Resources

Resources.

Everything you need to know about AI compliance, Shadow AI and the DORA register. Clear articles and the official sources, so you can see things clearly.

Articles

AI compliance, Shadow AI, DORA register.

Our expert articles on AI regulation (DORA, AI Act, GDPR) and Shadow AI.

DORA register

DORA register: the complete 2026 guide for fintechs

How to record your AI tools as third-party providers (Art. 28) and prepare the OneGate submission to the ACPR.

Coming soon
Shadow AI

Shadow AI: detecting it in 3 steps

Many companies underestimate the number of AI tools their teams use. The method for taking stock.

Coming soon
Regulation

DORA, AI Act, GDPR: three texts, three different priorities

Who requires what, and when: prioritising without alarmism.

Coming soon
Lawyers

Lawyers & AI: professional secrecy and consumer tools

Professional secrecy, tool confidentiality, data hosting: what every firm should check before using generative AI.

Coming soon
Case study

Mapping your AI in 15 minutes: a case study

An anonymised example of a scan revealing undeclared AI tools in a 200-employee fintech.

Coming soon
DORA register

The DORA register explained to your DPO

A simple guide to understanding the obligation and what is at stake.

Coming soon
Official sources

The texts that count.

Rather than paraphrase, we point you to the sources. Here are the official texts and references we use ourselves.

DORA Regulation (EU 2022/2554)

The full text on EUR-Lex: the source of every obligation, including the register of information (Art. 28).

ACPR — DORA page and FAQ

The French regulator's practical arrangements: register submission via OneGate, incident notification, submission calendar.

CNB guide « La déontologie et l'IA » (ethics and AI)

The ethical framework for lawyers facing generative AI (March 2026), as a PDF on the CNB website (in French).

AI Act — official text and timeline

The European AI regulation and its application timeline, on the European Commission website.

CNIL — AI and data protection

The CNIL's recommendations on the use of AI in light of the GDPR.

FAQ

Frequently asked questions.

General
What is Aleth?
Aleth is a French SaaS that detects the AI tools used in your organisation, including those the IT department does not know about. Each detected tool is classified by risk level and documented: this is the foundation of your compliance registers. Under the AI Act, the inventory of the AI systems your organisation deploys, even unknowingly. Under the GDPR, the access granted to third-party tools and the processing hosted outside the EU. And for regulated financial entities, the elements that feed your DORA register of information (Article 28). Aleth provides indicators and evidence, never a legal verdict on compliance.
Who is behind Aleth?
Aleth is a French start-up specialising in visibility over AI usage and regulatory compliance (DORA, GDPR, AI Act).
Where are you based?
In France. Data is hosted in the European Union.
Your obligations
Which AI Act obligations already apply?
The AI Act already applies, in stages. AI literacy (Article 4) and prohibited practices (Article 5) have been in force since February 2025, transparency obligations (Article 50) since August 2026. Aleth records the AI systems your organisation deploys, classifies them by risk level and tracks your declarative obligations. The obligations applicable to Annex III high-risk systems enter into application on 2 December 2027: the map established today lets you know whether you are concerned.
Which GDPR obligations are at stake?
Every AI tool connected by an employee may be granted access to personal data: files, calendars, contacts. The GDPR requires this processing and any transfers outside the EU to be framed. Aleth flags at-risk tools (hosting outside the EU, Cloud Act exposure, excessive permissions) so that you can address them.
What is the DORA register of information?
It is the register required by Article 28 of DORA: financial entities must record all their third-party ICT providers in it, AI tools included, and submit it to their regulator (via the ACPR's OneGate portal in France). Not to be confused with the FRIA, which falls under the AI Act.
Why does it matter?
An incomplete register is a DORA breach, subject to inspection by the ACPR / AMF, with sanctions from the regulator. Undeclared AI tools create precisely these blind spots.
How does Aleth help?
Aleth scans your AI tools (M365, Google Workspace), records them as third-party providers, classifies them by risk level, and produces evidence exportable to PDF for your ACPR / AMF audits.
Compliance
What does Aleth do, and what remains my responsibility?
Aleth records, classifies and documents your AI tools, feeds your registers and provides evidence for your audits. The legal assessment and the decisions remain yours: Aleth equips your compliance work, it never delivers a verdict.
Features
How does the scan work?
A read-only connection to your environment (M365, Google Workspace); Aleth automatically maps AI usage. Nothing to install.
How often does it scan?
Diagnostic: one-off. Visibilité (Visibility): weekly automatic scans. Conformité (Compliance) and Entreprise: weekly automatic scans, plus unlimited on-demand scans.
Which tools are detected?
The AI tools connected to your Microsoft 365 or Google Workspace environment: writing assistants, note-takers, coding copilots, extensions, tools embedding AI features, including those nobody has declared. A tool that is detected but not yet identified is classified as "undetermined", never ignored.
What is the AI Health Score?
The overall rating of your exposure to AI risk (0–100 gauge with exposure level), calculated from the tools detected, their permissions and their hosting. Each tool is also classified on 5 levels, from Low to Critical. The calculation criteria draw on the AI Act's risk categories (prohibited practices, high risk, transparency, minimal risk) and on the definition of risk set by the regulation itself (Article 3(2)).
Security
Where is my data hosted?
In the European Union. Aleth reads only metadata, never the content of your documents.
Does Aleth access my data?
Aleth connects in read-only mode and reads only metadata: never the content of your documents or e-mails. Nothing is modified.
Can I stop at any time?
Monthly plan: yes, at any time. Annual plan: 12-month commitment, which is what makes the 2 free months possible. The free Diagnostic is a one-off with no commitment whatsoever.
Pricing & support
Why pay for Aleth?
The Diagnostic measures your exposure at a given moment. But one connected tool, one new account, one installed extension, and the picture changes: an inventory established once is out of date within a few weeks. Obligations evolve too.

