AI exposure report
Contoso (demo) · generated Sep 14, 2026 · trailing 30 days · data as of 2 h ago. Print this page for a board-ready PDF, or download the inventory workbook for the working register.
What the evidence shows
Lantern found 85 AI applications with a foothold in Contoso (demo): 3 hold Entra consent grants, 5 appear in network discovery (3 with no Entra footprint at all), 9 run on 10 managed devices, 5 show in the Microsoft 365 audit log including Copilot, 5 have accounts created with work email, 12 are built in Azure or Power Platform, and 5 appear in SIEM or exported logs.
29 people use AI with their work identity, 4 of them in the last seven days. 1 app was approved tenant-wide by an administrator, and 1 holds application permissions that work with no user present. Vendor emails show 9 account signups and 4 personal payments on work addresses.
Purview recorded 12 DLP events involving AI destinations. 4 were blocked and 8 were not, including 1 user override. The information types involved most were All Full Names, U.S. Social Security Number (SSN), Email Address.
Microsoft 365 Copilot handled 70 interactions for 12 people and surfaced 4 labeled resources. 1 custom agent and 3 Teams AI apps are in use.
Recommended actions
- 01ChatGPT trains on data unless a business tier or opt-out is used. Verify which tier these users are on.CriticalChatGPTalsoGeminiChatGPT via Power PlatformGemini API (AI Studio)AWS AI ServicesAmazon Qand 3 more
- 02275 MB uploaded to DeepSeek in 30 days from 2 people. Check what data is leaving with Defender's file and session policies.CriticalDeepSeekalsoChatGPTOtter.ai
- 03DeepSeek shows up on the network but holds no Entra consent, so people are using personal accounts or no account at all. Conditional Access cannot see it; block or coach at the gateway with a Defender for Cloud Apps unsanction policy.CriticalDeepSeekalsoClaudeChatsonic
- 04The root user of account 123456789012 called Amazon Bedrock APIs. Root should never do day-to-day work: move this to an IAM role, enable MFA on root, and alert on any further root activity.CriticalAmazon Bedrock
- 05Bedrock model invocation logging is off in account 123456789012, so prompts and completions leave no record. Turn it on (CloudWatch Logs or S3) before this becomes the default way people reach models.CriticalAmazon Bedrock
- 06ChatGPT has tenant-wide admin consent. Confirm a documented approval exists, or revoke the grant and require per-user consent.CriticalChatGPT
- 07Scopes expose directory, email, files. Evaluate the vendor's retention and training terms before allowing continued use.CriticalChatGPT
- 08Otter.ai holds application permissions and can read data with no user signed in. Review the app role assignments and remove any that are not essential.CriticalOtter.ai
Ledger
- Critical6
- High18
- Medium58
- Low3
- Info0
Evidence by source
| Lane | Apps | Crit | High |
|---|---|---|---|
| Entra consent | 3 | 2 | 0 |
| Network | 5 | 1 | 1 |
| Endpoint | 9 | 0 | 0 |
| Audit log | 5 | 0 | 1 |
| 5 | 0 | 3 | |
| Azure & Power Platform | 12 | 0 | 2 |
| Purview DLP | 5 | 0 | 3 |
| SIEM | 5 | 0 | 2 |
| Source code | 14 | 2 | 0 |
| Identity | 12 | 0 | 2 |
| AWS | 4 | 1 | 0 |
| Google Cloud | 6 | 0 | 4 |
Kinds of AI in use
- Assistant31
- Cloud AI platform17
- Meeting notes9
- Coding5
- Search5
- Agent platform4
- Local runtime3
- Writing3
- Model hub3
- Unclassified2
- Embedded feature2
- Image & video1
Top findings
| Severity | App | Source | Evidence | People | First action |
|---|---|---|---|---|---|
| Critical90 | Amazon Bedrock Amazon Web Services · Cloud AI platform | AWS | 47 CloudTrail events by 6 identities, 4 denied, 3 resources in account 123456789012 | 6 | The root user of account 123456789012 called Amazon Bedrock APIs. Root should never do day-to-day work: move this to an IAM role, enable MFA on root, and alert on any further root activity. |
