Skip to main content

Shadow AI Exposure Assessment for Energy

Find the unsanctioned AI already in use, classify what it exposes, and get a defensible 60-day remediation plan. Three-week diagnostic, from $2,500.

Shadow AI Exposure Assessment for Energy — ModalPoint



95%
of EHS+ teams use unapproved AI
CORITY INSIGHTS ’25 →

/ Tier 0 · Shadow AI Exposure Assessment

Find the AI your team is using that you didn’t authorize.

A 3-week diagnostic that surfaces unsanctioned AI usage across your organization, classifies the exposure, and produces a defensible 60-day remediation plan. $2,500.

Built for operators in regulated industries
Tamboran Resources
Goldman 10KSB
OTC 2026
Texas AI Council
NIST AI CoI

Most operators we talk to assume they have an AI policy in place. They’ve issued the memo. They’ve stood up the sanctioned tool. They’ve mandated training.

Then we run the assessment. And we find:

  • A senior engineer pasting AFE economics into ChatGPT on a personal account because the sanctioned tool times out on documents over 50 pages.
  • A finance team running deal-memo summarization through Claude on the side because the corporate Copilot license doesn’t include the model they need.
  • A field operations lead routing inspection photos through a third-party vision API for analysis — outside any logged workflow, on a personal Stripe-funded developer account.
  • An entire procurement function quietly using Cursor to draft contract language with vendor PII embedded in the prompts.

This is not a security failure. It’s a signal that the sanctioned tool isn’t good enough, and the people whose work matters route around it. You don’t have a governance problem. You have a tool-quality problem creating a governance problem.

That’s what the Shadow AI Exposure Assessment surfaces, classifies, and gives you a defensible plan to fix.

→ Schedule a 30-minute discovery call


What We Look For

The assessment hunts for unsanctioned AI usage across six categories where exposure tends to concentrate:

  1. Browser-based generative AI on personal accounts. ChatGPT, Claude, Gemini, Perplexity — running through chat.openai.com and claude.ai on accounts the IT team didn’t issue.
  2. AI-augmented developer tooling. Cursor, Windsurf, GitHub Copilot configurations, Anthropic Claude Code, and AI-extended IDEs in dev workflows that weren’t approved at the function level.
  3. AI-in-Slack-or-Teams. Glean, ChatGPT-in-Slack, custom GPT integrations posted to channels, AI summarization plugins that received contract-level data.
  4. Spreadsheet and document agents. Excel =GPT() integrations, Google Docs Smart Compose with custom training, formula-resolving AI add-ons, AI-PDF analysis tools running on regulated documents.
  5. Field workflow API usage. Vision-recognition APIs analyzing physical assets, transcription services in inspection workflows, mobile AI tools used by field engineers and offline ops staff.
  6. Marketing and external-communications AI. Content tools, AI-image generators, brand-language assistants — running on assets that go to public regulators, investors, and customers.

For each category, we identify:
Who is using it (role, function, level of seniority)
What data class is being processed (employee, customer, contractual, regulated, classified, public)
Why they routed around the sanctioned tool (capability gap, access friction, training gap, deliberate workaround)
What downstream artifact the AI output ended up in (a memo? a regulator filing? a PR pitch? a customer email?)


What You Get

After three weeks, you receive a single binder containing:

1. Shadow AI Inventory

Every unsanctioned AI tool we identified, mapped to the user, function, and data class. Sorted by exposure severity.

2. Sanctioned-Tool Gap Analysis

For each shadow AI use case, the specific reason the sanctioned tool didn’t satisfy the user’s need. This is the part most clients didn’t realize they were missing.

3. Risk Classification Matrix

Each finding rated against four lenses: regulatory exposure (TRAIGA, EU AI Act, NIST AI RMF Critical Infrastructure Profile), data-protection exposure (GDPR, CCPA, contractual NDAs), reputational exposure (where outputs ended up that you’d rather not defend), and operational exposure (workflow continuity if the shadow tool is shut down).

4. 60-Day Remediation Roadmap

Specific, sequenced actions: which shadow uses to sanction, which to replace, which to ban, and what’s needed to upgrade the sanctioned-tool tier to close the capability gap that drove the workaround.

5. Discovery-Call-Ready Documentation

A separate executive brief sized for board and audit-committee distribution. Defensible language. No surprises.


What This Is Not

  • Not a security audit. We don’t pen-test the sanctioned tools. We don’t crawl the firewall logs. SOC2 auditors do that.
  • Not a tool ban. The fastest way to push shadow AI deeper underground is to issue a memo telling the team to stop. The assessment surfaces why people routed around the policy — so the next policy works.
  • Not a $50,000 big-bang governance project. That’s the Texas Ready or Cross-Border Binder — for organizations that already know their exposure. The Shadow AI Exposure Assessment is for the operators who don’t yet know.
  • Not theoretical. The deliverable lists specific tools, specific users, specific data classes. The remediation roadmap is sequenced and testable. Every finding has a citation.

Pricing & Scope

$2,500 flat fee. Three weeks. Five to ten stakeholder interviews (1:1, confidential, off the record). Documentation review. Sanctioned-tool capability inventory. Final binder + executive brief delivered as a single PDF + a 90-minute walkthrough.

