The full inventory
Formal and shadow AI use surfaced together — exposure analysis is worthless against a partial map, and the map is always partial until it is made.
An AI legal exposure review from Aun & Co.: every AI touchpoint mapped against contract, liability, IP and confidentiality risk — in one written read.
Most organisations cannot answer a simple question: where does AI touch our business, and what does each touchpoint legally expose. Tools adopted team by team, vendor terms accepted unread, outputs flowing into contracts and customer decisions, confidential material pasted into systems nobody vetted — each is a legal position taken without a decision. The exposure review is the inventory and the analysis: every touchpoint found, its legal risk characterised — contractual, liability, IP, confidentiality, regulatory — and the whole ranked into an actionable picture.
The review begins with discovery, because the inventory is always longer than management believes: formal systems, embedded features and the informal tools individual teams adopted. Each touchpoint is then read legally — the vendor terms as signed, the data that flows in, the outputs and where they land, the duties they engage. Findings are ranked by realistic cost and paired with fixes: terms to renegotiate, uses to gate, flows to reroute, and the handful to stop outright.
Formal and shadow AI use surfaced together — exposure analysis is worthless against a partial map, and the map is always partial until it is made.
Each tool's actual contractual position established — training rights, retention, liability — replacing assumption with the document.
Every exposure priced, sequenced and assigned an owner, so the review converts into remediation rather than a shelf document.
A typical engagement: an exposure review for a professional-services business finds forty-plus AI touchpoints where management expected a dozen — including client material flowing into two consumer-grade tools. The high-risk flows are rerouted within weeks; the rest enter a governed adoption path.
Described in abbreviated, anonymised form to preserve client confidentiality.

Everything AI touches in the business: the tools in use — sanctioned and shadow — the vendor terms actually agreed, the data flowing in, the outputs and their destinations, and the legal duties each engages. The product is a ranked exposure report with a remediation sequence.
In practice, four recur: confidential or personal data entering tools whose terms permit its use, vendor contracts that quietly disclaim everything, AI-shaped outputs creating liability or IP uncertainty in deliverables, and regulatory duties engaged unknowingly. All four are findable and fixable — once inventoried.
Structured discovery across teams and systems, followed by legal analysis of each touchpoint and its terms. A small-to-mid-size organisation typically sees first findings within two weeks and the full ranked report within four to six.
Then the EU AI Act and EU data rules add a second layer on top of Israeli law, and the cross-border exposure should be read together, not separately.