| Critical85 | ChatGPT OpenAI · Assistant | Entra consent | tenant-wide consent, 26 sign-ins | 4 | ChatGPT has tenant-wide admin consent. Confirm a documented approval exists, or revoke the grant and require per-user consent. |
| Critical85 | Otter.ai Otter.ai (AISense) · Meeting notes | Entra consent | 3 consenting users, 16 sign-ins | 3 | Otter.ai holds application permissions and can read data with no user signed in. Review the app role assignments and remove any that are not essential. |
| Critical81 | ChatGPT OpenAI · Assistant | Source code | 4 repos, 3 packages, 2 keys | 0 | 2 keys for ChatGPT are in source control, including a public repository. Rotate them now, move to a secret manager, and turn on push protection so it cannot happen again. |
| Critical76 | Gemini Google · Assistant | Source code | 1 repo, 1 packages, 1 keys | 0 | 1 key for Gemini is in source control, including a public repository. Rotate them now, move to a secret manager, and turn on push protection so it cannot happen again. |
| Critical75 | DeepSeek DeepSeek · Assistant | Network | 2 users, 275 MB up | 2 | 275 MB uploaded to DeepSeek in 30 days from 2 people. Check what data is leaving with Defender's file and session policies. |
| High70 | ChatGPT: sensitive data OpenAI · Assistant | Purview DLP | 5 DLP events, 4 not blocked | 3 | ChatGPT trains on data unless a business tier or opt-out is used. Verify which tier these users are on. |
| High70 | DeepSeek: sensitive data DeepSeek · Assistant | Purview DLP | 2 DLP events, 2 not blocked | 2 | DeepSeek trains on customer data. Block the app or move users to a business tier that excludes training. |
| High67 | Vertex AI Google · Cloud AI platform | Google Cloud | 55 audit entries by 7 principals, 5 denied, 4 resources in 6 projects | 7 | 5 calls were denied by IAM. People are trying to reach Vertex AI; grant it through a reviewed role or add an organization policy restricting the service so the attempts stop. |
| High66 | ChatGPT OpenAI · Assistant | SIEM · Splunk (demo) | 21007 events, 505 MB up via Splunk (demo) | 3 | ChatGPT trains on data unless a business tier or opt-out is used. Verify which tier these users are on. |
AI inventory register
| Sev | App | Source | Evidence | People | Last seen |
|---|---|---|---|---|---|
| critical 90 | Amazon Bedrock | AWS | 47 CloudTrail events by 6 identities, 4 denied, 3 resources in account 123456789012 | 6 | Sep 13, 2026 |
| critical 85 | ChatGPT | Entra consent | tenant-wide consent, 26 sign-ins | 4 | Sep 11, 2026 |
| critical 85 | Otter.ai | Entra consent | 3 consenting users, 16 sign-ins | 3 | Sep 12, 2026 |
| critical 81 | ChatGPT | Source code | 4 repos, 3 packages, 2 keys | 0 | Sep 13, 2026 |
| critical 76 | Gemini | Source code | 1 repo, 1 packages, 1 keys | 0 | Sep 2, 2026 |
| critical 75 | DeepSeek | Network | 2 users, 275 MB up | 2 | Sep 12, 2026 |
| high 70 | ChatGPT: sensitive data | Purview DLP | 5 DLP events, 4 not blocked | 3 | Sep 11, 2026 |
| high 70 | DeepSeek: sensitive data | Purview DLP | 2 DLP events, 2 not blocked | 2 | Sep 10, 2026 |
| high 67 | Vertex AI | Google Cloud | 55 audit entries by 7 principals, 5 denied, 4 resources in 6 projects | 7 | Sep 13, 2026 |
| high 66 | ChatGPT | Splunk (demo) | 21007 events, 505 MB up via Splunk (demo) | 3 | Sep 14, 2026 |
| high 62 | DeepSeek | Splunk (demo) | 220 events, 140 MB up via Splunk (demo) | 1 | Sep 12, 2026 |
| high 60 | ChatGPT via Power Platform | Azure & Power Platform | 3 connections in 1 env | 3 | Sep 9, 2026 |
| high 60 | Microsoft 365 Copilot: sensitive data | Purview DLP | 2 DLP events, 1 not blocked | 2 | Sep 11, 2026 |
| high 58 | ChatGPT | 3 signups, 2 billing emails | 4 | Sep 13, 2026 | |
| high 55 | Azure OpenAI: dave-openai-test | Azure & Power Platform | accounts in rg-sandbox-dave, public | 0 | n/a |
| high 55 | Midjourney | 1 signups, 1 billing emails | 1 | Sep 6, 2026 | |