If the assessment surfaces issues that warrant the full Texas Ready or Cross-Border Binder programs, the $2,500 is credited toward that engagement.


Who Should Run This

The Shadow AI Exposure Assessment is built for the operator who knows AI is happening informally inside their organization but doesn’t yet know how to map the exposure. Most often, this is:

  • A COO or VP Operations at a $50M–$300M energy operator, industrial firm, or PE-backed portfolio company who suspects unsanctioned AI usage but doesn’t have a credible inventory yet
  • A General Counsel or Chief Compliance Officer facing TRAIGA September 1, 2026 enforcement (or EU AI Act August 2, 2026 high-risk obligations) who needs to know what’s actually happening before policy goes into effect
  • A PE Operating Partner or MD running portfolio-company AI risk diligence — at the GP or portfolio level — who needs a short, repeatable assessment to deploy across the portfolio

Two things have to be true for the assessment to be a fit:

  1. You have 5–10 senior individuals across operations, finance, IT, marketing, and engineering whose work involves making decisions or producing artifacts that have regulatory, contractual, or reputational consequences. (Below 5 stakeholders, the assessment is a phone call. Above 100, it’s a different program.)
  2. You’re willing to let those individuals talk to ModalPoint off the record, with no IT-team supervision, with explicit safe-harbor for what they admit to using. Without that condition, the assessment surfaces nothing useful.

How It Connects to the Rest of the ModalPoint Practice

The Shadow AI Exposure Assessment is the entry tier of a four-tier engagement ladder, all built on the Digital Information Governance® framework:

Tier Engagement Investment Outcome
Tier 0 Shadow AI Exposure Assessment $2,500 / 3 weeks Inventory + gap analysis + 60-day roadmap
Tier 1 Texas Ready 4–6 weeks NIST AI RMF mapping, AI inventory, TRAIGA cure playbook
Tier 2 Cross-Border Governance Binder 8–12 weeks All nine DIG artifacts: TRAIGA + EU AI Act + NIST + ISO 42001
Tier 3 Governance-as-a-Service Monthly retainer Drift monitoring, regulatory watch, incident response standby

The Shadow AI Exposure Assessment is designed to be a complete-and-shippable deliverable on its own. Most operators run it, take the binder, and act on the roadmap themselves. About one in three return to commission the deeper Tier 1 or Tier 2 work after the initial assessment surfaces exposure that warrants the full binder.


Schedule a Discovery Call

A 30-minute discovery call to confirm fit, scope the stakeholder list, and answer questions about the methodology. No prep needed. No commitment. Held under NDA on request.

→ Request a discovery call

Or if you’d rather see the broader practice first:


Based in Houston, Texas. ModalPoint is the AI Decision Governance practice for regulated industries — built on 26 years of energy commercialization advisory through EWR Digital. Matthew Bertram is President of ModalPoint, CEO of EWR Digital, member of NIST’s Cyber AI Profile and Zero Trust Communities of Interest, Goldman Sachs 10,000 Small Businesses graduate (April 2026), and moderator of the Ericsson AI panel at Offshore Technology Conference 2026 (May 4).

/05 Begin

Find what’s already running inside your organization.

3 weeks · $2,500 · 60-day roadmap
Schedule a Discovery Call →

/ Who you're engaging with

A Houston-based AI decision governance practice. Built by operators, sharpened on regulated AI.

/ Practice

  • Houston, TX
  • Operating in US + EU
  • Response within one business day
  • Practice owner: EWR Digital

/ Credentials & affiliations

DIGUSPTO Reg. No. 8147558
NISTCyber AI · Zero Trust CoI
TexasHB 149 / TRAIGA active
Goldman10KSB graduate, Apr 2026
TAMUCorps of Cadets alumnus
IAPPAIGP candidate, Q3 2026
OTC 26Moderator, Ericsson AI panel

Frequently asked questions

How is this different from a security audit?+
A security audit pen-tests sanctioned tools and reviews firewall logs. The Shadow AI Exposure Assessment surfaces AI usage that isn't going through sanctioned tools at all — running on personal accounts, browser sessions, dev IDEs, and informal workflows. Different problem; complementary.
Is the $2,500 credited toward the larger Tier 1 or Tier 2 engagements?+
Yes. If the assessment surfaces issues that warrant Texas Ready ($35,000) or the Cross-Border Governance Binder ($75,000), the $2,500 is credited toward that engagement.
Will my team's admissions be confidential?+
Yes. Stakeholder interviews are 1:1, off the record, and conducted under explicit safe-harbor — what they admit to using stays out of any document IT or HR will see. The deliverable describes patterns and exposures, not individuals. This is a non-negotiable methodology requirement; without it, the assessment surfaces nothing useful.
How long does the assessment take?+
Three weeks: Week 1 — kickoff + stakeholder interviews. Week 2 — documentation review + sanctioned-tool capability inventory. Week 3 — final binder + executive brief + 90-minute walkthrough.
Does ModalPoint sell the AI tools we should use?+
No. ModalPoint is vendor-neutral and tool-independent. We don't resell, white-label, or earn commission on any AI tool. The assessment recommends remediation paths; the client chooses the tools.
Book a call

Talk to ModalPoint

A 30-minute call to see if ModalPoint is the right firm and whether the timing makes sense. No obligation either way.