ZDG AI Exposure Brief

Know what AI agents — yours and your vendors’ — can reach, before scrutiny arrives.

Outside-in evidence, no integration and no cooperation required: your public footprint plus your top ten vendors. What agents can reach, what control evidence exists, and the questions to send each vendor — every finding source-linked and confidence-graded, formatted for board, legal, and risk committee review.

The EU AI Act calendar now runs from August 2026 through August 2028 — and your board isn’t waiting for Brussels. This brief is the board-ready answer.

Fixed scope Fixed fee from $1,500 Evidence-linked findings

Findings your board can read. Questions your vendors must answer.

No open-ended engagement. No questionnaire fatigue. One defined output: reach versus control evidence, per deployment, per vendor — with a copy-paste questionnaire for every gap found.

Eight-section evidence brief

Detected agent signals, reach profiles, control evidence, regulatory relevance, vendor concentration risk, and a board summary — every claim source-linked.

Bounded. Defined. Repeatable.

Fixed fee. Fixed deliverable. Days, not quarters. Built from public evidence — nothing to install, nobody to interview.

ZDG proof surface summary showing decision mix, replay linkage, and governed evidence coverage
Evidence Surface

What the brief examines

  • Your public footprint: site, docs, changelogs, job postings, public repositories
  • Vendor pages: trust centers, subprocessor lists, product documentation, filings
  • What each detected agent deployment can plausibly reach — APIs, records, code, messages, workflows
  • What control evidence exists publicly: credentials scoping, identity, logging, kill-switch, incident commitments
  • Regulatory relevance per finding: EU AI Act, NIST AI RMF, ISO/IEC 42001
  • Concentration risk: shared model providers and frameworks across your vendor portfolio
Brief Output

What the findings deliver

  • Reach-versus-control-evidence findings, graded and source-linked — never verdicts
  • A copy-paste questionnaire for every flagged vendor
  • A defensible answer to "what is our AI exposure?"
  • Findings formatted for board, legal, and risk committee review
  • A baseline: continuous monitoring with delta alerts is available from here
Entry Point

Start with the brief. Move to runtime control.

The brief gives you the map. The platform gives you the infrastructure. The proof story shows you what controlled execution looks like in production.