AI Policy Profiles

Predefined policy rules for every field

Choosing allow, block or controls for 18 categories and 165 subcategories across 18,548+ AI tools can be daunting. Every profile below gives a recommended verdict for every AI tool domain, so a Shadow AI Audit finding tells you not just what was found, but what to do about it.

15profiles
165subcategory rules
18,548domains with a verdict
13risk flags checked
Choose a profile

Each profile assigns a Block, Allow with controls, or Allow verdict

Based on category, subcategory, risk flags and the vendor's training terms. Every profile is included with every Shadow AI Audit report.

Choose a profile. The counts, category defaults and sample rules below change with it.
Showing profile

Healthcare

Hospitals, clinics, practices and health-tech teams handling protected health information.

No patient data in a consumer AI tool, ever. Clinical and back-office AI only under a signed agreement.

Read the related guide →

8,524domains to block
9,868allow with controls
156allow
Agents & Automation
Healthcare default: Block
AI workflow automation: Block (6260) General autonomous agents: Block (4390) Personal AI assistants: Block (3363) RPA with AI: Block (2463) Agent-building frameworks: Block (1430) MCP servers & integrations: Block (1346) +2 more subcategories
Audio, Voice & Music
Healthcare default: Block
Text-to-speech: Block (694) Speech-to-text & transcription: Allow with controls (496) Real-time voice agents & phone AI: Block (367) Music generation: Block (321) Podcast tools: Block (311) Voice cloning: Block (288) +4 more subcategories
Business & Vertical
Healthcare default: Allow with controls
Finance & accounting: Allow with controls (1071) E-commerce: Allow with controls (971) HR & recruiting: Allow with controls (677) Healthcare & med-tech: Allow with controls (490) Government & public sector: Allow with controls (314) Legal: Allow with controls (233) +6 more subcategories
Code & Development
Healthcare default: Allow with controls
Code assistants & autocomplete: Allow with controls (1049) Documentation: Allow with controls (1030) Autonomous coding agents: Allow with controls (863) API dev assistants: Allow with controls (669) Debugging & error monitoring: Allow with controls (481) Testing & QA: Allow with controls (463) +6 more subcategories
Customer Support
Healthcare default: Allow with controls
Support chatbots & AI helpdesk: Allow with controls (1217) Conversational commerce & messaging bots: Allow with controls (671) Ticket routing & agent-assist: Allow with controls (533) Voice & call-center agents: Allow with controls (393) Review management: Allow with controls (64)
Data, Analytics & Research
Healthcare default: Block
Market & competitive intelligence: Block (2977) Predictive analytics & forecasting: Block (2370) BI & natural-language analytics: Block (1390) Document data extraction: Block (1258) Data cleaning & prep: Block (950) Survey & feedback analysis: Block (860) +4 more subcategories
Design, 3D & Creative
Healthcare default: Allow
UI/UX design assistants: Allow (1337) AR/VR content: Allow (683) Game-dev AI: Allow (609) 3D model & asset generation: Allow (603) Fashion design & virtual try-on: Allow (306) Font & typography: Allow (255) +1 more subcategories
Education & Learning
Healthcare default: Allow
AI tutors & personalized learning: Allow (1045) Course & curriculum creation: Allow (454) Quiz, flashcard & study: Allow (369) Grading & feedback: Allow (264) Kids' learning & STEM: Allow (234) Language learning: Allow (204) +1 more subcategories
Image & Visual
Healthcare default: Allow with controls
Text-to-image: Allow with controls (1515) Graphic design & layout: Allow (1027) Image editing & inpainting: Allow with controls (865) Illustration & character: Allow with controls (586) Avatars & headshots: Allow with controls (486) Background removal: Allow with controls (288) +7 more subcategories
Lifestyle & Entertainment
Healthcare default: Block
AI companions & character chat: Block (557) Gaming & AI-native games: Block (295) Dating & relationships: Block (241) Mental wellness & journaling: Block (220) Astrology & fun generators: Block (199) Health, fitness & nutrition: Block (120) +5 more subcategories
Marketing, Sales & SEO
Healthcare default: Allow with controls
Product marketing: Allow with controls (1857) SEO & GEO optimization: Allow with controls (1206) Sales prospecting & SDR agents: Allow with controls (1096) Ad creative & optimization: Allow with controls (1038) Social media management: Allow with controls (1026) Email marketing & personalization: Allow with controls (1006) +4 more subcategories
Models & Infrastructure
Healthcare default: Block
Hosting & inference platforms: Block (620) Foundation models & model APIs: Block (523) Fine-tuning & training: Block (436) LLM gateways & routing: Block (326) Observability & evals: Block (248) Local runtimes: Allow with controls (238) +6 more subcategories
Productivity & Collab
Healthcare default: Block
Meeting assistants: Block (2698) Document drafting & office copilots: Block (2248) Task & project management AI: Block (2134) Email management & triage: Block (587) Calendar & scheduling: Block (308) Presentation & slide generation: Allow with controls (278) +2 more subcategories
Robotics & Embodied AI
Healthcare default: Allow with controls
Robotics platforms & foundation models: Allow with controls (58) Computer-vision & edge vision: Allow with controls (30) Wearables & AI hardware: Allow with controls (24) IoT & smart-home AI: Allow with controls (17) Autonomous vehicles & drones: Allow with controls (16)
Search, Knowledge & Docs
Healthcare default: Block
AI search & answer engines: Block (433) Enterprise search & KM: Block (216) RAG platforms & retrieval infra: Block (177) Chat-with-documents & PDF: Block (105) Browser copilots & reading assistants: Block (50) Note-taking & second brain: Block (28)
Security & Detection
Healthcare default: Allow
AI for cybersecurity: Allow (315) Identity verification: Allow with controls (144) Fraud detection: Allow (135) Privacy & PII redaction: Allow with controls (89) AI-content detectors: Allow (21) Deepfake detection & forensics: Allow (20) +1 more subcategories
Text & Language
Healthcare default: Block
General assistants & chatbots: Allow with controls (3358) Writing & long-form: Block (1752) Copywriting & marketing copy: Block (1397) Summarization: Allow with controls (977) Translation & localization: Allow with controls (974) Grammar, style & proofreading: Allow with controls (813) +6 more subcategories
Video
Healthcare default: Allow with controls
Text-to-video: Allow with controls (1107) AI video editing: Allow with controls (840) Animation & motion graphics: Allow with controls (529) Dubbing, lip-sync & translation: Allow with controls (440) Short-form clip repurposing: Allow with controls (440) Talking avatars & presenters: Allow with controls (281) +4 more subcategories
Block keep it off the network Allow with controls enterprise or SSO tier, no-training terms, logging Allow fine on default settings

Apply this profile to your own network

Run a free Shadow AI Audit and every tool it finds gets a verdict under the profile you pick.

Run a Free AuditSee plans
FAQ

Questions before you deploy

What is an AI policy profile?

A recommended action for every AI tool: Block, Allow with controls, or Allow. One profile per audience, from MSPs to healthcare, legal and defense.

How is the verdict decided?

From fields every AI tool domain already carries: category and subcategory, risk rating, data-sovereignty exposure, abusive-purpose flag, and the vendor's stated position on training with user data.

How does this connect to my Shadow AI Audit?

Every tool your audit finds already carries these same fields. Pick a profile and the report shows how many findings would be blocked, controlled or allowed under it.

My sector is not listed

Start from General Business. Contact us if you need a profile for your specific sector.