Checklist | The AI Exposure Ten
How exposed is your organization to AI-related data risks? This practical 10-question checklist helps you assess AI usage, AI agent activity, and sensitive data exposure so you can uncover gaps and take action before they become threats.

Know Your AI · PART 1 · QUESTIONS 01-05 Score: 1 point per Yes, consistently
Yes, consistently Partly Not yet
01 Can you identify which AI tools and MCP servers
employees and developers are using?
02 Can you tell company AI accounts from personal ones,
even in the same tool?
03 Can you see AI use across browser, desktop, SaaS, and
developer environments?
04 Can you identify who uses each AI tool and MCP server,
and which team owns it?
05 Can you see every AI agent in your environment and track
its token usage?
Govern with Confidence · PART 2 · QUESTIONS 06-10 Score: 1 point per Yes, consistently
Yes, consistently Partly Not yet
06 Can policy vary by user, group, application, model,
destination, and data type?
07 Can you inspect sensitive text, source code, files, and
retrieved content before exposure?
08 Can you warn, block, or redact sensitive content without
shutting down approved AI use?
09 Are AI interactions and policy decisions logged for audit
and investigation?
10 Can you control which data, tools, and actions each AI
agent is allowed to use?
Know Your AI Yes answers / 5 Govern with Confidence Yes answers / 5
Count your Yes, consistently answers per part. Partly and Not yet count as zero. A control that works sometimes is a gap.
4–5 You can answer for your AI usage. Book a session to benchmark against enterprises governing AI use at scale.
2–3 Visibility is uneven. AI is being used in ways you can only partly account for, and these gaps widen as adoption grows.
0–1 You can't currently answer for where AI runs or where sensitive data goes. This is where a session helps most.
A I S E C U R I T Y C H E C K L I S T S E R I E S
The AI Exposure Ten Ten questions every organization should be able to answer about AI use, AI agents, and sensitive data. Mark one
answer per question, reflecting how consistently it works today.
Bring your two scores to a session
Exposure and governance gaps call for different fixes.
Talk to an AI security expert
Scan or tap to learn more
checkpoint.com/ai-security/
https://www.checkpoint.com/ai-security/ https://www.checkpoint.com/ai-security/
ai_exposure: question_01: Off question_02: Off question_03: Off question_04: Off question_05: Off question_06: Off question_07: Off question_08: Off question_09: Off question_10: Off score: know_your_ai: govern_with_confidence: