ShadowAI · Free tool
AI Tool Risk Index
25 AI tools employees actually use, scored on whether a written policy can be enforced against them — training on your data, administrative control, and independent assurance. The rubric is published below; the data is free to download.
| Tool | Score | Tier | Trains on your data | Admin control | BAA |
|---|---|---|---|---|---|
| ChatGPT Enterprise OpenAI · General assistant |
10/10 | Approved | No | Yes | Available |
| Claude for Work / API Anthropic · General assistant |
10/10 | Approved | No | Yes | Available |
| Google Gemini for Workspace Google · Productivity suite AI |
10/10 | Approved | No | Yes | Available |
| Grammarly Business Grammarly · Writing assistant |
10/10 | Approved | No | Yes | Available |
| HubSpot AI (Breeze) HubSpot · CRM / marketing AI |
10/10 | Approved | No | Yes | Available |
| Microsoft Copilot for M365 Microsoft · Productivity suite AI |
10/10 | Approved | No | Yes | Available |
| Notion AI Notion · Workspace AI |
10/10 | Approved | No | Yes | Available |
| Salesforce Einstein Salesforce · CRM / platform AI |
10/10 | Approved | No | Yes | Available |
| Slack AI Slack (Salesforce) · Workspace AI |
10/10 | Approved | No | Yes | Available |
| Adobe Firefly Adobe · Image generation |
9/10 | Approved | No | Yes | Undocumented |
| Zoom AI Companion Zoom · Meeting AI |
8/10 | Limited | No | Yes | Available |
| Fireflies.ai Fireflies.ai · Meeting transcription |
6/10 | Limited | Depends | Yes | Available |
| Canva AI / Magic Write Canva · Design & content |
5/10 | Limited | Depends | Yes | Undocumented |
| DALL·E (OpenAI Images) OpenAI · Image generation |
5/10 | Limited | Depends | Yes | Undocumented |
| GitHub Copilot GitHub (Microsoft) · Code assistant |
5/10 | Limited | Depends | Yes | Undocumented |
| Otter.ai Otter.ai · Meeting transcription |
3/10 | Limited | Depends | None | Undocumented |
| Perplexity Perplexity AI · AI search |
3/10 | Limited | Depends | None | Undocumented |
| ChatGPT (free) OpenAI · General assistant |
2/10 | Limited | Depends | None | No |
| ChatGPT Plus OpenAI · General assistant |
2/10 | Limited | Depends | None | No |
| Claude (claude.ai free) Anthropic · General assistant |
2/10 | Limited | Depends | None | No |
| Grammarly (free) Grammarly · Writing assistant |
2/10 | Limited | Depends | None | No |
| Midjourney Midjourney · Image generation |
1/10 | Limited | Yes | None | No |
| DeepSeek DeepSeek (Hangzhou) · General assistant |
0/10 | Prohibited | Yes | None | No |
| Google Gemini (personal) Google · General assistant |
0/10 | Prohibited | Yes | None | No |
| Meta AI Meta · General assistant |
0/10 | Prohibited | Yes | None | No |
Click any column heading to sort. Click a tool name for the full write-up, including the vendor's retention terms and the reasoning behind its tier.
How the score is calculated
The score is out of 10, and it is built only from facts that can be checked against a vendor's published terms. Nothing subjective is folded in silently:
- Governance tier (3 points) — Approved = 3, Limited = 1, Prohibited = 0. The tier already reflects whether the tool can be governed by a written policy at all.
- Training on your data (3 points) — Does not train on your content = 3, depends on a setting = 1, trains by default = 0.
- Administrative control (2 points) — IT can see, manage and offboard accounts = 2; otherwise 0. Consumer accounts score 0 because the company does not hold them.
- Independent assurance (2 points) — A published third-party certification = 1, a BAA available for regulated data = 1.
A high score does not mean a tool is safe for every use, and a low score does not mean it must be banned. It means the tool is easy or hard to govern — whether a written policy can actually be enforced against it. The most common shadow-AI problem is not a dangerous tool; it is an ordinary tool used through a personal account that IT cannot see.
What the tiers mean
Approved — business terms exclude your content from training by default, and IT has an admin console. A policy can be enforced against it.
Limited — usable for some work, but something material is outside your control: consumer terms, an opt-out the user controls, or no administrative visibility. These need a named, bounded use case in the policy rather than a blanket yes or no.
Prohibited — the terms or the data handling are incompatible with company or client data. These belong on a named block list, because "use good judgment" does not survive contact with a free tool that works well.
The index tells you which tools are governable. The policy is what governs them.
ShadowAI publishes a complete AI acceptable-use policy — the tiered tool list, the approval process, the disclosure and confidentiality sections, and the training acknowledgement — ready to adapt and issue.
Get the AI policy template — $79 Check your current policy freeHome · AI tool directory · Risk index · Vendor check · Exposure estimator · Regulation deadlines · Policy gap check
ShadowAI publishes AI governance policy templates. This page is general information about vendor terms and AI regulation, not legal advice — verify against the vendor's current terms and your own counsel before relying on it.