AI exposure report

Contoso (demo) · generated Sep 14, 2026 · trailing 30 days · data as of 2 h ago. Print this page for a board-ready PDF, or download the inventory workbook for the working register.

AI apps found
85
12 evidence sources
Need attention
24
6 critical · 18 high
People using AI
29
4 active this week
Sensitive data not blocked
8
4 blocked by policy
Summary

What the evidence shows

Lantern found 85 AI applications with a foothold in Contoso (demo): 3 hold Entra consent grants, 5 appear in network discovery (3 with no Entra footprint at all), 9 run on 10 managed devices, 5 show in the Microsoft 365 audit log including Copilot, 5 have accounts created with work email, 12 are built in Azure or Power Platform, and 5 appear in SIEM or exported logs.

29 people use AI with their work identity, 4 of them in the last seven days. 1 app was approved tenant-wide by an administrator, and 1 holds application permissions that work with no user present. Vendor emails show 9 account signups and 4 personal payments on work addresses.

Purview recorded 12 DLP events involving AI destinations. 4 were blocked and 8 were not, including 1 user override. The information types involved most were All Full Names, U.S. Social Security Number (SSN), Email Address.

Microsoft 365 Copilot handled 70 interactions for 12 people and surfaced 4 labeled resources. 1 custom agent and 3 Teams AI apps are in use.

This month

Recommended actions

  1. 01
    ChatGPT trains on data unless a business tier or opt-out is used. Verify which tier these users are on.
    CriticalChatGPTalsoGeminiChatGPT via Power PlatformGemini API (AI Studio)AWS AI ServicesAmazon Qand 3 more
  2. 02
    275 MB uploaded to DeepSeek in 30 days from 2 people. Check what data is leaving with Defender's file and session policies.
    CriticalDeepSeekalsoChatGPTOtter.ai
  3. 03
    DeepSeek shows up on the network but holds no Entra consent, so people are using personal accounts or no account at all. Conditional Access cannot see it; block or coach at the gateway with a Defender for Cloud Apps unsanction policy.
    CriticalDeepSeekalsoClaudeChatsonic
  4. 04
    The root user of account 123456789012 called Amazon Bedrock APIs. Root should never do day-to-day work: move this to an IAM role, enable MFA on root, and alert on any further root activity.
    CriticalAmazon Bedrock
  5. 05
    Bedrock model invocation logging is off in account 123456789012, so prompts and completions leave no record. Turn it on (CloudWatch Logs or S3) before this becomes the default way people reach models.
    CriticalAmazon Bedrock
  6. 06
    ChatGPT has tenant-wide admin consent. Confirm a documented approval exists, or revoke the grant and require per-user consent.
    CriticalChatGPT
  7. 07
    Scopes expose directory, email, files. Evaluate the vendor's retention and training terms before allowing continued use.
    CriticalChatGPT
  8. 08
    Otter.ai holds application permissions and can read data with no user signed in. Review the app role assignments and remove any that are not essential.
    CriticalOtter.ai
Severity

Ledger

  • Critical6
  • High18
  • Medium58
  • Low3
  • Info0
Coverage

Evidence by source

LaneAppsCritHigh
Entra consent320
Network511
Endpoint900
Audit log501
Email503
Azure & Power Platform1202
Purview DLP503
SIEM502
Source code1420
Identity1202
AWS410
Google Cloud604
Categories

Kinds of AI in use

  • Assistant31
  • Cloud AI platform17
  • Meeting notes9
  • Coding5
  • Search5
  • Agent platform4
  • Local runtime3
  • Writing3
  • Model hub3
  • Unclassified2
  • Embedded feature2
  • Image & video1
Highest risk

