A worked example of the report a client receives at the end of a Baimbroq AI Security Audit: where the AI risk sits, what it means for the business, and exactly what to fix first.
Where the business stands today, in one page.
Meridian relies on AI in more places than its leadership realised. Beyond the two approved tools, the audit found staff routinely pasting client information into consumer AI apps, a customer-facing assistant with no input controls, and no written policy governing any of it. None of this is unusual for a firm of this size, and none of it is catastrophic today, but three findings expose regulated client data and would be difficult to defend in a breach or a regulator's question.
What we looked at, and how.
In scope
How we work
Testing is non-destructive and read-only. No production data is exfiltrated; prompt-injection tests use benign markers.
Severity combines how likely an issue is to be exploited or trigger a breach with how much it would hurt the business.
| Severity | What it means | Expected action |
|---|---|---|
| Critical | Active exposure of regulated data or a directly exploitable path. Reputational or regulatory harm likely if left. | Fix now (days) |
| High | Serious weakness that a plausible mistake or attacker could turn into a data loss or compliance failure. | Fix this quarter |
| Medium | Real gap that raises risk or blocks compliance, but needs other conditions to cause harm. | Plan & schedule |
| Low | Hygiene and hardening. Worth doing; not urgent. | Backlog |
Nine findings, ordered by severity. Detail follows.
| # | Finding | Area | Severity |
|---|---|---|---|
| F-01 | Regulated client data pasted into consumer AI tools (shadow AI) | Data flow | High |
| F-02 | Website AI assistant has no prompt-injection or input controls | App security | High |
| F-03 | AI API keys shared in plaintext and over-scoped | Access | High |
| F-04 | No AI acceptable-use policy or named owner | Governance | Medium |
| F-05 | AI vendor processing outside UK/EU with no transfer safeguards | Compliance | Medium |
| F-06 | EU AI Act classification not performed; Art.4 AI-literacy gap | Compliance | Medium |
| F-07 | No visibility of what AI tools are running or what data they touch | Monitoring | Medium |
| F-08 | No incident path for an AI-related data leak | Response | Low |
| F-09 | Staff unaware which tools are approved | Awareness | Low |
The three High findings in full; Medium and Low summarised.
| # | Medium & Low findings | Recommended fix |
|---|---|---|
| F-04 | No AI acceptable-use policy or owner. Nobody owns AI risk; there is no written line on what is and isn't allowed. | Adopt a one-page AI use policy; name an accountable owner. |
| F-05 | Cross-border processing, no safeguards. Primary AI vendor processes in the US with no transfer mechanism recorded. | Choose EU/UK-hosted options where possible; record transfer safeguards and update the privacy notice. |
| F-06 | No EU AI Act position; Art.4 gap. Deployer obligations not assessed; staff lack the required baseline AI literacy. | Classify each use; run short AI-literacy training (already in force); add transparency notices where AI interacts with people. |
| F-07 | No visibility. The firm cannot see which AI tools are running or what data they touch, so shadow AI reappears. | Introduce lightweight, metadata-level monitoring of AI data flows. |
| F-08 | No AI-incident path. If a tool leaked data, staff would not know who to tell or what to do. | Add an AI-leak scenario to the incident plan; brief the team. |
| F-09 | Approval unclear. Staff genuinely don't know which tools are sanctioned. | Publish the approved list where people work; repeat quarterly. |
Meridian acts as a deployer of AI systems. Here is what actually applies, on the real timeline.
| Obligation | Status for Meridian | Timeline |
|---|---|---|
| AI literacy (Art. 4) — staff who use AI must have baseline competence | Gap No training in place | In force now |
| Transparency (Art. 50) — tell people when they interact with AI / see AI-generated content | Partial Chatbot not labelled | Applies from Aug 2026 |
| Prohibited practices (Art. 5) | Clear None in use | In force now |
| High-risk system duties (Annex III) | N/A today No high-risk use identified | Deferred to Dec 2027* |
What to do, in what order. Most of the risk closes in the first two weeks.
The audit tells you where you stand. Two routes from here, and most clients use both:
Not sure where your firm sits? Begin exactly where this sample client did: a free 15-minute AI security consult, or the free 2-minute automated check. No install, no card, no obligation.
Book a free 15-min AI security consult