Can you name every AI tool your employees used last week?

Almost no owner can. That's the problem — not the AI itself. Find out what's actually running inside your business, what it can reach, and whether it puts your compliance obligations at risk.

45%

of employees now use AI regularly on company devices — up from 15% a year earlier
Verizon DBIR 2026

1 in 5

breaches now involve an unsanctioned AI tool, adding roughly $670,000 to the cost
IBM Cost of a Data Breach

63%

of organizations breached this way had no AI governance policy in place when it happened
IBM Cost of a Data Breach

THE ACTUAL RISK

It’s almost never malicious.

It’s your best employee trying to move faster. A customer list pasted into a chatbot to clean it up. A contract run through a free assistant to summarise it. A browser extension nobody approved, quietly reading every page it’s opened on. The moment they hit enter, that data is outside your control — often retained by a company you never signed an agreement with.

Think of an AI assistant as an extremely capable, extremely confident intern. Fast, useful, and often right. But you wouldn’t hand a new intern the master password, unsupervised access to the client folder, and permission to take work home on a personal laptop. Right now, in most businesses, that’s exactly the access an ungoverned AI tool already has.


And if you carry compliance obligations — HIPAA, CMMC, NIST 800-171, PCI, or a cyber policy with a controls attestation — the stakes sharpen. “An employee used a tool we didn’t know about” does not satisfy an auditor, and it will not satisfy an underwriter looking for a reason to deny a claim.

STEP ONE · FREE

The AI Exposure Scorecard

Ten yes-or-no questions about how AI is actually being used inside your business. Five minutes, scored instantly, and you’ll know where you stand before you talk to anyone. No email required to see your result.

A sample of what it asks

  • Do you know which AI tools have permission to read your Microsoft 365 mail and files?
  • Do you have a written AI acceptable use policy your team has signed?
  • Are AI browser extensions controlled on company devices?
  • If an auditor or insurer asked today, could you document your AI controls?
  • In a compliance review, “not sure” counts as a no. Most owners score worse than they expect.

STEP TWO · FIXED FEE

What a scorecard can't tell you

The scorecard tells you what you know. It can't tell you what's actually happening inside your environment. The AI Exposure & Governance Assessment examines three independent layers, so findings are corroborated by evidence rather than inferred.

LAYER 01

Network

Which AI services were reached, from which device or identity, how often, and over what period. Including the long tail nobody has on a blocklist yet.

LAYER 02

Devices

Every AI application and browser extension installed across your machines — and precisely what data each one is able to read.

LAYER 03

Microsoft 365

Third-party applications holding standing permission to your mail, files, and calendars. These survive password changes and persist until an administrator revokes them.

WHAT YOU RECIEVE:

  • AI Tool Inventory — every service, extension, and connected application found, with evidence
  • Written Assessment Report — executive summary, findings, and severity ratings
  • Compliance Gap Matrix — each finding mapped to the framework or contract clause it affects
  • Remediation Roadmap — prioritised actions with estimated hours attached
  • Draft AI Acceptable Use Policy — tailored to your operations, ready for your counsel to review
  • Findings presentation — 90 minutes with your leadership team, on site or by video

TRANSPARENT PRICING

Fixed fee. No hourly surprises.

Priced by size and regulatory burden, not by hours — and the fee doesn't change with how much we find.

Tenant Snapshot

Want to see something real before committing to anything

$750

Fixed · 3 business days
Microsoft 365 permission audit
Every app that can read your mail and files
Two-page written finding
Credited in full toward a full assessment

Standard Assessment

26–75 seats, or multiple locations, or contractual security obligations

$3,500–5,000

Fixed · 3–4 weeks
All three evidence layers
Full deliverable set
Compliance gap mapping
Findings presentation
Credited toward remediation

[MOST COMMON]

Regulated

76+ seats, or HIPAA, CMMC, NIST 800-171, or NERC CIP in force

$7,500+

Fixed · 4–6 weeks
Everything in Standard
Framework control mapping
Cyber insurance questionnaire review
Audit-ready evidence pack

Up to 25 seats and non-regulated? Essential tier runs $1,500–2,500. Ask.

Fee credited
Engage us for remediation within 60 days and the full assessment fee is credited against that work. You’re not paying twice to find and fix the same problem.

WHO’S DOING THE WORK

I’ve done this before.

In 1994 I sat with CPAs who were nervous about moving off paper ledgers onto a computer. The machine was faster than they were, and that was exactly what scared them. My job was to show them how to trust it — carefully, with guardrails.

Thirty-two years later I’m having the same conversation about AI.

Heath Carlson, Principal · My Computer Pro LLC

Thirty-two years of technology consulting in the Valley. This assessment is delivered personally — not handed to a junior technician and not outsourced to a scanning vendor. The scan takes minutes; the judgement about what it means for your business is the part you’re paying for.

Microsoft Cloud Solution Provider | WatchGuard Silver Partner | Dell EMC Partner | Intel Channel Partner | Phoenix & Scottsdale

Step three · Free

Or just book twenty minutes

If you'd rather talk it through than read a page, pick a time that suits you. No form, no phone tag.

WE WILL

  • Talk through your score and what’s behind it
  • Cover what the assessment examines and why
  • Identify which compliance obligations actually apply to you
  • Give you a scope and a fixed price

WE WON’T

  • Tell you what’s in your environment — that takes the assessment
  • Put you through a sales sequence
  • Ask you to switch IT providers
  • Need more than twenty minutes of your day

Booking a call doesn’t reserve an assessment slot. Assessments are scheduled separately and capacity is limited — we’re taking six before year end. The call is where we work out whether it’s the right fit and when we could start.

Straight answers

Questions we get asked

Will this disrupt my team or slow anything down?

No. Collection is read-only and passive. Nothing is installed permanently, no setting is changed, and no one’s work is interrupted. Most staff never know it ran.

Do you see what my employees typed into ChatGPT?

No, and we say so plainly in the report. The assessment establishes which services were reached and what each tool is capable of accessing — not the content of what was sent. Content-level inspection requires different licensing, and if that’s what you need, the report tells you exactly what it would take.

Is this just a sales pitch for something else?

The assessment is the product, and it stands on its own. You get the full written findings whether or not you engage us for anything afterward. If we recommend remediation, the fee credits toward it — and if you’d rather have your existing IT provider do the work, the roadmap is written so they can.

What if you don't find anything?

Then you have documented evidence of that, which is worth having the next time a customer, auditor, or insurer asks. In practice, we have not yet run this in an environment that produced nothing worth acting on — the Microsoft 365 permission layer in particular almost always surfaces something the owner didn’t know about.

If I book a call, how soon could you actually start?

The call is usually within a week. The assessment itself depends on capacity — we run six at a time, and a Standard engagement takes three to four weeks from kickoff to findings presentation. We’ll tell you the real start date on the call rather than after you’ve signed something.

We already have an IT provider.

Most of our assessment clients do. This is a specific, bounded engagement, and a second set of eyes on a risk category that emerged faster than most providers have adapted to. The roadmap is written so your existing provider can execute it.

Start with the five-minute version.

Take the scorecard. If your number bothers you, we'll talk. If it doesn't, you've spent five minutes and learned something useful either way.