Top findings

SeverityAppSourceEvidencePeopleFirst action
Critical90Amazon Bedrock
Amazon Web Services · Cloud AI platform
AWS47 CloudTrail events by 6 identities, 4 denied, 3 resources in account 1234567890126The root user of account 123456789012 called Amazon Bedrock APIs. Root should never do day-to-day work: move this to an IAM role, enable MFA on root, and alert on any further root activity.
Critical85ChatGPT
OpenAI · Assistant
Entra consenttenant-wide consent, 26 sign-ins4ChatGPT has tenant-wide admin consent. Confirm a documented approval exists, or revoke the grant and require per-user consent.
Critical85Otter.ai
Otter.ai (AISense) · Meeting notes
Entra consent3 consenting users, 16 sign-ins3Otter.ai holds application permissions and can read data with no user signed in. Review the app role assignments and remove any that are not essential.
Critical81ChatGPT
OpenAI · Assistant
Source code4 repos, 3 packages, 2 keys02 keys for ChatGPT are in source control, including a public repository. Rotate them now, move to a secret manager, and turn on push protection so it cannot happen again.
Critical76Gemini
Google · Assistant
Source code1 repo, 1 packages, 1 keys01 key for Gemini is in source control, including a public repository. Rotate them now, move to a secret manager, and turn on push protection so it cannot happen again.
Critical75DeepSeek
DeepSeek · Assistant
Network2 users, 275 MB up2275 MB uploaded to DeepSeek in 30 days from 2 people. Check what data is leaving with Defender's file and session policies.
High70ChatGPT: sensitive data
OpenAI · Assistant
Purview DLP5 DLP events, 4 not blocked3ChatGPT trains on data unless a business tier or opt-out is used. Verify which tier these users are on.
High70DeepSeek: sensitive data
DeepSeek · Assistant
Purview DLP2 DLP events, 2 not blocked2DeepSeek trains on customer data. Block the app or move users to a business tier that excludes training.
High67Vertex AI
Google · Cloud AI platform
Google Cloud55 audit entries by 7 principals, 5 denied, 4 resources in 6 projects75 calls were denied by IAM. People are trying to reach Vertex AI; grant it through a reviewed role or add an organization policy restricting the service so the attempts stop.
High66ChatGPT
OpenAI · Assistant
SIEM · Splunk (demo)21007 events, 505 MB up via Splunk (demo)3ChatGPT trains on data unless a business tier or opt-out is used. Verify which tier these users are on.
85 open findings

