Senior leaders use unapproved AI at twice the rate of their teams - often bypassing policies they signed off themselves. They want results fast without the paper trail or the bureaucracy. Banning AI tools doesn’t work. Awareness and safe enablement does.
Four surveys across 2025 and 2026 point the same way. TrustedTech and Censuswide (2,001 workers, UK and US), UpGuard, Teramind, BlackFog. Self-reported, large-enterprise samples.
Your team uses more AI than you rolled out: personal accounts, features inside tools you already pay for, AI built in and running in the background.
1 in 3 workers use AI tools nobody approved. Work AI Institute, 6,000 workers across Australia, the US and the UK, 2026.
It’s a governance job, not an engineering one. This isn’t about knowing how AI models work - it’s about knowing what’s in use, what it touches, who owns it, and being able to prove it.
We help you find the AI your team uses, give each use a named owner, turn it into a record anyone can verify, and keep that record true as the tools change.
Quickly and cleanly map your AI usage.
Pick the tool you use, Copilot, ChatGPT, Cursor, and 30-plus more, and the risks, controls, and policies are already mapped. No more wondering about your AI risk or what to do about it.
| AI System | Risk level | Owner | Status |
|---|---|---|---|
| Customer Support ChatbotAIS-001 | High | Sarah Mitchell | Active |
| CV Screening AssistantAIS-002 | High | Tom Jenkins | Active |
| Invoice ProcessingAIS-003 | Medium | Maria Rodriguez | Active |
| Marketing Content GeneratorAIS-005 | Not set | Paul Harrison | Draft |
Delegate the responsibility. Keep the oversight. Know at a glance what AI is in use, what it touches, who’s responsible for it, and have every decision on the record.
Only users in your company are listed. Adding a secondary owner sends them an email and an in-app notification.
Certrak freezes a snapshot of your governance and seals it with a fingerprint. And nobody can quietly change it. Not even you.
Proof of Governance Report
Acme Corp · Report #12 · Generated 25 Jul 2026, 14:30 by Paul Harrison
computing…
| Active systems (3) | Owner | Risk level |
|---|---|---|
| Customer Support Chatbot | Sarah Mitchell | High |
| CV Screening Assistant | Tom Jenkins | High |
| Invoice Processing | Maria Rodriguez | Medium |
Certrak’s library is built and reviewed by people. We take what leading AI governance frameworks agree on, and turn it into a consistent set of governance practices.
You: We use ChatGPT to draft replies to customer emails. What governance do we need?
You: ChatGPT, drafting replies to customer emails.
9f2b41c8e7d3a6b05f1c94e2d8a730bc4e6f19a2c58d0b3e7f4a1c9d26e8b5073Work AI Institute, 6,000 workers across Australia, the US and the UK, 2026. The LLM answers are scripted illustrations, not live output.
Governance doesn’t fail loudly. It fails through gaps, silence and change. Certrak checks your record for all three every night, and turns what it finds into a task for the right person.
Certrak opens a review for every system it touches, and the owner answers one question.
When a vendor changes what a tool can do, Certrak reads the release notes, records the review, and opens a task for every system in your register that uses that tool.
The spreadsheet was true in March. It has no idea what happened in August. Certrak read the note and asked two owners one question each.
Active AI agents in Microsoft 365 grew fifteen-fold in a year. Microsoft Work Trend Index, May 2026.
Give everyone on your team a way to contribute, while gaining the intelligence you need to make informed decisions.
Add the people closest to the output. They get a heads-up when new AI shows up and can flag anything that looks off. No logins, no extra seats.
Your team can tell you, privately, how AI is affecting their work. Anonymously or in confidence, their choice. It becomes part of your Proof.
Owners, observers and the private channel all land in the same record, with a name and a date on every change. Delegate as much as you like. The oversight stays with you.
Your best people keep the tools that make them fast, on terms the business can stand behind. We set it up with you, on your real tools, for a small number of Australian businesses. Founding-customer pricing, locked in. Nothing to pay until it’s set up and useful. A couple of hours of your time, not a project.
A short form. No pitch deck required.
Twenty minutes to check it’s right for you.
On your real tools, with our team.
Proof in hand, and the team a message away.
No. Your risks and controls come from a fixed library we built and maintain by hand, so the same use always gives you the same governance. AI only reads your description to match you to the right items, it never invents your governance. When something is genuinely new, Certrak drafts a starting point and flags it for your approval.
Yes, it’s built for exactly that. Describe what you’re doing in your own words. Certrak maps the risks and controls, suggests owners, and gives you a short list of things to do. No frameworks to read, no jargon to decode.
No tool can guarantee that. Certrak gives you documented, defensible governance: what you run, the risks you’ve considered, the controls in place, and who’s accountable. It’s built on the common themes of recognised frameworks and regulator guidance.
Governance attaches to what the AI does, not your industry. Computer vision in a vet clinic and computer vision on a factory line get the same proven data-analysis governance, and Certrak shows you which pattern it matched and why. If nothing matches, it drafts suggestions for you to review.
Certrak isn’t built around one standard. AI regulation currently is a complex and evolving field. We take what widely recognised AI governance frameworks and regulators agree on, the controls that come up again and again, and turn them into one practical list you work through. Your governance then lines up with what people expect, without you having to choose or read any framework yourself. While mapping AI governance to specific frameworks is on our roadmap to help our users meet legislative and certification requirements, we are currently focussed on the principles of good governance that apply across all frameworks.
Almost certainly, yes. 88% of organisations now use AI in at least one business function (McKinsey, The State of AI). Someone in your business is already responsible for that, named or not. Certrak makes the ownership explicit before something goes wrong, not after, and gives you the tools and direction to safely manage your AI use.
That depends on the size of your team and how much AI you use, but you can get started in minutes. Pick a tool you use and Certrak loads a pre-built governance stack instantly, or describe a use case in a sentence and it builds one. From there you work through a short, prioritised list at your own pace.
No. You can run it solo. When you want to share the load, assign owners, let your team flag the AI they’re using, and delegate tasks, all against one shared, current picture.
They already do: 41% of workers deliver AI-generated work they can’t explain, and 53% of AI users worry that relying on it makes them look replaceable (Work AI Institute 2026; Microsoft Work Trend Index). Bans and monitoring make the hiding worse. Certrak takes the opposite approach: nothing is scanned or watched, and your team gets a simple, safe way to flag the tools they actually use.
A dated snapshot of your governance: what you had in place, and when. It’s sealed with a digital fingerprint, so any later change shows up. Share it by link and a client, board member or regulator can check that fingerprint in their own browser, nothing gets uploaded. Links stay live for as long as you set, up to 90 days.
The pace is real: active AI agents in the Microsoft 365 ecosystem grew fifteen-fold in the past year (Microsoft Work Trend Index, 2026). Forward a vendor’s release-notes email to your Certrak address and it becomes an owned review task against every system using that model. Controls falling due, expiring evidence and stale systems are detected automatically, so your governance stays current instead of going stale.
No. Anthropic doesn’t train its models on data sent through its commercial API, and Certrak never uses your governance data to train AI or sells it to anyone.
In Australia. You can export your entire account or delete it whenever you choose. The one thing that leaves is what goes to the AI step: the free text you enter, plus system and control names and descriptions, sent to Anthropic in the United States. Anthropic does not use commercial API data to train its models.
No. AI does one job: reading the free text you type so Certrak can map it to the right governance, and occasionally drafting suggestions you approve. The decisions come from fixed rules you can see and trace, not a black box.
Apply, take a short fit call, and we set it up with you.