How do you find the AI tools staff signed up for on their own?

Third Shift finds AI tools staff signed up for on their own by reading sign-in records, network activity, browser add-ons, and expense claims. We also ask team leads what people are actually using. Personal AI accounts and browser add-ons are the most common finds, followed by AI features a software vendor switched on without anyone noticing.

Will the assessment conflict with our MSP's security work?

No, the assessment does not conflict with your IT firm's security work. Your IT firm protects the computers, the sign-ins, and the network. The assessment reads the AI layer on top of that: which AI tools are in use, what information reaches them, and under whose accounts. Where a fix lands on your IT firm, we share the finding with them.

What do we get at the end of the assessment?

At the end of the AI security assessment you get four things. A list of every AI tool in use, approved or not. A map of where your information goes and who can reach it. The gaps ranked by what they expose. And a short list of what to fix first, which sets what happens next.

All questions and answers

Start here

Start with the review.

The first conversation covers your environment, and this work is scoped from what it finds.