Learn / Risks

Shadow AI risks, tiered by urgency

"AI is risky" is not actionable. This taxonomy sorts shadow AI exposure into four tiers with different clocks: what needs blocking today, what needs terms review this quarter, and what merely needs watching.

Find your tier-1 exposure free
The tier model

Four tiers, four clocks

Each tier pairs a risk class with the response speed it deserves. The audit's flags map straight onto them.

TIER 1

Abusive-purpose tools

Clock: same day
The risk
  • Deepfake, nudify, NSFW and uncensored-generation tools reached from corporate networks.
  • Exposure is not data-shaped, it is conduct-shaped: harassment liability, criminal exposure, reputational detonation.
  • One user, one incident, is enough. Volume does not matter at this tier.
The response
  • Block the domains the same day the report lands; the audit's abusive flag is the shortlist.
  • Involve HR and legal on any per-user finding rather than improvising a confrontation.
  • Document the block date; it is the artifact that shows duty of care.
TIER 2

Data-leaving risks

Clock: this month
The risk
  • Training on your data: our analysis counts 700+ tools that train on customer content by default, and opt-out tools whose switch nobody flipped.
  • Silent terms: 85.5% of AI tools say nothing about training at all. Silence is not safety; it is unpriced exposure.
  • Data sovereignty: tools processing under jurisdictions your contracts or regulators exclude.
The response
  • Rank by users x sensitivity: a summarizer in legal outranks a chatbot in facilities.
  • Migrate real workloads to enterprise tiers with contractual no-training terms.
  • Use the report's dated verdicts as the vendor-review queue, highest tier first.
TIER 3

Account and access risks

Clock: this quarter
The risk
  • Credential reuse: personal AI accounts created with work emails and recycled passwords become phishing and takeover surface.
  • No offboarding: shadow accounts survive departures, keeping pasted history outside your deprovisioning.
  • OAuth sprawl: AI tools granted broad scopes on corporate Google or Microsoft accounts.
The response
  • Fold the audit's tool list into SSO onboarding: sanctioned tools get SSO, which restores offboarding.
  • Review third-party app grants against the report's findings.
  • Password-manager policy quietly fixes most of the reuse tail.
TIER 4

Governance and drift risks

Clock: standing review
The risk
  • Compliance exposure: inventories demanded by frameworks and insurers that you cannot produce on request.
  • Terms drift: a tool that did not train last quarter may train now; verdicts age.
  • Dependency creep: deliverables silently depending on tools nobody contracts for.
The response
  • Quarterly audits with a constant window; deltas between reports are the governance signal.
  • File each PDF as the period's inventory evidence; the compliance angles live under governance inventory.
  • Re-check changed verdicts against the affected teams before renewal season.
Scale of the problem

The numbers that set the tiers

From our register and vendor-terms research. These are the base rates your findings land against.

85.5%of AI tools say nothing about training in their public terms, across 13,000+ reviewed
700+tools train on customer data by default
3,900+tools mapped to the model provider actually behind them
20,399AI domains classified and risk-flagged in the live register

Every stat above, plus the implications, is unpacked tile by tile on the statistics page.

Common mis-rankings

Where instinct ranks risk wrong

Three inversions we see in nearly every first triage meeting.

The famous chatbot is not tier 1

Big-name assistants are usually tier 2: real training-terms questions, solvable with an enterprise contract. The obscure tool with an abusive flag and one user outranks it.

Silence is worse than "trains by default"

A tool that admits training can be negotiated with or blocked on facts. A silent-terms tool gives you nothing to file, which auditors treat as your gap, not the vendor's.

Transcription outranks text generation

Drafting tools see what someone chose to paste. Meeting bots hear everything everyone said, including the parts nobody would have pasted. Rank by intake breadth, not output glamour.

The report encodes these corrections already: abusive flags, silent-terms verdicts and category context per tool. Triage from its columns, not from name recognition.

