Resources

Practical guides for AI spend, coverage, compliance, and accountability.

Use these starting points to align finance, security, legal, and leadership around a common operating language for employee AI use and policy evidence.

Resources / Start here

Shadow AI discovery, from first signal to owned decision.

What is Shadow AI? Risks, examples, and discovery

Shadow AI is the use of AI tools, accounts, or features outside the organization’s approved inventory or operating process. Discovery starts by separating observable evidence from assumptions.

How to detect AI usage without capturing employee prompts

Security teams can identify supported AI services through managed-browser hostname evidence without turning Shadow AI discovery into employee-content surveillance.

Shadow AI discovery checklist for security teams

A defensible Shadow AI program combines scoped collection, reviewed provider coverage, identity reconciliation, owned triage, and an explicit record of what remains outside the map.

Resources / Shadow AI reference

Inspect the catalog and the evidence behind discovery.

Shadow AI Provider Coverage Index

Browse the production catalog by category and see how candidates, vendor evidence, safety gates, verification dates, and versioned releases work.

Shadow AI Detection Methods Compared

Compare managed-browser, SSO, provider, CASB, network, DLP, gateway, enterprise-browser, and expense signals by what each can and cannot prove.

Resources / All guides

What is Shadow AI? Risks, examples, and discovery

Shadow AI is the use of AI tools, accounts, or features outside the organization’s approved inventory or operating process. Discovery starts by separating observable evidence from assumptions.

  • Treat Shadow AI as an inventory and ownership problem, not only a blocking problem.
  • Cover native AI tools and AI features embedded in existing software.
  • Keep browser, identity, provider, network, and expense evidence distinct.
  • Turn each material finding into an owned decision.

How to detect AI usage without capturing employee prompts

Security teams can identify supported AI services through managed-browser hostname evidence without turning Shadow AI discovery into employee-content surveillance.

  • Record supported AI hostnames and timestamps, not employee content.
  • Do not collect URL paths, query strings, searches, or unrelated browsing history.
  • Use managed identity and sanctioned rosters as separate evidence sources.
  • State clearly what browser discovery can and cannot prove.

Shadow AI discovery checklist for security teams

A defensible Shadow AI program combines scoped collection, reviewed provider coverage, identity reconciliation, owned triage, and an explicit record of what remains outside the map.

  • Define the browser population and privacy boundary.
  • Use a reviewed catalog that covers hundreds of AI providers and keeps expanding.
  • Reconcile sanctioned access without treating account identity as proven when it is not.
  • Assign owners, dispositions, exceptions, and a recurring review cadence.

How to build an AI spend ledger

A company AI spend ledger should reconcile provider bills, expense evidence, directory context, and usage telemetry without hiding how complete each signal is.

  • Start with ChatGPT, Claude, Gemini, Copilot, and paid AI vendors found in expenses.
  • Separate observed, inferred, enforced, and not covered spend.
  • Attach owner, department, vendor, date, amount, confidence, and evidence source to every row.
  • Never treat missing signals as zero spend.

How to explain AI coverage to leadership

Coverage is the difference between what the company can prove, what it can infer, what it can enforce, and what remains outside the map.

  • Observed usage is directly measured.
  • Inferred usage is likely but not directly measured.
  • Enforced usage is governed by an approved control.
  • Not covered usage should be named as a blind spot, not hidden.

How to prepare an AI usage review

A useful AI usage review gives leadership a forwardable snapshot of spend, adoption, risk, and blind spots without pretending the picture is complete.

  • Show total AI spend with signal labels.
  • List shadow AI tools found through card or expense evidence.
  • Name blind spots explicitly.
  • End with three concrete next actions.

What to track for AI hiring compliance

AI hiring review starts with use-case inventory, jurisdiction scope, evidence ownership, and the distinction between Tallin-proved data and customer-attested artifacts.

  • Name the employment decision before naming the AI model.
  • Track jurisdictions explicitly rather than using a freeform policy note.
  • Separate Tallin-proved evidence from customer-attested evidence.
  • Keep missing audits, notices, and sign-offs visible as open gaps.

Consumer chatbot AI disclosure checklist

Consumer chatbot review should connect external AI experiences to disclosure text, escalation paths, owner review, jurisdiction scope, and operational evidence.

  • Track consumer-facing experiences, not only backend model providers.
  • Attach the exact disclosure copy and human-escalation path.
  • Use Tallin evidence for routes, owners, and activity where available.
  • Treat federal and sector obligations as review pointers, not Tallin verdicts.

How gateway privacy modes work

Gateway privacy modes let a customer choose what Tallin stores while keeping the operational ledger useful for spend, attribution, and policy evidence.

  • Metadata-only stores who, what, when, how much, route, and policy outcome.
  • Full audit capture is useful for deeper review but stores more sensitive content.
  • Helper tokens preserve employee attribution for developer tools.
  • Only self-hosted or VPC deployment fully removes Tallin-hosted data-plane visibility.

How to find shadow AI spend

Shadow AI spend usually appears first in card and expense data, long before it appears in an IT inventory.

  • Scan merchant names for AI vendors and assistants.
  • Group findings by department and account email.
  • Mark unrecognized vendors as unclassified.
  • Review recurring subscriptions first.

Tallin vs. AI gateway tools

AI gateway tools govern traffic for AI applications a company builds. Tallin governs employee use of AI tools the company already has.

  • Gateway tools govern AI application traffic.
  • Tallin governs employee use of existing AI tools.
  • Tallin can use gateway events as one signal source.
  • The product outcome is accountable usage, spend, evidence, and blind spots.

Resources / Reference

Coverage glossary

Plain-language definitions of the coverage states and evidence terms Tallin uses, from observed and inferred to auto-proved and open gap. Use them in your own policy and reports.

Documentation

Tallin documentation starts with setup paths for the AI Exposure Assessment, provider connections, expense CSV imports, coverage labels, and Exposure Snapshot exports. Product-specific setup instructions are available inside each customer workspace.

Support

Customers can contact Tallin through their workspace or through the company contact route. Support requests should include the workspace domain, affected page, and whether the issue involves signup, provider connection, CSV import, Snapshot export, or billing.

Every AI provider. One operating system.

Start a 30-day trial with the Tallin services you need or the full Core platform. No credit card is required.

AI Spend Ledger and Coverage Resources | Tallin