
For your company
Organisation & People
Module · What your staff already do with AI
The Shadow-AI Exposure Check
Every company has AI usage; the only question is whether it is visible. This module measures the gap between your policy and the reality on your staff's screens: visibility, rules people can follow, sanctioned alternatives, data exposure, and whether honesty is safe.
What the five levels look like
Every dimension in this assessment is scored 1 to 5. This is what the levels mean, dimension by dimension. The graded report diagnoses where your own answers land and what to do about it.
Usage is visible
- 1No idea
- 2Anecdotes only
- 3One-off survey
- 4Recent inventory
- 5Continuous visibility
At the low end: You are managing a risk you have never measured. Run an anonymous two-question survey this month; the honest answer will surprise you. What good looks like: Continuous visibility is rare and valuable. Feed it back into procurement so the sanctioned tools track what people actually reach for.
A usable rule exists
- 1No rule
- 2Vague appeal
- 3Written, unknown
- 4Written and known
- 5Known and enforced
At the low end: Without a usable rule every employee invents their own; the cautious lose productivity while the careless leak. Write the one-pager this week. What good looks like: A known, enforced rule with tooling support is the end state. Review it quarterly; the tool landscape will not wait for your policy cycle.
Sanctioned tool good enough
- 1Nothing sanctioned
- 2Evaluation running
- 3Pilot for a few
- 4Rolled out broadly
- 5Rolled out, preferred
At the low end: Every week without a sanctioned option pushes more work into private accounts. An imperfect approved tool beats a perfect ban. What good looks like: When the sanctioned tool is the preferred tool, shadow usage collapses on its own. Keep it competitive; that is the whole game.
Data exposure is known
- 1No idea
- 2Assume the worst
- 3Spot checks
- 4Partial monitoring
- 5Systematic monitoring
At the low end: Hope is not a control. Start with one focused question in the survey from question 1: "what have you pasted in?", with amnesty attached. What good looks like: Systematic visibility of outbound data is exceptional. Pair it with the amnesty culture from question 5 so monitoring does not drive usage underground.
Honesty is safe
- 1It is punished
- 2Don't ask, don't tell
- 3Tolerated quietly
- 4Encouraged with rules
- 5Celebrated and shared
At the low end: Punishment does not stop usage; it stops reporting. Declare an amnesty before you measure anything, or the numbers will lie to you. What good looks like: A culture that shares AI wins openly turns staff into sensors: they will tell you about new tools and new risks before any audit does.