"AI is risky" is not actionable. This taxonomy sorts shadow AI exposure into four tiers with different clocks: what needs blocking today, what needs terms review this quarter, and what merely needs watching.
Find your tier-1 exposure freeEach tier pairs a risk class with the response speed it deserves. The audit's flags map straight onto them.
From our register and vendor-terms research. These are the base rates your findings land against.
Every stat above, plus the implications, is unpacked tile by tile on the statistics page.
Three inversions we see in nearly every first triage meeting.
Big-name assistants are usually tier 2: real training-terms questions, solvable with an enterprise contract. The obscure tool with an abusive flag and one user outranks it.
A tool that admits training can be negotiated with or blocked on facts. A silent-terms tool gives you nothing to file, which auditors treat as your gap, not the vendor's.
Drafting tools see what someone chose to paste. Meeting bots hear everything everyone said, including the parts nobody would have pasted. Rank by intake breadth, not output glamour.
The report encodes these corrections already: abusive flags, silent-terms verdicts and category context per tool. Triage from its columns, not from name recognition.
Risk without an owner is a slide, not a control. The mapping that makes the taxonomy operational:
| Tier | Primary owner | The artifact they need | Report section that feeds it |
|---|---|---|---|
| 1: abusive tools | Security + HR | Block date and per-user finding, handled formally | Abusive flag, per-user table |
| 2: data-leaving | Security + vendor management | Migration list with dated verdicts | Training and sovereignty columns |
| 3: account risks | IT / identity | SSO onboarding queue, OAuth grant review | Tool list x user counts |
| 4: governance | Compliance / CISO | Quarterly inventory PDF, delta narrative | The whole evidence pack |
Evidence-handling note: the audit reads hostnames and identities only, uploads are discarded after each run, and reports are deletable before their 90-day expiry.
The free preview counts your high-risk, training-exposed and abusive-flagged tools without naming them all. The full report turns each tier into a worklist.
Overclaiming risk burns credibility you will need for the real findings.
Provably false in your own report: sanctioned tools with no-training contracts sit at the bottom of the table doing fine. Blanket alarm teaches staff to ignore you.
The per-user table shows initiative, not malice. Treating discoverers as offenders guarantees the next tool stays hidden longer.
Blocking answers tier 1 and selected tier 2 rows. The rest is contracts, identity and cadence, which no firewall rule provides. Sequencing lives on detect before you block.
By frequency: tools whose terms are silent on training, carrying real workloads. By severity per incident: abusive-purpose tools on corporate networks.
It can, when content enters tools that train by default or stay silent. The fix is contractual: enterprise tiers with no-training terms for the tools that matter.
The audit's training column gives a dated verdict per tool found on your network, drawn from 13,000+ vendor terms reviews.
Generally yes: training-by-default clauses concentrate in free and consumer tiers, and enterprise contracts are where protections live. Tier is a stronger signal than brand.
Work the tiers in order: block abusive same day, migrate data-leaving workloads this month, fold accounts into SSO this quarter, then hold the cadence.
Continuously; vendors edit terms without announcements. That is why verdicts carry check dates and why quarterly re-audits treat changed verdicts as findings.
A generic-safe composite of the pattern, stage by stage. No firm names; every stage is common.
The lesson is not "AI is dangerous". It is that unmeasured usage converts small contractual gaps into large disclosure exercises.
Risk taxonomies impress auditors; boards ask simpler questions. Each has a tier-shaped answer.
Tier 1. The answer is the abusive-tool count and the block dates. Zero with evidence is a genuinely great slide.
Tier 2. Answer with the training-exposure count and the migration list, both dated from the report.
Tiers 2 and 4 together: the inventory PDF plus the sanctioned split is the pass. The compliance page shows the evidence chain.
A morning per quarter plus report pricing. Boards approve controls whose cost fits in one sentence.
One log export sorts your actual tools into these four tiers, with counts. The free preview shows the tier totals today.
Run the free audit