← TRAINING

// TRAINING QUIZ

Do You Know What's Acting in Your Name?

A ten-question visibility check on agentic AI in your organisation. This is not an audit - ten questions cannot assess your exposure, only whether you could assess it yourself. 'Not sure' scores as 'No' by design: uncertainty about a control is the absence of that control.

10 QUESTIONS DIFFICULTY 1/5 MULTI-ANSWER
// CONTENT & USAGE

Public self-check, pillar 1 lead instrument. Yes = control present. Explanations carry the honest framing; topic recommendations carry the CTA.

01 Visibility

Do you know how many non-human identities - service accounts, bots, agents - currently hold write access to your production data?

If the number is unknown, so is the attack surface. In our assessments, the belief and the measured count are rarely within a factor of two of each other.

02 Visibility

Could you produce, within one hour, a list of AI tools your employees built or adopted this quarter without IT involvement?

AI now enters companies as behaviour, not as projects. The tools your teams built by prompt never crossed an approval gate - which is exactly why no list exists.

03 Identity & Authority

Does every AI agent in your company run under its own identity - or do some share service accounts?

A shared service account is how one compromised agent becomes an incident with no attribution.

04 Identity & Authority

If an agent misbehaved right now, is there a person on call who knows they have the authority to stop it?

Kill authority that nobody knows they hold does not exist. The question is not whether a switch exists - it is whether a named human will pull it at 2 a.m.

05 Control & Recovery

Have you ever actually stopped an AI system in production - deliberately, as a test?

An untested kill path is a hypothesis. Stopping the process is the easy half; the hard half is what its side effects do while it is gone.

06 Control & Recovery

When an agent completes a task, do you have any record of what it did that the agent itself did not write?

The incident record already includes agents confidently narrating work they never performed. Evidence the actor writes about itself is testimony, not evidence.

07 Control & Recovery

If 24 hours of an agent's output turned out to be wrong, could you unwind it?

Reversibility is the control that makes autonomy affordable. Without it, every delegation is a one-way door.

08 Identity & Authority

Has anyone defined which systems an AI agent may never touch - in writing, with an owner?

Zones you have not defined are being defined for you, by whatever credentials the agent happens to hold.

09 Governance Reality

Do your vendor contracts tell you which of your suppliers' products now include agentic components acting on your data?

Your suppliers are adopting agents at the same speed you are. Their autonomy runs on your data - with whatever containment they chose.

10 Governance Reality

Does your AI governance document mention any of the tools your teams actually used this week?

Governance that describes a company which no longer exists is not governance. Enforced governance has a different name: containment.