Public lookup

AI tool catalog, classified by risk

This is the same catalog Tangerin AI uses to detect artificial-intelligence usage in corporate environments. It holds 6,010 catalogued tools — 3,971 of them active today — each with a risk level, a category and the home country of the company behind it. The lookup is open and requires no signup.

Search the entire catalog

6,010

Tools catalogued

3,971

Active and browsable

11

Categories

79

Home countries

Browse by category

Each category groups tools that present the same kind of exposure — and therefore call for the same kind of control in your AI usage policy.

Language models

General-purpose chat assistants and language models. This is the category that receives the highest volume of corporate data pasted into a text box — and the one that shows up most often in Shadow AI leak incidents.

243 tools

Autonomous agents

Tools that act on their own: they open files, browse the web, call APIs. The risk is not what the person types, it is what the agent does unsupervised — a central category in both the EU AI Act and ISO 42001.

470 tools

Code generation

Coding copilots and generators. They transmit source-code fragments, credentials left in comments and business logic to third-party servers, often with training on your data enabled by default.

301 tools

Image

AI image generation and editing. The risk concentrates on image rights, intellectual property of the uploaded material, and photos of identifiable people.

380 tools

Video

Video generation and editing, including facial synthesis. Deepfake and face-swap tools are classified as critical risk by default.

339 tools

Audio and voice

Transcription, voice generation and voice cloning. Realistic cloning is critical risk: it enables identity fraud, and voice is biometric data under Brazilian and European data protection law.

292 tools

Writing and marketing

Copywriting, translation and content. Low technical risk, high compliance risk when the input text is a contract, an internal policy or customer data.

234 tools

Productivity

Meetings, notes, spreadsheets, slides and work assistants. The largest category in the catalog and the hardest to see: it arrives through the end user's door, not through IT.

1,323 tools

Automation

System-to-system integration with AI in the middle. The risk comes from reach: an automation wired to email, CRM and cloud storage moves corporate data between services with no review step.

239 tools

Search

Search engines with generative answers. What gets searched reveals projects, pending deals and internal weaknesses — intent telemetry leaving the company.

69 tools

Platforms and infrastructure

Model providers, orchestration and AI infrastructure. Usually contracted by the technical team, and for that reason frequently absent from the formal vendor inventory.

81 tools

Browse by risk level

Prefer to start from risk instead of category? Each level groups the tools that call for the same kind of attention in your AI usage policy.

How risk is classified

The risk band does not measure tool quality — it measures what happens if an employee pastes corporate data into it without anyone knowing. The criterion combines the kind of data the tool naturally receives, its capacity to act on its own, the jurisdiction its vendor operates under, and its default behaviour regarding training on customer data.

Critical

123

Direct harm is possible: identity fraud, biometric data, or autonomous action without oversight.

High

1,202

Naturally receives sensitive corporate data — source code, contracts, customer records.

Moderate

2,256

Risk depends on what goes in. Requires an explicit classification in your policy.

Low

390

Narrow scope and clear vendor governance. A candidate for the allowed list.

A living catalog — and what we do with what dies

It exists because the first question of any AI governance programme — “this tool that showed up on my network, what is it, and should I worry?” — had no public answer that went beyond the tool vendor's own website.

The AI market is born and dies fast. A tool that was a reference eight months ago is a parked domain for sale today. So the catalog is continuously re-audited: we check whether each domain still responds, and we review whether each entry still makes sense as a corporate AI tool.

3,971

Active

They respond today and are available for detecting new usage. These are the ones you browse on the pages below.

1,027

Offline

Dead domain, parked, 404 or failing DNS. They left detection but stayed in the catalog.

1,012

Out of scope

Reviewed and reclassified: personal rather than corporate use, or a cataloguing error on our side.

Why we do not delete what went offline

Deleting would be simpler and would make the number look better. We do not, for two concrete reasons. The first is that offline domains come back — the product gets sold, reborn under a new owner, revived after a funding round. A deleted tool would have to be rediscovered from scratch; kept as retired, it only needs to be reactivated once it responds again.

The second is auditability. An event detected ten months ago did not stop happening because the tool died afterwards. If the entry vanished from the catalog, that historical record would lose its risk classification and the compliance report for a closed period would change on its own — the opposite of what an evidence trail is for. A retired entry keeps its risk frozen precisely so the past stays auditable, even as it leaves detection of new usage.

Research: one in five AI tools we catalogued no longer exists

Knowing what exists is different from knowing what is being used

This catalog answers “is this tool risky?”. It does not answer “which of these are running in my company right now?” — and that second question is the one that shows up in an audit. The free assessment takes 5 minutes, asks for no signup, and returns your maturity level per dimension with an action plan.

About this base

The catalog is maintained by Tangerin AI and continuously re-audited. The 2,039 retired entries — 1,027 because they went offline and 1,012 after a scope review — remain on record with their risk frozen, but stay out of new-usage detection and out of the browsable listings on this page. Classifications reflect our team's judgement based on the tools' public documentation and may change when the tool changes.

Home country is the headquarters of the company behind the tool — it is not a claim about where data is physically processed or stored. Data residency depends on the plan you hold and must be verified with the vendor.

Found a classification you believe is wrong, or a tool that should be here? contato@tangerinai.com.