That is the difference between assessing and tracking. The subscription keeps the inventory up to date and preserves the history of your scans: your scan history and your monthly report document how your exposure evolves. The day an auditor or a regulator asks where you stand, you show today's state, not last year's report.

For regulated financial entities, it is also what keeps your register of information (Article 28) aligned with the reality of your estate.
Which plan should I choose?
The Diagnostic to measure your exposure. Visibilité for the continuous inventory: Aleth space, regular scans, history. Conformité for the complete Aleth space: risk classification (5 levels), foundation of your registers, alerts, audit evidence. Entreprise above 100 employees, with dedicated support.
How do I get help?
By e-mail (support@aleth.pro). Reply within 24 business hours.
Glossary

Understanding the key terms.

DORA register of information
Register required by Article 28 of DORA, listing all of a financial entity's third-party ICT providers, including AI tools. Submitted to the regulator via the ACPR's OneGate portal.
DORA
Digital Operational Resilience Act, EU Regulation 2022/2554 on the digital operational resilience of the financial sector. In force since 17/01/2025.
FRIA
Fundamental Rights Impact Assessment, required by the AI Act (Art. 27) for certain high-risk systems. Distinct from DORA.
Shadow AI
Use of AI tools by employees without the approval or knowledge of IT or compliance.
AI Act
European AI regulation, classifying systems by risk level. In force in stages: AI literacy (Art. 4) and prohibited practices (Art. 5) since February 2025, transparency (Art. 50) since August 2026. High-risk obligations (Annex III): 2 December 2027.
GDPR
General Data Protection Regulation, the EU regulation on personal data.
Cloud Act
US law (2018) allowing United States authorities to demand access to data held by American providers, even when it is hosted outside the United States.
AI Health Score
Proprietary Aleth indicator: an overall rating (0–100) of a company's exposure to AI risk, complemented by a classification of each tool on 5 levels (Low to Critical). A risk indicator, not a legal verdict.
ACPR / AMF
French financial-sector regulators, the competent authorities for DORA.
CNB
Conseil National des Barreaux, the representative body of lawyers in France. Author of the guide « La déontologie et l'IA » (March 2026).
ICT provider
Provider of information and communication technology services, a category that includes AI tools within the meaning of DORA.

Ready to reveal your Shadow AI?

Start with a free diagnostic, or explore our resources. Free diagnostic with no commitment and no credit card. Hosted in the EU.

No credit card. No commitment.