AI inventory register

SevAppSourceEvidencePeopleLast seen
critical 90Amazon BedrockAWS47 CloudTrail events by 6 identities, 4 denied, 3 resources in account 1234567890126Sep 13, 2026
critical 85ChatGPTEntra consenttenant-wide consent, 26 sign-ins4Sep 11, 2026
critical 85Otter.aiEntra consent3 consenting users, 16 sign-ins3Sep 12, 2026
critical 81ChatGPTSource code4 repos, 3 packages, 2 keys0Sep 13, 2026
critical 76GeminiSource code1 repo, 1 packages, 1 keys0Sep 2, 2026
critical 75DeepSeekNetwork2 users, 275 MB up2Sep 12, 2026
high 70ChatGPT: sensitive dataPurview DLP5 DLP events, 4 not blocked3Sep 11, 2026
high 70DeepSeek: sensitive dataPurview DLP2 DLP events, 2 not blocked2Sep 10, 2026
high 67Vertex AIGoogle Cloud55 audit entries by 7 principals, 5 denied, 4 resources in 6 projects7Sep 13, 2026
high 66ChatGPTSplunk (demo)21007 events, 505 MB up via Splunk (demo)3Sep 14, 2026
high 62DeepSeekSplunk (demo)220 events, 140 MB up via Splunk (demo)1Sep 12, 2026
high 60ChatGPT via Power PlatformAzure & Power Platform3 connections in 1 env3Sep 9, 2026
high 60Microsoft 365 Copilot: sensitive dataPurview DLP2 DLP events, 1 not blocked2Sep 11, 2026
high 58ChatGPTEmail3 signups, 2 billing emails4Sep 13, 2026
high 55Azure OpenAI: dave-openai-testAzure & Power Platformaccounts in rg-sandbox-dave, public0n/a
high 55MidjourneyEmail1 signups, 1 billing emails1Sep 6, 2026
high 55Otter.aiIdentity0 sign-ins, 3 OAuth grants via Google Workspace (demo)3Aug 25, 2026
high 55Read AIIdentity0 sign-ins, 2 OAuth grants via Google Workspace (demo)2Sep 2, 2026
high 53Gemini API (AI Studio)Google Cloud38 audit entries by 2 principals in 2 projects1Sep 13, 2026
high 52Vertex AI Search and Agent BuilderGoogle Cloud32 audit entries by 2 principals, 2 resources in 1 project2Sep 13, 2026
high 51ChatGPTNetwork11 users, 50 MB up11Sep 14, 2026
high 51DialogflowGoogle Cloud6 audit entries by 1 principal, 1 resources in 1 project1Sep 12, 2026
high 50Microsoft 365 CopilotAudit log70 audit events12Sep 14, 2026
high 50Otter.aiEmail1 signups, 1 billing emails1Aug 18, 2026
medium 49Amazon SageMakerAWS13 CloudTrail events by 3 identities, 2 resources in account 1234567890123Sep 13, 2026
medium 48AWS AI ServicesAWS35 CloudTrail events by 2 identities in account 1234567890122Sep 13, 2026
medium 48Amazon QAWS30 CloudTrail events by 5 identities, 1 resources in account 1234567890125Sep 13, 2026
medium 48ChatGPTEndpoint2 devices, 2 accounts2Sep 13, 2026
medium 48CursorEndpoint2 devices, 2 accounts2Sep 13, 2026
medium 48Local model filesEndpoint2 devices, 2 accounts2Sep 13, 2026
medium 48OllamaEndpoint2 devices, 2 accounts2Sep 13, 2026
medium 48Otter.aiNetwork4 users, 90 MB up4Sep 14, 2026
medium 45Contoso HR AssistantAudit log18 audit events7Sep 14, 2026
medium 45GeminiSplunk (demo)560 events, 7 MB up via Splunk (demo)2Sep 14, 2026
medium 45GrammarlyEndpoint3 devices, 0 accounts0n/a
medium 45GrammarlyIdentity0 sign-ins, 1 OAuth grants via Google Workspace (demo)1Aug 12, 2026
medium 45MeetingMind NotetakerEntra consent1 consenting user, 3 sign-ins1Aug 30, 2026
medium 45Perplexity: sensitive dataPurview DLP1 DLP events, 1 not blocked1Sep 13, 2026
medium 45Zoom AI CompanionIdentity0 sign-ins, 1 OAuth grants via Google Workspace (demo)1Sep 6, 2026
medium 43ClaudeEmail2 signups, 0 billing emails1Sep 7, 2026
medium 42Azure Machine Learning: aml-researchAzure & Power Platformworkspaces in rg-datasci, public0n/a
medium 42Read AIAudit log3 audit events2Sep 5, 2026
medium 41ClaudeSource code2 repos, 1 packages0Sep 12, 2026
medium 40ClaudeSplunk (demo)320 events, 7 MB up via Splunk (demo)1Sep 13, 2026
medium 40DeepSeekEndpoint2 devices, 2 accounts2Sep 12, 2026
medium 40Gemini AI (custom)Azure & Power Platform1 connections in 1 env1Sep 2, 2026
medium 40PerplexityEmail2 signups, 0 billing emails1Aug 31, 2026
medium 40PerplexityEndpoint1 devices, 0 accounts0n/a
