ShadowAI · Free tool

Shadow AI exposure estimator

How many people are using AI for work through an account you do not control? Set your own assumptions — the arithmetic is shown in full, and no industry statistic is quoted at you.

Percent. Set this to your own number — a survey, an SSO report, or your best estimate.
Percent. Personal accounts are the part IT cannot see, manage, or offboard.
This is arithmetic on your assumptions, not a measurement. We deliberately do not seed this with an industry adoption statistic. Published shadow-AI numbers vary enormously by sector, seniority and how the question was asked, and quoting one at you would dress a guess up as a finding. The two percentages above are yours to set, the arithmetic is shown in full, and the output is only ever as good as what you entered.

How to get a real number instead

Three sources will beat any estimate, and all of them are usually available within a week:

Your identity provider. SSO and OAuth grant logs show which AI services employees have connected to company accounts — including the ones nobody asked for. This is the single highest-yield place to look.

Your network or CASB logs. DNS or egress data shows traffic to AI domains. It will not tell you what was pasted, but it establishes scale quickly.

An amnesty survey. Ask, in writing, with an explicit no-consequences guarantee, which AI tools people use and what for. Response quality depends entirely on whether people believe the amnesty — which is why it works far better before a policy lands than after.

Why personal accounts are the whole problem

Of the 25 tools tracked in the risk index, 10 offer no administrative visibility at all on the tier employees are most likely to use, and 14 either train on your content by default or leave that decision to a setting the individual user controls.

None of that is a security failure in the ordinary sense. Nothing was breached. An employee pasted a client document into a tool that works well, using an account the company does not hold, under terms the company never agreed to — and there is no log of it and no way to revoke it.

The exposure is the argument. The policy is the answer.

ShadowAI publishes a complete AI acceptable-use policy — tiered tool list, approval route, disclosure and confidentiality sections, and a training acknowledgement your staff actually sign.

Get the AI policy template — $79 Check your current policy free

Home · AI tool directory · Risk index · Vendor check · Exposure estimator · Regulation deadlines · Policy gap check

ShadowAI publishes AI governance policy templates. This page is general information about vendor terms and AI regulation, not legal advice — verify against the vendor's current terms and your own counsel before relying on it.