TrustLayer
Book a demo
Customers/Add AI Exposure
Already a TrustLayer customer

You already have the visibility.
Now use it.

If you run Web Security and CASB, AI Exposure is already reporting.

Nothing to enable, install or reconfigure. Ask for your report, then decide what to allow, block or track.

Or ask BT, your MSP or reseller. Web Security only? You need to add CASB. Details below.
AI Exposure report
Your organisation
PDF
AI tools
27
Users
214
Unapproved tools
24
ToolUsersTop action
ChatGPT98Sent a message
Microsoft Copilot142Upload
Browser AI extension19Sign in
Illustrative. Your report comes from your own logs.
What you're adding

What is AI Exposure?

AI Exposure is the part of TrustLayer Browse that governs AI tool use. It finds the generative AI tools your staff use in the browser on company devices, sanctioned or not, marks each one approved or unapproved, risk-scores the actions inside it, and applies a policy of allow, block or track by action, user or group.

It is not a separate module. The existing Web Security and CASB modules already identify when people use AI tools, through what's already on your devices. No proxy, nothing new in the traffic path. It draws on a catalogue of 2,000+ cloud apps and 8,000+ risk-rated actions, with the AI tools flagged.

Supported AI activity is logged by user, device, application, action, risk level and outcome. When the insurer, the auditor or the board asks how you govern AI, you export the report.

Getting the report

Three steps. No project.

Policy recipes in the help centre →
Step 1
Check your modules

Web Security and CASB together give you AI Exposure. Both already? Skip to step 2. Web Security only? Add CASB through BT, your MSP or reseller. Same install, same invoice.

Step 2
Ask for the report

Request your AI Exposure report. It comes from logs you already have: AI tools used across managed browsers, by whom, with a risk score per action.

Step 3
Set the rules

Mark the tools you sanction. Allow those. Block the ones you don't. Track everything else. Per action: open, sign in, send a message, upload, share. We'll help write the first set.

Policy

Three outcomes. Per action, user or group.

Block, allow, or allow and track. The same policy engine you use for web and cloud apps: conditions combine with AND/OR logic across user, group, device, network, location, time and risk level.

OutcomeWhat happensTypical use
AllowThe action goes through. Nothing in the way.Sanctioned tools on a corporate account. The ones you approved and paid for.
TrackThe action goes through and is logged. The person sees nothing.The long tail. See what people use before you decide. Most customers start here.
BlockA block page. The action does not happen.Unsanctioned tools. Uploads of the wrong file type.

Block and warning pages are customisable per policy. A warn rule can explain the risk, point people at your approved tool and let them continue, with the activity logged.

Visibility and privacy

It sees what you tell it to see.

Every action is a switch. Track it, block it, or turn tracking off. If prompt privacy matters in your organisation, set the chat action to not track and you still see the tool, the user and the uploads.

Sees
Which AI tool was opened
Any generative AI app used in the browser, whether you sanctioned it or someone found it.
Sees
Who, exactly
By user, group and device, so you can see where the activity concentrates and where the risk sits.
Sees
The action, and the file
Open, sign in, send a message, upload, share, download. File type checked before an upload reaches the tool.
Optional
The message itself
Prompts sent to browser AI chat can be logged. If that is more than you want, set the action to not track. Your call, not ours.
Outside
Native desktop and mobile apps
Coverage is browser-based on managed Windows, Mac, iOS and Android. The ChatGPT desktop app or a native phone app is not seen.
What changes for you

Nothing changes.
Except you can see it.

Same console, same agent, same account team. What you gain is the inventory, the risk score and an answer to the question the insurer started asking this year.

Same agent on every device. No redeploy.
Same console. AI tools are already in the app catalogue, flagged.
Same policy engine and AND/OR logic.
Same log stream to your SIEM, if you use one.
No extra line on the invoice if you already have both modules.
Questions

Asked by customers before they ask for the report.

Do I need to install or enable anything?

No. If you run Web Security and CASB, the data is already being collected. Ask us for the report, or sign in and query the logs yourself. If you only have Web Security, add CASB; it uses the agent already on your devices.

Does it read what people type into AI tools?

In the browser, it can. Prompts sent to a web AI chat are logged as an action. If you would rather not record them, set that action to not track: you still see the tool, the user, the account and any uploads. Native desktop and mobile apps are not inspected.

Can it block ChatGPT but allow Copilot?

Yes. Mark Copilot sanctioned and allow it; leave ChatGPT unsanctioned and block or track it. Rules apply per tool, per action and per user or group, so a marketing team can be allowed what finance is not.

Will it slow the laptops down?

No. Policy is enforced by what's already on the device. There is no proxy and nothing new in the traffic path.

Does it coach people or suggest a safer tool?

Yes, if you set it up that way. Block and warning pages are customisable per policy, a warn rule can show your own message, explain the risk, point people at the approved tool and let them continue with the activity logged. A hard block stays a block.

Will it help with Cyber Essentials or the insurance renewal?

Yes. Cyber Essentials' 2026 question set brings AI tools into scope like any cloud service: declared, known to IT. Insurers increasingly ask about AI use directly. AI Exposure gives you a dated record of the tools in use and the policy applied to each, exportable in one report.

Web Security only, or not a customer yet?
AI Exposure comes with Web Security and CASB. Together, that is TrustLayer Browse.

Add CASB to what you have, or start with the whole Browse layer. From the device. Live in 30 minutes.

See Browse →

Say yes to AI.
Safely.

Two minutes to see what you're exposed to. One template to set the rules.

AI risk check
Ten questions. No sales call.
Start
One email a month
On AI and security. No more than that.
Subscribe →