AI governance

Your people already use AI. You just can't see it.

See every AI service in use. Decide what is allowed. Keep the evidence that you did.

Question 1 of 6

Could you list every AI service your staff used last month?

Free, no sign-up. Nothing you click leaves your browser.

The problem

Nobody approved it.
Everybody is doing it.

AI arrived through the browser, one person at a time, without a procurement process. Most organisations cannot name the services their staff used last month, which makes both the security question and the compliance question unanswerable.

Over half
of organisations have no systematic inventory of the AI systems they operate
€15m or 3%
Maximum penalty for breaching high-risk obligations, whichever is higher
2 Dec 2027
New EU AI Act high-risk deadline, deferred from August 2026. What you need to produce has not changed

Sources: Cloud Security Alliance research note on the deferred high-risk deadline, Regulation (EU) 2024/1689 and the Digital Omnibus on AI, Regulation (EU) 2026/1744.

How it works

One control point. Three outcomes.

No proxy, no rerouting. Traffic goes where it was always going, and policy is applied on the way.

Chat assistants
Code generation tools
Document and image AI
TrustLayer
Policy, by service
and user group
AllowedSanctioned tools, used freely
CoachedA warning at the moment it matters
BlockedUnverified services stopped
Representation
TrustLayer · Browse · Application catalogue
Categories
Cloud storage31
Collaboration18
AI services47
Social24
AI services
Public chat assistant
Code generation
Document summariser
Image generator
Unverified service
Public chat assistant
128 users · First seen 14 days ago · Discovered, not declared
High
Baseline risk
ActionBaselineYour policy
Access the service Low Allowed
Sign in with a personal account Medium Coached
Upload a file High Blocked
Share a conversation link High Blocked
Connect a third-party plugin High Blocked
Use on an unmanaged device Medium Coached
Policy applied · Marketing, Finance and 4 other groups
Straight answers

What it does today

Don't invest in a roadmap, this is what we can do for you right now:

What you get today:

  • Discovers AI services in use across your organisation
  • Allows, coaches or blocks by service and by user group
  • Reports on usage, by team and over time
  • Retains logs as evidence for audit
  • Deploys in minutes, with an endpoint agent
  • Runs with no proxy and no traffic rerouting

We're not the people for you if you need:

  • Security for the AI you build. This governs how your people use external AI services, not the models and applications your own developers create
  • A guarantee of compliance. No company can honestly promise that. We produce the audit evidence, your organisation makes the assessment
Why TrustLayer

AI governance from a company that also secures your email

The AI specialists solve AI and leave you to buy an email vendor separately. TrustLayer covers email, web, cloud and users on one platform, bought through the partner you already work with.

1,500+
Organisations protected globally
700m
Threats blocked every year
16+
Years of experience
Zero
Traffic rerouted through our cloud
Customers

Who we already protect

Healthcare, charity, local government, manufacturing and hospitality. The same platform, the same direct architecture.

NHS Macmillan Cancer Support NSPCC National Portrait Gallery Thatchers Middlesbrough Council Progress Housing Group
Get started

Find out what your people are actually using

Start with the two-minute check. If you want the real numbers rather than an estimate, the AI Health Check runs for two weeks and reports what is genuinely in use.