The most common shadow AI tools aren't obscure — they're tools your employees find through a Google search, a LinkedIn post, or a recommendation from a colleague. Here's a plain-language breakdown of what the most widely used tools actually do with your company's data, and how to handle each one in your AI policy.
Building a tool tier list for your AI policy requires knowing what each tool actually does with the data employees enter. Most employees don't read terms of service. Most HR managers don't either. This guide cuts through to what actually matters for policy purposes: whether inputs are used for model training, whether enterprise agreements change that, and what risks each tool category creates.
For every tool on your list, employees should be able to answer: "If I use this tool for [specific task], is that okay?" The tier designation (approved / limited / prohibited) is only half the answer. The data handling guidance is the other half — because an approved tool used with the wrong data creates the same risk as a prohibited tool.
A well-constructed tier list pairs the tool name with the specific data restrictions that apply: "ChatGPT Enterprise — Tier 1 — approved for use with internal company information excluding customer PII and financial data" is more useful than "ChatGPT Enterprise — Approved."
Shadow AI Policy generates a tool tier list tailored to the AI tools your company uses — paired with your acceptable use policy, employee acknowledgment form, and manager FAQ.
Generate my tool tier list →When you're not sure how to classify a tool, apply this test: does this vendor have a signed data processing agreement with your organization, and does that agreement include a commitment that inputs are not used for model training?
If yes to both: Tier 1 or Tier 2 depending on what data categories are explicitly covered.
If no: Tier 2 (non-sensitive data only) at best, Tier 3 if the tool handles anything where data exposure would create legal, regulatory, or client relationship risk.
This heuristic handles 90% of tool classification decisions without needing to read every vendor's terms from scratch.
Building your own policy? Start with our free AI acceptable use policy template — copy, edit, and download it as Word or PDF.
A tool tier list classifies each AI tool into one of three or four categories: Approved (can be used without restriction for specified purposes), Limited/Approved with Conditions (can be used only for specified purposes or only with non-sensitive data), Under Review (employees should check before using), and Prohibited (must not be used for company work). Each tool's classification should be based on its data retention practices, training data policies, security certifications, and whether a Business Associate Agreement or Data Processing Agreement is available.
Useful approaches include: a voluntary anonymous survey asking employees which AI tools they use for work, reviewing network traffic logs with your IT team, checking expense reports and credit card statements for AI tool subscriptions, and simply asking department heads what tools their teams use. A formal discovery exercise typically finds 3–5x more AI tool usage than IT was previously aware of.
Companies should not simply ban ChatGPT — bans push usage underground without eliminating the risk. The effective approach is: (1) define which version of ChatGPT is acceptable — ChatGPT Enterprise with data controls, not the free consumer tier; (2) specify which data categories must never be entered into any ChatGPT version; (3) consider whether Microsoft 365 Copilot or another enterprise AI tool can meet employee needs with better data protections; and (4) communicate this clearly in your AI acceptable use policy.
Grammarly processes all text that users type or paste into the tool. Under Grammarly's standard consumer terms, this data is used to improve the service. Grammarly for Enterprise offers different data handling terms including options to restrict data training. For companies where employees use Grammarly with confidential client documents, internal memos, or sensitive business data, the consumer version creates a data exposure risk. The enterprise version with appropriate data processing terms is the appropriate alternative.
The AI tools that appear most frequently in enterprise shadow AI audits are: free-tier ChatGPT and Claude (personal accounts without enterprise data protections), Grammarly (which processes all text entered including sensitive documents), Otter.ai and Fireflies for meeting recording on personal accounts, Notion AI, browser-embedded AI in Microsoft Edge and Google Chrome, and AI coding assistants like GitHub Copilot on personal subscriptions. Most employees using these tools are doing so for legitimate productivity reasons, not maliciously.