Risk to owner

Every tier has a desk it belongs on

Risk without an owner is a slide, not a control. The mapping that makes the taxonomy operational:

TierPrimary ownerThe artifact they needReport section that feeds it
1: abusive toolsSecurity + HRBlock date and per-user finding, handled formallyAbusive flag, per-user table
2: data-leavingSecurity + vendor managementMigration list with dated verdictsTraining and sovereignty columns
3: account risksIT / identitySSO onboarding queue, OAuth grant reviewTool list x user counts
4: governanceCompliance / CISOQuarterly inventory PDF, delta narrativeThe whole evidence pack

Evidence-handling note: the audit reads hostnames and identities only, uploads are discarded after each run, and reports are deletable before their 90-day expiry.

Your tiers are already in your logs

The free preview counts your high-risk, training-exposed and abusive-flagged tools without naming them all. The full report turns each tier into a worklist.

See a finished audit
What risk is not

Three framings to retire

Overclaiming risk burns credibility you will need for the real findings.

"All AI use is risky"

Provably false in your own report: sanctioned tools with no-training contracts sit at the bottom of the table doing fine. Blanket alarm teaches staff to ignore you.

"The risk is employees"

The per-user table shows initiative, not malice. Treating discoverers as offenders guarantees the next tool stays hidden longer.

"We will block our way out"

Blocking answers tier 1 and selected tier 2 rows. The rest is contracts, identity and cadence, which no firewall rule provides. Sequencing lives on detect before you block.

FAQ

Risk questions

What is the single biggest shadow AI risk?

By frequency: tools whose terms are silent on training, carrying real workloads. By severity per incident: abusive-purpose tools on corporate networks.

Does using AI tools risk our intellectual property?

It can, when content enters tools that train by default or stay silent. The fix is contractual: enterprise tiers with no-training terms for the tools that matter.

How do I know which tools train on our data?

The audit's training column gives a dated verdict per tool found on your network, drawn from 13,000+ vendor terms reviews.

Are free AI tools riskier than paid ones?

Generally yes: training-by-default clauses concentrate in free and consumer tiers, and enterprise contracts are where protections live. Tier is a stronger signal than brand.

What should we do first after finding risky tools?

Work the tiers in order: block abusive same day, migrate data-leaving workloads this month, fold accounts into SSO this quarter, then hold the cadence.

How often do risk verdicts change?

Continuously; vendors edit terms without announcements. That is why verdicts carry check dates and why quarterly re-audits treat changed verdicts as findings.

Anatomy of an incident

How a tier-2 risk becomes a disclosure question

A generic-safe composite of the pattern, stage by stage. No firm names; every stage is common.

Stage 1A team adopts a free summarizer for client documents. Terms silent on training. Months pass quietly.
Stage 2A client's security questionnaire asks which processors touch their data. The tool is not on any register.
Stage 3Legal must now answer whether client data reached an unvetted vendor, without logs anyone prepared. Reconstruction is expensive precisely because nothing was measured.
Stage 4The eventual answer is qualified and awkward. The remediation, an audit plus enterprise contract, is what a quarterly cadence would have done for $99.

The lesson is not "AI is dangerous". It is that unmeasured usage converts small contractual gaps into large disclosure exercises.

Board translation

The four questions boards actually ask

Risk taxonomies impress auditors; boards ask simpler questions. Each has a tier-shaped answer.

"Can this embarrass us publicly?"

Tier 1. The answer is the abusive-tool count and the block dates. Zero with evidence is a genuinely great slide.

"Is our data training someone's model?"

Tier 2. Answer with the training-exposure count and the migration list, both dated from the report.

"Would we pass the question from our biggest client?"

Tiers 2 and 4 together: the inventory PDF plus the sanctioned split is the pass. The compliance page shows the evidence chain.

"What does managing this cost?"

A morning per quarter plus report pricing. Boards approve controls whose cost fits in one sentence.

Stop debating risk in the abstract

One log export sorts your actual tools into these four tiers, with counts. The free preview shows the tier totals today.

Run the free audit