Responsible AI Governance
The homepage sets out the problem: the IT list is not what is actually being used, and without a complete overview, every governance effort is built on a gap. This page shows how the scan builds that overview, step by step, and what it requires from you. More about the setup and scope of the scan can be found on What it is; what the scan concretely delivers can be found on Outcomes.
The scan begins with a survey tool that goes out to departments and employees, not just to IT. That is deliberate: shadow AI becomes visible through the people who use it, not through a central register that is, by definition, never complete. The survey can be divided among multiple people. A central coordinator sends out the survey, department heads or individual employees fill in their own part, and the answers come together in a single overview. What you provide is knowledge: which tools are used, for what purpose, with what data, and on whose initiative. No technical documentation, no legal interpretation in advance. Most of the time goes into gathering answers from the organization, not into filling it in itself; the more departments involved, the more rounds this requires.
The answers from the survey are supplemented with guided desk research: a structured search for applications that were never formally registered but do leave traces, such as browser extensions, API connections or standalone subscriptions. Everything that surfaces is classified using the aiacta datasets: what role an organization plays in relation to an application, provider or user, and what risk level applies under the AI Act. This is machine work based on established datasets, not interpretation by an advisor. That is also why the outcome remains explainable: every classification can be traced back to the rule and the dataset it is based on, not to an individual assessment that cannot be reproduced. Who is involved: the person managing the survey, and the individuals asked to verify an answer when a classification raises doubt.
The classification results in a timeline: what must already be in order under the rules, and what can be addressed later. This report does not just set out the status, it also exposes where accountability, human oversight or monitoring are missing for applications that are already in use. The order matters more here than a deadline: first make visible what is going on, only then determine what is urgent. The report comes in a form that can be read both at detail level, per application, and in summary, per risk category. Who invests time in this: mainly the person who coordinated the earlier steps, to check the outcome against what is known within the organization.
The final step delivers a governance framework as a set of templates, built to connect to the risk structure that already exists. Not a second process alongside the first, but a filling in of what is missing from the existing structure. In addition, there is a one-page board report: a summary suitable for a boardroom table, without the underlying detail list. What a repetition later delivers is contained in the horizon scanner subscription: a recurring scan that shows what has been added, what has changed in risk classification, and where the timeline needs to be adjusted. Shadow AI does not stand still; a one-off scan is a snapshot, the subscription turns that into a series. Who is involved: whoever becomes owner of the template within the organization, and the person who passes on the board report.
The scan is not an AI Act compliance tool for register, classification and literacy; for that full field, aiacta.eu is the home, and that boundary does not shift. The scan structures what is there, it does not prove a track record: there are no completed engagements being referenced, only a method that relies on datasets. And the templates are meant to connect to the existing structure, not to give rise to a new process alongside it.
What happens after the report is a choice. Those who continue on their own keep the register, templates and timeline in their own hands, with literacy built up through the aiacta seats. Those who prefer to hand off part of it engage a partner for the design of the oversight and its embedding into the existing risk structure. Those who want to outsource the entire governance process do so with a partner, with the scan as the file to build on. More background on these choices can be found in the knowledge base.
The scan as described here has not yet been built; the button on this site is in waitlist mode. Those who sign up will be kept informed as soon as the first version becomes available.
Making AI use visible is one side of the story; the other side is what it means for tasks, hours and systems in the organization. Those who want to calculate that can find the sequel to this overview at the work scan of [FTE TO AI](https://ftetoai.com).
Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.