medium 39Gemini for Google CloudGoogle Cloud30 audit entries by 3 principals in 1 project3Sep 13, 2026
medium 39GitHub CopilotSource code2 repos0Sep 13, 2026
medium 39Google Cloud AI APIsGoogle Cloud30 audit entries by 2 principals, 1 resources in 2 projects2Sep 13, 2026
medium 38ChatGPTIdentity10 assigned, 60 sign-ins via Okta (demo)10Sep 14, 2026
medium 38ClaudeNetwork3 users, 6 MB up3Sep 13, 2026
medium 38LM StudioEndpoint1 devices, 1 accounts1Sep 11, 2026
medium 37Azure AI Services: ais-multiserviceAzure & Power Platformaccounts in rg-ai-prod, public1n/a
medium 37Azure Bot Service: contoso-helpdesk-botAzure & Power Platformbotservices in rg-bots, public1n/a
medium 37Otter.aiAudit log2 audit events1Aug 24, 2026
medium 34Claude CodeSource code1 repo0Sep 11, 2026
medium 33GleanIdentity12 assigned, 90 sign-ins via Okta (demo)12Sep 14, 2026
medium 32Local modelsSource code2 repos0Sep 11, 2026
medium 31CursorSource code1 repo0Sep 13, 2026
medium 31Hugging FaceSplunk (demo)60 events, 1 MB up via Splunk (demo)1Sep 8, 2026
medium 31Hugging FaceSource code2 repos, 3 packages0Sep 11, 2026
medium 31LangChainSource code1 repo, 1 packages0Sep 11, 2026
medium 31LiteLLMSource code1 repo, 1 packages0Sep 11, 2026
medium 31MicrosoftSource code1 repo, 1 packages0Sep 8, 2026
medium 31VercelSource code1 repo, 2 packages0Sep 13, 2026
medium 30Azure AI Foundry: proj-support-agentAzure & Power Platformworkspaces in rg-ai-prod0n/a
medium 30Azure OpenAI via Power PlatformAzure & Power Platform3 connections in 2 envs3Aug 30, 2026
medium 30Azure OpenAI: aoai-prod-eastusAzure & Power Platformaccounts in rg-ai-prod1n/a
medium 30ChatGPTIdentity0 sign-ins, 5 OAuth grants via Google Workspace (demo)5Aug 16, 2026
medium 30MeetingMind NotetakerAudit log1 audit events1Sep 8, 2026
medium 29Gemini for WorkspaceIdentity0 sign-ins via Google Workspace (demo)8Sep 14, 2026
medium 29Otter.aiIdentity4 assigned, 14 sign-ins via Okta (demo)4Sep 14, 2026
medium 29PerplexityIdentity22 sign-ins via Google Workspace (demo)5Sep 11, 2026
medium 28ChatsonicNetwork1 users, 1 MB up1Sep 5, 2026
medium 26AiderSource code1 repo0Sep 2, 2026
medium 26Azure OpenAISource code1 repo, 1 packages0Sep 8, 2026
medium 25AI Builder via Power PlatformAzure & Power Platform1 connections in 1 env1Jun 16, 2026
medium 25Azure AI Foundry: hub-contoso-aiAzure & Power Platformworkspaces in rg-ai-prod1n/a
medium 25Azure AI Services via Power PlatformAzure & Power Platform1 connections in 1 env1Aug 15, 2026
medium 25Claude: sensitive dataPurview DLP2 DLP events, 0 not blocked1Sep 6, 2026
low 20Hugging FaceEndpoint1 devices, 1 accounts1Sep 8, 2026
low 20JasperIdentity2 assigned, 0 sign-ins via Okta (demo)2n/a
low 8MeetingMind AI NotetakerIdentity1 assigned, 0 sign-ins via Okta (demo)1n/a
Data sources

Where this came from

SourceKindStatusSynced
Contoso
all sources available
Microsoft 365 tenantactive2 h ago
Splunk (demo)
SIEM (fixture)active2 h ago
GitHub (demo)
Source code (fixture)active2 h ago
Okta (demo)
Identity (okta)active1 h ago
Google Workspace (demo)
Identity (google)active1 h ago
AWS (demo)
AWS account (123456789012)active42 min ago
Google Cloud (demo)
Google Cloud (organizations/123456789012)active42 min ago
Method

How to read this

Each finding is one AI application as seen by one evidence source. The same product can appear more than once when several sources see it; those findings link to each other and corroborate the risk.

Risk scores combine how confidently the app was identified, what it can reach, how many people use it, how it was approved, the vendor's training and retention terms, and, where Purview data exists, whether sensitive data reached it and whether policy stopped it. Sanctioned apps are discounted but still listed.

Recommendations are generated per finding from the evidence and rolled up above by action. Nothing in this report modifies the tenant; every source is read-only.

Delivery

Email this report on a schedule

not scheduled