Sample AI Security Snapshot  ·  illustrative only  ·  fictional company, not a real client  ·  all data anonymised
Baimbroq
AI Security Snapshot · Tier 1

AI Security Snapshot -- Sample

The one-look picture a client receives from a fast, fixed-scope Snapshot: an automated AIMS scan plus a short expert review, turned into a prioritised, act-on-it view. Fictional example.

Prepared forHarbourline Logistics Ltd*
SectorLogistics (UK, ~30 staff)
EngagementAI Security Snapshot (a few working days)
ReportSample

01Snapshot

Where the AI risk sits today, in one look.

AI tools in use (approved)2
AI tools in use (shadow / unapproved)6+
Devices scanned (Mac / Windows)28
EU AI Act roleDeployer
Priorities flagged2 High · 2 Medium · 1 Low
Elevated
Risk posture
Driven by company data flowing into ungoverned AI tools. The top items are quick to close.

02Top priorities

The findings that matter most, weighted by likelihood and business impact. (A Snapshot surfaces the priorities; the full written report with the complete fix list is the deeper Tier 2 engagement.)

PriorityWhat we foundDo this next
High Staff paste company and customer data into free consumer AI tools (shadow AI) with no data agreement. Publish an approved-tools list; block the two highest-risk apps this week.
High Shared AI API key sits in a spreadsheet, full-access, no spend cap; one belongs to a former contractor. Rotate the key, scope it per service, add a spend limit.
Medium The website assistant passes visitor input straight to the model, a testable prompt-injection exposure. Separate instructions from input; add a topic guardrail and human hand-off.
Medium No written AI acceptable-use policy and no named owner for AI risk. Adopt a one-page AI use policy; name an accountable owner.
Low Staff are unsure which AI tools are actually approved. Share the approved list where people work; repeat quarterly.

03EU AI Act risk classification

Harbourline acts as a deployer. Here is what actually applies, on the real timeline.

ObligationStatusTimeline
AI literacy (Art. 4): staff using AI need a baselineGap no trainingIn force now
Transparency (Art. 50): label AI interactions / AI-generated contentPartial chatbot unlabelledApplies from Aug 2026
Prohibited practices (Art. 5)Clear none in useIn force now
High-risk duties (Annex III)N/A today no high-risk useDeferred to 2 Dec 2027*
* The high-risk (Annex III) obligations were deferred by the 2026 Digital AI Omnibus, now formally adopted (European Parliament final approval 16 June 2026; Council final approval 29 June 2026): standalone Annex III high-risk applies from 2 December 2027, and high-risk embedded in regulated products from 2 August 2028. For a firm like Harbourline the genuinely live items are AI literacy (Art. 4, in force now) and the transparency duties (Art. 50, from 2 August 2026). Defensible focus, not panic. This classification is a compliance aid, not legal advice.

04Recommended next step

Start here: this week

Close the two High items first: publish an approved-tools list and block the highest-risk shadow apps, and rotate the exposed API key. That removes most of the exposure in days. Then set a one-page AI policy and label the website assistant.

Want us to carry it out and keep it closed? The Tier 2 AI Security Systems engagement executes this end-to-end, and AIMS keeps watching your AI data flows so shadow AI does not quietly return.