Which tools are in use, and for what
Every observed tool is in the register, with vendor, country, hosting region, training policy and the kind of work it is used for.
Most teams cannot say which AI tools are running in their org. BeeSensible shows each one as it appears, counted anonymously, with a risk assessment and a suggested policy already attached. You decide what is allowed without starting from a blank page.
The method
Every BeeSensible module follows this cycle. Here is what it looks like for managing AI tools.
Which AI actually runs
Every AI tool your people open shows up, counted anonymously, including the ones nobody ever requested.
Your decision at the moment of work
When someone opens a tool you decided on, they see that decision, with the approved alternative leading.
What the policy delivers
The share of AI use through approved tools, the tools still missing a decision, and the trend behind it.
and again How the cycle works
The moment a new AI tool shows up in your org, it waits for a decision: allow it, allow it within a condition you set, disallow it, or decide later. Every tool starts with no decision, and nothing comes pre-selected. Confirm one at a time or decide a whole batch at once; the organisation always calls it, never BeeSensible.
Before you can decide anything about a tool, you need to know what it does with your data. Finding that out takes an afternoon per tool. We did it for 865: from Low to Critical, with the vendor, its country, its training policy and known incidents on the row. Filter on what matters to you, select a range, and set policy on many tools in one go. Tools your people have never opened are covered before anyone tries them.
And it grows every week. Tools discovered in organisations and in BeeSensible's own research land in a review queue, get assessed, and join the catalog with the full fact sheet. Hunting for facts to base policy on is no longer your job; deciding still is. New arrivals carry a badge in the catalog for 30 days.
Risk assessment
Every tool in the catalog is scored on six dimensions, each from 1 to 5, where higher means more risk. The dimensions do not weigh the same: what the vendor does with your data counts heaviest.
Data governance
Weight 6How the vendor handles your data: whether it trains on your input, offers a processing agreement, and where data is stored.
Jurisdiction
Weight 4Legal risk from where the vendor and its data live. Countries allowing state access or lacking GDPR adequacy score higher.
Compliance
Weight 3Alignment with GDPR and the EU AI Act, plus recognised certifications such as ISO 27001 and SOC 2.
Incidents
Weight 3History of breaches, leaks or misuse tied to this tool. More or more serious documented incidents score higher.
Integration scope
Weight 2How much access the tool asks for: from a standalone chat box up to connectors and actions inside your own systems.
Vendor trust
Weight 2Transparency about ownership and the underlying model, track record and maturity of the company.
From score to risk band
DeepSeek
Critical 86/100DeepSeek · China
Why this assessment
Incidents, with a source
Where a tool has a history, that history is listed with a link to the source. When a verified source is missing, the product says so in as many words. That keeps it a fact rather than a rumour.
EU AI Act
Next to our own risk assessment, every tool gets a classification under the EU AI Act. We keep those two apart on purpose: the risk score is our reading, the classification is about the duties the law attaches to a use.
Falls under a high-risk category of the EU AI Act (Annex III).
Transparency duty (Art. 50): must disclose it is AI, or label generated content.
No specific EU AI Act duties for this use.
The classification depends on which feature you use.
Infrastructure with no use of its own. Classification depends on what runs on it.
Not legal advice; based on the vendor's documented intended use.
What high risk covers (Annex III)
Where a tool lands on high risk, the product names the category that applies.
The register
The GDPR asks for a record of processing, NIS2 for a view of your suppliers, and the EU AI Act for demonstrable AI literacy. Because every observed tool is recorded with its vendor, hosting region and training policy, and carries a decision from your organisation, you can answer at any moment.
Every observed tool is in the register, with vendor, country, hosting region, training policy and the kind of work it is used for.
One decision per tool: allowed, limited use, not allowed, or no decision yet. Nothing is silently approved; the decision is always yours.
Anyone opening a tool you have decided something about sees it at that moment, right in the page. That the notice appeared is counted, without content and without a name, so you can show the mechanism actually reached people.
The overview does not establish that you comply with the law. It shows which measures you can substantiate with measurements, and which you cannot. The judgement stays with you.
Open a tool and you see it all together: the score with its per-dimension breakdown, why the assessment lands where it does, the EU AI Act classification next to it, and the documented incidents with their source. At the bottom you set the policy, and that decision is yours.
Risk breakdown
Higher = more risk (5 = worst)
Incidents
Turn on coaching and opening a tool that is not approved shows a notice from BeeSensible, right in the page. It leads with the approved alternative: one click on "Open Claude" and the person is working in a tool you stand behind. The safer options come from the catalog, but you decide which one is offered first. Continuing is always possible, never by reflex: for a not-allowed tool it takes a deliberate press-and-hold. Try both versions below.
Your organisation does not allow this tool for work. Use an allowed alternative.
When someone opens an AI tool, only the website's domain is counted, added up across the team. No names, no content, no individual tracking.
Every tool in the catalog comes with a suggested policy based on its risk. You confirm or override it. Your own decision always wins, on every screen and in the extension.
Open a tool that is not approved and a gentle notice appears in the browser, leading with the approved alternative. People can still continue.
Every notice is counted with what happened next: the alternative opened, or continued anyway. Per decision you see those outcomes side by side, in counts and never per person. If a not-allowed tool stays busy, that is not a verdict on your people but a question for your policy: is the alternative good enough, or was the line drawn in the wrong place?
Adoption is the positive story; Risk is the one that flags what needs your attention: disallowed tools still in use, undecided tools with real activity, and tools growing fast. A policy-compliance figure shows the share of AI use that runs through approved tools, and its trend, so you can see whether the gap is closing.
Roll out the extension and watch the list of AI tools fill in, with no agent rollout and no log collection.
Rens, BeeSensible
I am happy to give you a twenty-minute tour. Leave your details and I will find a moment that suits you. Calling or emailing works just as well.