AI security · governance · risk for SMBs

Two weeks to underwriter-ready AI governance.

A productized AI security practice for $1–25M businesses navigating cyber insurance AI riders, audit pressure, and customer‑due‑diligence questionnaires.

Built around the standards your underwriter and auditor expect

NIST AI RMFISO/IEC 42001HIPAAEU AI ActSOC 2CCPA
Inside the AI Risk Sprint

Fixed-scope across two weeks. Six deliverables. One executive readout.

The same scope every time. No discovery calls to “figure out what you need.” No hourly billing. No surprise change orders. By Day 14 you have everything in this section, paginated, branded, ready to forward to your underwriter or auditor.

01

AI Tool Discovery

Browser telemetry analysis, employee survey, procurement and SSO log audit. Surfaces every sanctioned and unsanctioned AI tool in active use.

Days 1–4
02

Risk Classification Matrix

Each tool mapped against NIST AI RMF risk severity and business criticality. Identifies which tools need immediate remediation versus policy-only controls.

Days 3–6
03

Cyber Insurance Rider Gap Analysis

Side-by-side of what your carrier's AI security rider requires against what you can document today. Color-coded gaps with remediation priority.

Days 5–9
04

AUP & Training Outline

Acceptable Use Policy drafted to your operational reality, plus a sequenced employee training plan with LMS-ready content modules.

Days 6–10
05

90-Day Remediation Roadmap

Every gap sequenced into a Week 1 / 30 / 60 / 90 plan with owners, dependencies, and expected effort. Hands off cleanly to internal IT or to Implementation.

Days 9–13
06

Executive Readout

Sixty-minute Zoom with leadership, walking through findings, exposure, regulatory citations, and the path to underwriter-ready. Final PDF delivered same day.

Day 14
Three ways to engage

Start with the Sprint. Scale into Implementation. Retain a Fractional officer when you need ongoing coverage.

Front door
AI Risk Sprint
$5,500· 2 weeks · fixed scope

Discovery, classification, gap analysis, AUP, remediation roadmap, executive readout. Designed to satisfy a cyber insurance AI rider questionnaire or vendor security DD on first ask.

Learn about the Sprint
AI Governance Implementation
$15–35K· 6–10 weeks

Closes the gaps the Sprint identifies. DPA repaper, vendor BAA execution, DLP configuration, IR runbook update, control rollout. Sprint fee credits toward Implementation.

Learn about Implementation
Fractional AI Security Officer
$4.5–8.5K· /mo · 6 mo min

Named AI security officer on retainer for businesses without an internal CISO. Carrier liaison, vendor reviews, employee training, quarterly board readout. Activate once governance is in place.

Learn about Fractional
Proof of work

See what an AI Risk Sprint deliverable actually looks like.

22-page sample Sprint report from a 118-employee healthcare practice. Discovery, risk classification, cyber insurance gap analysis, three findings with regulatory citations, 90-day remediation roadmap. Anonymized; representative of an actual engagement.

Download sample report (PDF · 22 pp · 1.1 MB)
Field Report · SAL-2026-014Page 04 of 22
Discovery · count
47
AI tools, sanctioned and unsanctioned, in active use across 118 employees.
04
PHI · no BAA
05
BAA gaps
38
Sanctioned-eligible
Shadow · AI · Labsshadowailabs.com

Preview · page 4 of 22

Who runs the engagement
Peter Kwidzinski
Peter Kwidzinski
Founder, Shadow AI Labs

Twenty years in platform security architecture, with deep work in confidential computing, hardware attestation, and supply-chain trust. AMD Fellow. Contributor to Caliptra, the open-source hardware root-of-trust used across the cloud-and-silicon industry.

Read more on the About page

Frequently Asked Questions

Common questions about Shadow AI and our services.

Don't wait for a breach to act

With 71% of employees using AI without approval and shadow AI breaches costing an extra $670Kon top of an already-painful breach, the question isn't if you have exposure — it's how much.