All Services
AI under control

Shadow AI Assessment

Move from invisible AI use to controlled adoption.

Multi-week engagementAI governance

Verified discovery, policy, enablement, governance, and a funded roadmap help the organization use AI without leaving material risk unmanaged.

Led directly by SvenIndependent recommendationsScope agreed before delivery

Runs on the Galactus assessment platform: anchored questions, evidence-based scoring, and red flags that override averages. See how our assessments work

34 anchored questions · 4 model steps · EU AI Act context where relevant

Where this sits

  1. 1AI GRIP Scan (free, 2 minutes, self-service): Your first signal.
  2. 2AI Exposure Audit (1 day on site, fixed fee): Where AI actually lives and your three biggest risks, named.
  3. 3Shadow AI Assessment (multi-week): Full control: verified discovery, policy, enablement, governance, and a funded roadmap.
How this engagement stays controlledA senior mandate should make the decision, evidence, and accountability easier to control.

Decision first

The mandate starts with the decision, owner, time window, and evidence that could change the answer.

Evidence and boundaries

Scope, exclusions, evidence access, and uncertainty are made explicit before conclusions are presented.

Accountable handover

Sven leads the work directly and closes with clear ownership, decisions, and next actions.

Build controlled adoption

How Shadow AI becomes a governed operating system

Discovery, policy, ownership, enablement, and roadmap decisions are connected without pretending that governance is a certification exercise.

Discover

What is Shadow AI?

Shadow AI is the use of AI tools, models, assistants, extensions, or embedded vendor features without sufficient visibility, approval, ownership, or control. The risk is not limited to public chatbots. It also includes personal accounts, standing access to company data, unreviewed data flows, and AI-assisted decisions whose output is not adequately checked.

Control model

What an AI governance framework needs to control

A practical AI governance framework connects an inventory of AI use cases and tools to accountable owners, permitted and restricted use, data rules, human oversight, vendor decisions, incident handling, AI literacy, and evidence that controls operate. The objective is controlled adoption: useful AI can move forward while material risks remain visible and owned.

Operating change

From discovery to policy, ownership, and enablement

The assessment verifies what is in use, maps material data and decision exposure, and separates sanctioned use from uncontrolled workarounds. It then establishes a policy people can follow, decision rights leadership can enforce, approved paths that support productive use, prioritized controls, and a funded roadmap.

Regulatory context

EU AI Act context without a compliance claim

Relevant EU AI Act concepts are used as context where they affect the organization, including its role, AI literacy, use-case visibility, risk classification, human oversight, and documentation. Galactus does not certify EU AI Act compliance or provide a legal opinion. Legal interpretation remains with qualified counsel.

Decision dossier

What this mandate decides, includes, and hands back.

The useful boundary is visible before the work begins: the decision, the evidence, what is excluded, and what happens next.

Decision

The decision this supports

What AI use to permit, restrict, enable, fund, and govern, and who must own each decision.

Included

In scope

Use cases, tools, data exposure, policy, ownership, controls, literacy and enablement, vendor dependencies, relevant governance obligations, and the funded path forward.

Boundary

Out of scope

A blanket certification of legal compliance, individual employee monitoring, model development, or implementation of every selected control unless separately scoped.

Evidence

Evidence required

Policies, inventories, approved usage and vendor records, relevant logs or expense data where lawfully available, data classifications, contracts, stakeholder interviews, and control evidence.

Handover

What happens next

Leadership receives verified findings, governance decisions, prioritized controls, ownership, and a roadmap that can be funded and governed.

Belgian context

Shadow AI is already a leadership issue in Belgium

Public AI tools, personal accounts, browser extensions, and embedded vendor features can enter daily work before governance catches up. The practical question is whether leadership can verify the tools, data flows, owners, and decisions involved.

Read the Belgian evidence and first-control framework

How the mandate is set up

Timing

Multi-week engagement

Delivery owner

Every mandate is led directly by Sven Van Roosenbroek. Specialist involvement, when needed, is made explicit in scope.

Commercial model

Fixed fee based on organization scope, evidence access, and governance depth.

What you receive

  • A verified inventory of AI usage: sanctioned, shadow, and the tools with standing access to your data
  • Data flows mapped per tool: what goes into which AI, under which contractual terms
  • A livable AI policy people can actually repeat, not a ban they route around
  • Your EU AI Act position: deployer obligations, high-risk use cases, literacy duty
  • Governance that covers vendor-pushed AI features, not just new tools
  • A maturity roadmap with owners, budget logic, and kill criteria

Use this when

  • Leadership teams adopting AI faster than they can govern it
  • Organizations with client or personal data flowing through AI tools
  • Boards that need assurance ahead of customer, insurer, or regulatory questions
  • Companies moving from isolated pilots to controlled adoption

Discovery involving usage logs or expense data is executed with explicit consent and respect for Belgian employee-monitoring rules (CAO nr. 81, GDPR); we review patterns, not individuals.

Bring the decision to a direct conversation.

Thirty minutes is enough to establish fit, the right depth, and the next responsible step.