ShadowAI · Free tool

Does this AI tool train on your data?

Look up a vendor’s training terms, retention, administrative controls and BAA availability — or compare two side by side. The answer usually differs between the consumer and business tier of the same product.

The question that actually matters

Most AI vendor reviews start with "is it secure?" — which almost every vendor can answer yes to. The question that decides whether a tool belongs in your policy is narrower: does the vendor's default contract let them train on what your employees put in, and can your IT team see and revoke the accounts?

Those two answers split the market cleanly. Business and enterprise tiers usually exclude customer content from training and give you an admin console. Consumer tiers of the very same product usually do neither — and cost nothing, which is exactly why employees are already using them.

Why "the user can opt out" is not an answer

Several vendors let an individual user turn off training in a settings menu. That is a control the user holds, not one the company holds — there is no way to verify from the outside that anyone actually set it, and no way to enforce it at scale. For policy purposes a per-user opt-out is closer to "trains on your data" than to "does not", which is why it scores 1 out of 3 rather than 3.

Turn these answers into an enforceable policy

Knowing which tools are governable is step one. ShadowAI publishes the complete AI acceptable-use policy: the tiered tool list, the approval workflow, and the sections that make it enforceable.

Get the AI policy template — $79 Check your current policy free

Home · AI tool directory · Risk index · Vendor check · Exposure estimator · Regulation deadlines · Policy gap check

ShadowAI publishes AI governance policy templates. This page is general information about vendor terms and AI regulation, not legal advice — verify against the vendor's current terms and your own counsel before relying on it.