· Mohamed Ben Haddou · AI readiness  · 7 min read

Are you AI-ready? Part 6 — Security & Trust: the AI you don't know about is the AI you should worry about

Ask an IT director which AI tools employees already use and the honest answer is usually "no idea". The final dimension of AI readiness: shadow AI, the leakage vectors that matter, model risk and auditability — and why banning tools fails where offering a better alternative works. Plus: what the full six-dimension radar tells you.

Ask an IT director which AI tools employees already use and the honest answer is usually "no idea". The final dimension of AI readiness: shadow AI, the leakage vectors that matter, model risk and auditability — and why banning tools fails where offering a better alternative works. Plus: what the full six-dimension radar tells you.

Last of six articles on the dimensions of the Mentis READY Framework. The series so far: Strategy & Value, Data Foundations, Architecture & Infrastructure, Governance & AI Act, and People & Operating Model. This one is about the dimension that is already live in your organisation, whether you have started or not.

Usage precedes governance. Everywhere.

Five dimensions into this series, a reader could be forgiven for thinking AI readiness is about preparing for something that has not started yet. It is not. In every organisation we assess — every one — employees are already using AI: public chatbots for drafting and summarising, browser extensions, transcription bots sitting quietly in meetings, AI features switched on inside familiar SaaS tools by a vendor update nobody read.

So the first scorecard question for this dimension — “do you know which AI tools your employees already use?” — is not hypothetical, and the honest answers cluster at the bottom of the scale: no idea, or we suspect usage but have no view. That is shadow AI, and the name makes it sound more sinister than it is. Shadow AI is mostly conscientious people using the best tool they can find because the organisation has not offered one. The risk is real; the motive is usually diligence.

You cannot secure usage you cannot see. Which is why this dimension starts with visibility, not with controls.

What the dimension actually covers

  1. Visibility. A defensible answer to “what AI is in use here?” — including the unofficial layer.
  2. Leakage prevention. Controls that keep confidential and personal data out of systems that should not hold it — and an approved alternative, because prevention without an alternative just relocates the problem.
  3. Model risk. Knowing how the systems you rely on fail: wrong-but-confident answers, drift as the world changes, bias in the data (Part 2), and — for the newer agentic tools — inputs crafted to manipulate them.
  4. Auditability. The ability to reconstruct, after the fact, what an AI system did, on what data, and who checked it. If Part 4 defined the obligations, this is the machinery that makes them demonstrable.

The five maturity levels of Security & Trust

LevelWhat it looks like in practice
1 · Ad hocNo idea what AI tools are in use; nothing, in practice, prevents confidential data reaching public chatbots.
2 · ExperimentingSuspected usage, no view; a policy asks people not to; model risk not considered.
3 · StructuredA partial view of usage; some technical controls; risks understood for the main systems.
4 · ManagedAn approved tool list plus monitoring; data-loss prevention plus approved alternatives; logs kept and reviewed.
5 · OptimisedA governed catalogue with audited usage; controls monitored and tested, incident drills run; models risk-assessed and auditable.

Three questions that tell you where you are

These are the three the scorecard asks for this dimension.

Do you know which AI tools your employees already use? The jump from “no idea” to “a partial view” costs one anonymous survey and one look at network and expense data — an afternoon, not a programme. The jump to level 4 is a decision, not a technology: an approved list, published, with a request path for new tools that answers in days rather than quarters. Slow approval is the engine that manufactures shadow AI.

What prevents confidential data ending up in public chatbots? “A policy asks people not to” is the level-2 answer, and on its own it is close to worthless under deadline pressure — the person pasting a contract into a chatbot at 22:00 is trying to finish the work you gave them. Controls that work combine three things: technical friction on the worst flows (data-loss prevention on the obvious destinations), an approved alternative that is genuinely good, and training that explains the why (Part 5’s literacy obligation, earning its keep).

