AI RISK & GOVERNANCE
Shadow AI Is Your Biggest Compliance Risk. Find It First.

AI adoption is moving faster than most organizations can govern it.
Waldo Security gives security, privacy, and compliance teams continuous visibility into which SaaS applications use AI, who is using them, where corporate data may flow, and what those AI capabilities can actually do.
Discover Shadow AI, identify higher-risk applications, and build an evidence-based AI governance program without manually investigating every SaaS vendor.

Shadow AI Is Bigger Than ChatGPT
AI governance is no longer just about employees using standalone generative AI tools.
AI assistants, copilots, agents, automated workflows, and embedded models are appearing inside the SaaS applications organizations already use every day. A vendor that was approved years ago may now process data through AI systems that did not exist when the original security review took place.
That creates a visibility problem.
Security Teams Need To Know
. . . . . . . . . . . . . . . . . . . . .
AI-enabled apps
Which applications use AI?
Controls
Can administrators disable AI?
Users & departments
Who is actually using them?
Capabilities
What can the AI actually do?
Training
Is company data used to train AI?
Approval
Does AI use require approval?
External models
Is data sent outside AI providers?
. . . . . . . . . . . . . . . . . . . . . . . . .
Discover Shadow AI Across Your SaaS Stack
Know where AI exists before trying to govern it.
Traditional application inventories only show the software organizations already know about.
Waldo Security first discovers the SaaS applications actually being used across the environment, then identifies which of those applications contain AI-powered capabilities.
This gives organizations a real-world view of their AI footprint without relying on:
-
Employee surveys
-
Self-reported AI inventories
-
Manually maintained spreadsheets
-
Procurement records alone
-
Browser extensions as the sole source of discovery
Teams can quickly identify unknown AI applications, unsanctioned AI usage, newly introduced AI capabilities, and departments with high levels of AI adoption.
understand
what the AI actually does . . .
Not every AI-enabled application creates the same level of risk.
Waldo evaluates the characteristics that determine whether an AI capability can be governed safely at enterprise scale.
what the AI actually does:
Customer Data & AI Training
Understand how vendors describe the use of customer data for AI model training.
Does the AI learn from our company's information?
Waldo helps surface whether:
-
Customer data may be used for training
-
Training requires opt-in
-
Training occurs unless customers opt out
-
Enterprise customers are excluded
-
Customer data is not used for training
-
The vendor’s position is unclear

Unknown or ambiguous training practices are themselves a governance concern because organizations cannot assess risk confidently when data handling is unclear.
what the AI actually does:
External LLM Exposure
Many SaaS applications rely on external AI model providers instead of operating their own models.

Is our information getting sent to another AI company?
Waldo helps identify when customer information may be sent to external LLM providers and, where evidence is available, which providers are involved.
This gives security teams greater visibility into the AI supply chain behind applications employees already trust.
what the AI actually does:
Administrative AI Controls
Determine whether administrators can control or disable AI functionality.
Can a company turn AI features on and off?
An organization may approve a SaaS application for traditional use while deciding that its newly introduced AI features are not yet appropriate.
Waldo highlights where AI controls are available, missing, incomplete, or unknown.

what the AI actually does:
AI Auditability
AI governance requires more than policy. Security teams also need to understand whether AI activity can be reviewed after the fact.

Can we review what happened after someone uses AI?
Waldo evaluates whether applications provide administrative visibility or audit logging that can help answer:
-
What information was submitted to AI?
-
Which user initiated the interaction?
-
What actions did the AI perform?
-
Was organizational policy followed?
prepare
For Action-Capable AI
There's a huge difference between an AI system that summarizes information and one that can act on it.
%20(1).png)
AI agents and automated SaaS features can increasingly:
-
Modify data
-
Create content
-
Send communications
-
Trigger workflows
-
Perform administrative activities
-
Interact with other applications
-
Execute automated processes
Waldo identifies AI functionality that can take actions and evaluates whether human approval is required before those actions occur.
That's how we help security teams assess a new layer of enterprise risk:
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
What happens when AI moves from generating information to performing work.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Prioritize AI Risk
Instead of reviewing every app equally.
Simply identifying hundreds of AI-enabled applications creates another inventory problem.
Waldo helps security teams prioritize applications where AI behavior creates greater organizational exposure.

