The one-look picture a client receives from a fast, fixed-scope Snapshot: an automated AIMS scan plus a short expert review, turned into a prioritised, act-on-it view. Fictional example.
Where the AI risk sits today, in one look.
The findings that matter most, weighted by likelihood and business impact. (A Snapshot surfaces the priorities; the full written report with the complete fix list is the deeper Tier 2 engagement.)
| Priority | What we found | Do this next |
|---|---|---|
| High | Staff paste company and customer data into free consumer AI tools (shadow AI) with no data agreement. | Publish an approved-tools list; block the two highest-risk apps this week. |
| High | Shared AI API key sits in a spreadsheet, full-access, no spend cap; one belongs to a former contractor. | Rotate the key, scope it per service, add a spend limit. |
| Medium | The website assistant passes visitor input straight to the model, a testable prompt-injection exposure. | Separate instructions from input; add a topic guardrail and human hand-off. |
| Medium | No written AI acceptable-use policy and no named owner for AI risk. | Adopt a one-page AI use policy; name an accountable owner. |
| Low | Staff are unsure which AI tools are actually approved. | Share the approved list where people work; repeat quarterly. |
Harbourline acts as a deployer. Here is what actually applies, on the real timeline.
| Obligation | Status | Timeline |
|---|---|---|
| AI literacy (Art. 4): staff using AI need a baseline | Gap no training | In force now |
| Transparency (Art. 50): label AI interactions / AI-generated content | Partial chatbot unlabelled | Applies from Aug 2026 |
| Prohibited practices (Art. 5) | Clear none in use | In force now |
| High-risk duties (Annex III) | N/A today no high-risk use | Deferred to 2 Dec 2027* |
Close the two High items first: publish an approved-tools list and block the highest-risk shadow apps, and rotate the exposed API key. That removes most of the exposure in days. Then set a one-page AI policy and label the website assistant.
Want us to carry it out and keep it closed? The Tier 2 AI Security Systems engagement executes this end-to-end, and AIMS keeps watching your AI data flows so shadow AI does not quietly return.