| high 55 | Otter.ai | Identity | 0 sign-ins, 3 OAuth grants via Google Workspace (demo) | 3 | Aug 25, 2026 |
| high 55 | Read AI | Identity | 0 sign-ins, 2 OAuth grants via Google Workspace (demo) | 2 | Sep 2, 2026 |
| high 53 | Gemini API (AI Studio) | Google Cloud | 38 audit entries by 2 principals in 2 projects | 1 | Sep 13, 2026 |
| high 52 | Vertex AI Search and Agent Builder | Google Cloud | 32 audit entries by 2 principals, 2 resources in 1 project | 2 | Sep 13, 2026 |
| high 51 | ChatGPT | Network | 11 users, 50 MB up | 11 | Sep 14, 2026 |
| high 51 | Dialogflow | Google Cloud | 6 audit entries by 1 principal, 1 resources in 1 project | 1 | Sep 12, 2026 |
| high 50 | Microsoft 365 Copilot | Audit log | 70 audit events | 12 | Sep 14, 2026 |
| high 50 | Otter.ai | 1 signups, 1 billing emails | 1 | Aug 18, 2026 | |
| medium 49 | Amazon SageMaker | AWS | 13 CloudTrail events by 3 identities, 2 resources in account 123456789012 | 3 | Sep 13, 2026 |
| medium 48 | AWS AI Services | AWS | 35 CloudTrail events by 2 identities in account 123456789012 | 2 | Sep 13, 2026 |
| medium 48 | Amazon Q | AWS | 30 CloudTrail events by 5 identities, 1 resources in account 123456789012 | 5 | Sep 13, 2026 |
| medium 48 | ChatGPT | Endpoint | 2 devices, 2 accounts | 2 | Sep 13, 2026 |
| medium 48 | Cursor | Endpoint | 2 devices, 2 accounts | 2 | Sep 13, 2026 |
| medium 48 | Local model files | Endpoint | 2 devices, 2 accounts | 2 | Sep 13, 2026 |
| medium 48 | Ollama | Endpoint | 2 devices, 2 accounts | 2 | Sep 13, 2026 |
| medium 48 | Otter.ai | Network | 4 users, 90 MB up | 4 | Sep 14, 2026 |
| medium 45 | Contoso HR Assistant | Audit log | 18 audit events | 7 | Sep 14, 2026 |
| medium 45 | Gemini | Splunk (demo) | 560 events, 7 MB up via Splunk (demo) | 2 | Sep 14, 2026 |
| medium 45 | Grammarly | Endpoint | 3 devices, 0 accounts | 0 | n/a |
| medium 45 | Grammarly | Identity | 0 sign-ins, 1 OAuth grants via Google Workspace (demo) | 1 | Aug 12, 2026 |
| medium 45 | MeetingMind Notetaker | Entra consent | 1 consenting user, 3 sign-ins | 1 | Aug 30, 2026 |
| medium 45 | Perplexity: sensitive data | Purview DLP | 1 DLP events, 1 not blocked | 1 | Sep 13, 2026 |
| medium 45 | Zoom AI Companion | Identity | 0 sign-ins, 1 OAuth grants via Google Workspace (demo) | 1 | Sep 6, 2026 |
| medium 43 | Claude | 2 signups, 0 billing emails | 1 | Sep 7, 2026 | |
| medium 42 | Azure Machine Learning: aml-research | Azure & Power Platform | workspaces in rg-datasci, public | 0 | n/a |
| medium 42 | Read AI | Audit log | 3 audit events | 2 | Sep 5, 2026 |
| medium 41 | Claude | Source code | 2 repos, 1 packages | 0 | Sep 12, 2026 |
| medium 40 | Claude | Splunk (demo) | 320 events, 7 MB up via Splunk (demo) | 1 | Sep 13, 2026 |
| medium 40 | DeepSeek | Endpoint | 2 devices, 2 accounts | 2 | Sep 12, 2026 |
| medium 40 | Gemini AI (custom) | Azure & Power Platform | 1 connections in 1 env | 1 | Sep 2, 2026 |
| medium 40 | Perplexity | 2 signups, 0 billing emails | 1 | Aug 31, 2026 | |
| medium 40 | Perplexity | Endpoint | 1 devices, 0 accounts | 0 | n/a |
| medium 39 | Gemini for Google Cloud | Google Cloud | 30 audit entries by 3 principals in 1 project | 3 | Sep 13, 2026 |
| medium 39 | GitHub Copilot | Source code | 2 repos | 0 | Sep 13, 2026 |
| medium 39 | Google Cloud AI APIs | Google Cloud | 30 audit entries by 2 principals, 1 resources in 2 projects | 2 | Sep 13, 2026 |
| medium 38 | ChatGPT | Identity | 10 assigned, 60 sign-ins via Okta (demo) | 10 | Sep 14, 2026 |
| medium 38 | Claude | Network | 3 users, 6 MB up | 3 | Sep 13, 2026 |
| medium 38 | LM Studio | Endpoint | 1 devices, 1 accounts | 1 | Sep 11, 2026 |
| medium 37 | Azure AI Services: ais-multiservice | Azure & Power Platform | accounts in rg-ai-prod, public | 1 | n/a |
| medium 37 | Azure Bot Service: contoso-helpdesk-bot | Azure & Power Platform | botservices in rg-bots, public | 1 | n/a |