How do you handle model risk and auditability? “Not considered yet” is the most common answer and the one with the longest tail of regret, because auditability cannot be retrofitted onto decisions already made. The minimum that matters: for each system that touches decisions or customers, know its failure modes, log its use, and record the human check. That trail is what turns “the AI made a mistake” from a crisis into an incident.

Banning fails; substitution works

The reflex response to shadow AI is a ban. We have yet to see one work. Usage moves to personal devices and private accounts, visibility drops to zero, and the organisation converts a manageable risk into an invisible one — while telling itself the problem is solved.

What works is substitution: an approved assistant that is actually good, reachable in one click, with the confidentiality question answered by design. In regulated sectors that increasingly means an assistant that runs on your own documents, respects your access rights, and keeps data inside your perimeter — on EU infrastructure or on-premise (the sovereign path from Part 3; a document assistant that ignores access rights is a data breach with a chat interface, as Part 2 put it). Give people that, publish the short list of what remains forbidden and why, and shadow usage collapses on its own — not because people were caught, but because the sanctioned tool is finally the best one available.

Where the law lands on security

GDPR was the binding constraint on shadow AI before the AI Act existed: personal data pasted into a public chatbot is a disclosure to a third party — potentially a reportable breach with a 72-hour clock — and “an employee did it informally” is not a defence the regulator accepts. The EU AI Act adds the machinery for high-risk systems: logging, record-keeping, accuracy and robustness requirements, human oversight that can be demonstrated rather than asserted. And for many organisations in essential and important sectors, NIS2 obligations folded AI tools into general ICT risk management the moment they touched operations. None of these regimes names “shadow AI”; all three price it.

What to do in the next 30 days

If you recognise yourself at level 1 to 3:

  • Measure before you regulate. One anonymous survey (“what do you use, for what?”), one pass over network and billing data. Amnesty explicitly: you are mapping diligence, not hunting offenders.
  • Stand up the approved alternative. Even a modest sanctioned assistant beats an excellent forbidden one, because it comes with visibility. Route the most sensitive work to the most controlled tier.
  • Put friction on the worst flows only. Data-loss prevention aimed at the genuinely confidential categories, not blanket blocks that reignite the shadow layer.
  • Add AI to the incident playbook. Who acts (the owner from Part 5), what gets preserved (the logs from this part), who is informed (the register from Part 4). One page.

The radar, complete

That closes the six dimensions: what AI is for, whether the data is ready, where it runs, what the law requires, who owns it, and whether you can trust it. Plotted together they form a maturity radar — and the radar’s value is in its shape, not its average. A typical mid-market profile is lopsided: decent architecture, promising data, and a governance-and-people trough — which reads as “capability without control”, and tells you exactly where the next euro should go. The inverse shape — policies and committees ahead of any running system — is control without capability, and it burns momentum instead of risk. Balanced-but-low beats spiky-and-high, because the weakest dimension caps the value of the strongest ones; the radar makes that cap visible before the budget finds it out.

That radar — scored across all six dimensions, with the gaps prioritised and a 90-day plan attached — is the deliverable at the heart of the AI Readiness Assessment, our four-week, fixed-price diagnostic for mid-market organisations in regulated sectors.

Want your own reading first? The free AI Readiness Scorecard asks the three security questions above — and the fifteen across the other five dimensions — and gives you your maturity radar in four minutes. No account, no sales call attached; if you want a second opinion on your results, leave an email and we will write back within a business day.

Mohamed Ben Haddou is the founder of Mentis Consulting (Brussels, ULB spin-off, since 2005) and an Independent AI Expert for the European Commission.

Back to Blog

Related Posts

View All Posts »
Are you AI-ready? Part 4 — Governance & AI Act: the deadline is no longer in the future

Are you AI-ready? Part 4 — Governance & AI Act: the deadline is no longer in the future

Since 2 August 2026, the bulk of the EU AI Act applies. Most mid-market organisations still have no inventory of their AI systems — which means their exposure is unnamed, not absent. The fourth dimension of AI readiness: the register, the risk classifications, what deployers actually owe, and why governance done right is a rhythm rather than a scramble.