Risk can increase when an application:
-
Can take actions on behalf of users
-
Sends customer data to external model providers
-
Lacks administrative AI controls
-
May use customer data for AI training
-
Has unclear AI data-handling practices
Instead of manually reviewing every AI-enabled SaaS application, teams can focus resources on the vendors and capabilities that deserve attention first.
ai governance
Turn AI governance into a continuous process
AI capabilities change fast.
A SaaS application that was considered low risk during its original review may later introduce:
-
A generative AI assistant
-
An external model integration
-
An AI agent
-
Autonomous workflow capabilities
-
New data-training practices
That's why AI governance can't be a one-time vendor questionnaire.
Waldo supports an ongoing SaaS governance lifecycle:
.png)
DISCOVER
Identify AI-enabled applications employees are actually using.
UNDERSTAND
Determine how AI behaves and how customer information may be handled.
ASSESS
Identify applications with elevated AI risk.
PRIORITIZE
Focus security reviews where the potential exposure is greatest.
GOVERN
Approve, sanction, restrict, or prohibit applications according to organizational policy.
MONITOR
Detect new AI applications and changing AI capabilities over time.
see ai adoption
by User, Department, & Software Category
AI adoption rarely happens evenly across an organization.
Waldo helps security teams understand where adoption is occurring by showing activity across departments such as:

→
Engineering
→
Marketing
→
Sales
→
Customer Support
→
Finance
→
HR
→
Product

Teams can also identify users with higher levels of AI application usage and understand which categories of SaaS are seeing the fastest AI adoption.
This can help distinguish between:
→
Teams experimenting with new workflows
→
Shadow AI requiring investigation
→
Areas of greater exposure
→
Employees who may benefit from approved alternatives
→
Early adopters who could support internal AI programs
evidence-based
For Action-Capable AI
AI risk scores shouldn't be unexplained black boxes.
Waldo gathers supporting evidence about vendor AI behavior and policies so security teams can understand why an application was classified a certain way.
Evidence may include vendor information related to:

AI capabilities

AI privacy policies

Data usage

Model training practices

Administrative controls

Auditability

External AI providers

Automation capabilities
Where information cannot be determined confidently, Waldo identifies it as unknown instead of making unsupported assumptions.
take AI Governance pro.
Build an AI Governance System of Record
Swap out those fragmented spreadsheets, security questionnaires, procurement records, and individual employee knowledge with a continuously enriched view of enterprise AI usage.

Over time, Waldo can provide a centralized source of information about:
→
Which AI applications exist
→
Who uses them
→
Which departments use them
→
What AI risks they introduce
→
Which applications have been reviewed
→
Which applications are sanctioned
→
Which applications remain unknown
why
Waldo Security for AI Risk & Governance?

Discover AI in the SaaS You Already Use
Find AI capabilities embedded inside SaaS applications, not just standalone AI websites.
Uncover Shadow AI
Identify unknown and unsanctioned AI applications that sit outside formal IT and procurement processes.


Understand Data Exposure
Investigate customer-data training practices, external LLM usage, and unclear vendor policies.
Evaluate AI Controls
See whether administrators can disable AI functionality and whether activity can be audited.


Identify AI Action Risk
Understand which AI systems can perform actions rather than simply generate information.
Prioritize Higher-Risk Applications
Focus security reviews on the applications most likely to create meaningful organizational exposure.


Govern Continuously
Monitor AI adoption and changing AI capabilities instead of relying on periodic reviews.
Frequently Asked Questions . . .
What is AI governance?
AI governance is the process of establishing visibility, oversight, policies, controls, and accountability for how artificial intelligence is used across an organization. Effective AI governance includes understanding which AI systems are in use, what data they process, what actions they can take, who uses them, and what administrative controls exist.
What is Shadow AI?
Shadow AI refers to AI applications or AI-enabled SaaS features used without formal organizational approval, visibility, or governance. Shadow AI may include standalone AI tools as well as AI functionality embedded inside SaaS applications employees already use.
How does Waldo Security discover Shadow AI?
Waldo discovers SaaS applications being used across the organization and identifies which applications contain AI-powered features. Then it enriches those applications with AI governance context such as training practices, external model providers, administrative controls, auditability, automation capabilities, and organizational approval status.
Why is Shadow AI a security risk?
Shadow AI can expose corporate data to applications, models, or external providers that security teams may not know are being used. The risks can include unclear data retention, customer-data training, unmanaged access, insufficient audit logs, and AI systems capable of taking actions.
Can Waldo identify whether customer data is used to train AI?
Waldo evaluates available vendor evidence about AI training practices and identifies whether customer data may be used for training, whether training requires opt-in or opt-out, whether enterprise customers are excluded, whether data is not used for training, or whether the vendor’s position is unclear.
Does Waldo identify external LLM providers?
Where supporting evidence is available, Waldo identifies whether a SaaS application appears to send information to external LLM or AI providers and can surface the providers involved.
Can Waldo show which users or departments are using AI?
Yes. Waldo can provide user- and department-level context around AI application usage, helping organizations understand where AI adoption is occurring and where governance efforts may need to be prioritized.