| medium 37 | Otter.ai | Audit log | 2 audit events | 1 | Aug 24, 2026 |
| medium 34 | Claude Code | Source code | 1 repo | 0 | Sep 11, 2026 |
| medium 33 | Glean | Identity | 12 assigned, 90 sign-ins via Okta (demo) | 12 | Sep 14, 2026 |
| medium 32 | Local models | Source code | 2 repos | 0 | Sep 11, 2026 |
| medium 31 | Cursor | Source code | 1 repo | 0 | Sep 13, 2026 |
| medium 31 | Hugging Face | Splunk (demo) | 60 events, 1 MB up via Splunk (demo) | 1 | Sep 8, 2026 |
| medium 31 | Hugging Face | Source code | 2 repos, 3 packages | 0 | Sep 11, 2026 |
| medium 31 | LangChain | Source code | 1 repo, 1 packages | 0 | Sep 11, 2026 |
| medium 31 | LiteLLM | Source code | 1 repo, 1 packages | 0 | Sep 11, 2026 |
| medium 31 | Microsoft | Source code | 1 repo, 1 packages | 0 | Sep 8, 2026 |
| medium 31 | Vercel | Source code | 1 repo, 2 packages | 0 | Sep 13, 2026 |
| medium 30 | Azure AI Foundry: proj-support-agent | Azure & Power Platform | workspaces in rg-ai-prod | 0 | n/a |
| medium 30 | Azure OpenAI via Power Platform | Azure & Power Platform | 3 connections in 2 envs | 3 | Aug 30, 2026 |
| medium 30 | Azure OpenAI: aoai-prod-eastus | Azure & Power Platform | accounts in rg-ai-prod | 1 | n/a |
| medium 30 | ChatGPT | Identity | 0 sign-ins, 5 OAuth grants via Google Workspace (demo) | 5 | Aug 16, 2026 |
| medium 30 | MeetingMind Notetaker | Audit log | 1 audit events | 1 | Sep 8, 2026 |
| medium 29 | Gemini for Workspace | Identity | 0 sign-ins via Google Workspace (demo) | 8 | Sep 14, 2026 |
| medium 29 | Otter.ai | Identity | 4 assigned, 14 sign-ins via Okta (demo) | 4 | Sep 14, 2026 |
| medium 29 | Perplexity | Identity | 22 sign-ins via Google Workspace (demo) | 5 | Sep 11, 2026 |
| medium 28 | Chatsonic | Network | 1 users, 1 MB up | 1 | Sep 5, 2026 |
| medium 26 | Aider | Source code | 1 repo | 0 | Sep 2, 2026 |
| medium 26 | Azure OpenAI | Source code | 1 repo, 1 packages | 0 | Sep 8, 2026 |
| medium 25 | AI Builder via Power Platform | Azure & Power Platform | 1 connections in 1 env | 1 | Jun 16, 2026 |
| medium 25 | Azure AI Foundry: hub-contoso-ai | Azure & Power Platform | workspaces in rg-ai-prod | 1 | n/a |
| medium 25 | Azure AI Services via Power Platform | Azure & Power Platform | 1 connections in 1 env | 1 | Aug 15, 2026 |
| medium 25 | Claude: sensitive data | Purview DLP | 2 DLP events, 0 not blocked | 1 | Sep 6, 2026 |
| low 20 | Hugging Face | Endpoint | 1 devices, 1 accounts | 1 | Sep 8, 2026 |
| low 20 | Jasper | Identity | 2 assigned, 0 sign-ins via Okta (demo) | 2 | n/a |
| low 8 | MeetingMind AI Notetaker | Identity | 1 assigned, 0 sign-ins via Okta (demo) | 1 | n/a |
Where this came from
| Source | Kind | Status | Synced |
|---|---|---|---|
| Contoso all sources available | Microsoft 365 tenant | active | 2 h ago |
| Splunk (demo) | SIEM (fixture) | active | 2 h ago |
| GitHub (demo) | Source code (fixture) | active | 2 h ago |
| Okta (demo) | Identity (okta) | active | 1 h ago |
| Google Workspace (demo) | Identity (google) | active | 1 h ago |
| AWS (demo) | AWS account (123456789012) | active | 42 min ago |
| Google Cloud (demo) | Google Cloud (organizations/123456789012) | active | 42 min ago |
How to read this
Each finding is one AI application as seen by one evidence source. The same product can appear more than once when several sources see it; those findings link to each other and corroborate the risk.
Risk scores combine how confidently the app was identified, what it can reach, how many people use it, how it was approved, the vendor's training and retention terms, and, where Purview data exists, whether sensitive data reached it and whether policy stopped it. Sanctioned apps are discounted but still listed.
Recommendations are generated per finding from the evidence and rolled up above by action. Nothing in this report modifies the tenant; every source is read-only.