Free AI Governance Resources
Everything on this page is free and ungated: how to turn a list of detected AI tools into an inventory you can act on, an AI use policy you can take to a leadership meeting, and the free QuickScan. Nothing about your scan was sent here — the link from the Shadow AI Scan Preliminary Report carries only a generic source tag, never a service name, count, date, or identifier.
You Have a List. Here Is What to Do With It.
A detection means a web address appeared in a browser’s history. Turning that into something you can act on takes one conversation per service — usually a short one.
Ask Openly, Not Forensically
“I saw this tool come up — what do you use it for?” gets you an accurate inventory. Anything that sounds like an investigation gets you silence, and the tools move somewhere you cannot see them.
Record Teams, Not Names
Note the business purpose and which function relies on the tool. Naming individuals turns an inventory exercise into a performance conversation, and people stop telling you things.
Write Down What You Cannot Confirm
An honest gap list is more useful than a confident guess — and it is exactly what a customer questionnaire or a board member will ask about next.
The Evidence Model, Briefly
The report labels every fact with how firmly it is established, so you can tell what the scan actually showed from what someone still has to check. There are four labels:
- Detected
- A web address matching a reviewed rule appeared in the history available to the Chrome profile. This is the only thing the scan establishes on its own.
- Capability
- A dated source from the service's own documentation says the service offers a particular capability. It does not mean the capability was used.
- Confirmed
- A person or an authorized administrator verified what actually happened — the account, the data, the settings. The free scan cannot reach this level.
- Unknown
- The scan cannot determine it. Most facts about vendor terms, retention and account type sit here until someone checks.
The scan produces Detected findings and, separately, sourced Capability information. It never converts either into Confirmed — only a person can do that.
Questions Worth Asking
- Was any meeting actually recorded or transcribed, and did everyone on the call know?
- Were any documents uploaded, and if so, what kind of information did they contain?
- Is any detected service connected to your email, calendar, storage or CRM?
- Are accounts personal or organizational, and who set them up?
- What happens to these accounts and connections when someone leaves?
AI Use Policy Starter Template — Discussion Draft
A concise, standalone AI use policy you can download, edit, and take to a leadership meeting. No form, no email address, no sign-up.
What It Covers
Who it applies to, which tools are approved and which are not, and what information must never be entered into any of them. It also covers meeting recording, connections to other systems, accounts when someone leaves, responsibility for output, and what to do when something goes wrong.
How to Use It
Read it with the people who would actually enforce it. Delete what does not apply. The bracketed decisions are the parts that matter — argue about those, then have it approved the way you normally approve policy.
What It Is Not
A starting policy document only. Not customization, not implementation, not legal advice, not a compliance certification, and not organizational approval. Adopting it unchanged would be a mistake.
The Wider Question: AI Governance QuickScan
A browser scan tells you which tools appeared. The QuickScan asks how ready your organization is to govern them — 21 questions across seven pillars, with an instant Readiness Level, a pillar-by-pillar snapshot, your biggest gaps, and a Policy Starter Outline (Discussion Draft) built from your answers.
It takes about ten minutes and needs no sensitive operational data. Results are directional and based on self-reported information — they support discussion and prioritization, not certification or a compliance determination.
Practical Governance Resources
The Shadow AI Scan Itself
A local Chrome extension that checks the browsing history available to a Chrome profile against a reviewed list of AI services. It accesses and processes that history locally for the user-initiated scan. It initiates no background network requests, and does not transmit browsing history or scan results to Priority Governance.
What a Scan Cannot See
Worth knowing before you treat any inventory as complete: 9 categories of activity a browser-history scan is structurally blind to — including embedded AI features, browser extensions, mobile apps, and other devices.
How We Handle Data
What the free tools access locally, what Priority Governance receives (and does not receive), and how the tools minimize sensitive-data handling. This supplements — never replaces — our Privacy Policy and Terms.
Paid Next Steps
Nothing above requires any of this. The free material is complete on its own, and the 30-day plan in your scan report has nothing to buy in it. These exist for organizations that would rather not do the work alone.
AI Governance Starter Kit — $497 — one-time
Editable implementation materials and guidance: a start-here guide, AI inventory workbook, use-case intake, risk-classification matrix, data-boundary and staff-rollout materials, vendor questionnaire, evidence pack, and a 30-day plan template. Not legal or compliance documents.
QuickStart Workshop — $1,500
One live 90-minute facilitated leadership session for up to eight participants: interpret your results, prioritize, assign owners, and leave with a leadership-ready summary. Includes the complete Starter Kit. Practical facilitation — not legal, audit, security, or compliance consulting.
Fractional AI Governance
For organizations that need someone to own this every month rather than once. A bounded operating function: we keep the inventory current, review new tools, track decisions and risks, and brief leadership. Typically starts with a 90-day pilot.
Control Center
Set the rules once, and keep them current as your AI use changes. Once you have an inventory and a policy, Control Center is where they live: which AI tools people may use, what information may go into them, the decisions and exceptions you have approved, and the reviews coming due — with a leadership view of what needs attention. It starts with Guided Activation, included support to establish governance around your organization. Choose a published plan and begin through secure checkout; a sales call is optional.
Paid offers check out through Stripe; anything else opens an email to jason@prioritygovernance.com. Nothing here is legal advice, a security assessment, or a compliance certification.