PreviewYou're previewing CIO AI Nexus. Sign in to use it.Sign in
← Tools

Signature tool · CIO AI Nexus

Shadow-AI discovery & response kit

A four-part kit. (a) A discovery checklist of the places shadow AI shows up — SSO and OAuth grants, expense reports, network and CASB logs, browser extensions, an employee survey — with progress. (b) An employee questionnaire you can copy. (c) A triage table: for each tool you found, answer five questions (data sensitivity, does the vendor train on your data, is there an enterprise plan, business value, is there an approved alternative) and fixed rules return block, replace or approve, with the reasons. (d) An approved-tools catalog in Markdown, generated from your decisions. Nothing is generated by AI; the explain button only explains the result.

The example tools in the triage table are illustrative, not real findings — replace them with what you discover. The triage rules are a sensible default, not a standard; adjust the outcomes to your own policy.

Organization

a. Discovery checklist

Where shadow AI shows up. Tick each source once you have checked it.

Progress0 of 10 · 0%

b. Employee questionnaire

A template to paste into your survey tool. It is framed as help, not an audit — people answer more honestly.

We want to give everyone at our organization good AI tools that are safe to use with company data. Tell us which AI tools you use today and what you use them for. This is not an audit: your answers help us decide which tools to approve, replace or provide. It takes about five minutes.

  1. Which AI tools do you use for work, even occasionally?
    • ☐ A general chat assistant (personal account)
    • ☐ A general chat assistant (company account)
    • ☐ An AI meeting note-taker
    • ☐ An AI writing or summarizing browser extension
    • ☐ An AI coding assistant
    • ☐ AI features inside a business application
    • ☐ Other (please name below)
  2. Please name the tools (and whether you use a free, personal paid or company plan).

    Open answer

  3. What do you mainly use them for?
    • ☐ Drafting or rewriting text
    • ☐ Summarizing documents or meetings
    • ☐ Research and finding information
    • ☐ Analysing data
    • ☐ Writing or reviewing code
    • ☐ Creating images or presentations
    • ☐ Other
  4. What kind of information do you put into these tools?
    • ☐ Only public information
    • ☐ Internal but not sensitive information
    • ☐ Confidential information (customer, financial, HR, strategy)
    • ☐ Restricted information (personal data, source code, regulated data)
    • ☐ Not sure
  5. How often do you use AI tools for work?
    • ☐ Daily
    • ☐ Weekly
    • ☐ Monthly or less
  6. How much time or effort do these tools save you in a typical week?
    • ☐ Less than 30 minutes
    • ☐ 30 minutes to 2 hours
    • ☐ 2 to 5 hours
    • ☐ More than 5 hours
  7. Why do you use this tool rather than an approved company tool?
    • ☐ I didn't know an approved tool existed
    • ☐ The approved tool doesn't do what I need
    • ☐ The approved tool is harder to access
    • ☐ There is no approved tool for this
    • ☐ Other
  8. What would you most like an approved AI tool to help you with?

    Open answer

c. Triage what you found

Example data — replace with yours

Answer five questions per tool. Fixed rules return block, replace or approve — the reasons are shown so you can check them.

  • ReplaceExposure 79/100

    • Non-public data is safe here only on an enterprise plan, and an approved tool (Approved enterprise assistant) already covers the need: move users there rather than buying a second enterprise plan.
  • BlockExposure 61/100

    • Confidential data, and nobody has confirmed whether the vendor trains on it.
    • No approved alternative yet: block, tell users why, and log the need for the AI intake backlog.
  • ReplaceExposure 59/100

    • The vendor trains on inputs and there is no enterprise plan that switches this off — non-public data would leave your control.
    • Low business value (2/5) does not justify the data risk.
    • An approved alternative covers the need: move users to Approved enterprise assistant.
  • ApproveExposure 26/100

    • High business value (4/5) with a manageable data risk.

    Conditions

    • Use only the enterprise plan, with SSO and the vendor's no-training setting confirmed in the contract.
    • Allowed data: up to confidential.
    • Name a business owner and add the tool to the AI portfolio tracker.
  • ReplaceExposure 76/100

    • Non-public data is safe here only on an enterprise plan, and an approved tool (Approved code assistant) already covers the need: move users there rather than buying a second enterprise plan.
  • ApproveExposure 40/100

    • Moderate value (3/5) and a manageable data risk.

    Conditions

    • Get written confirmation that your inputs are not used for training (or switch training off).
    • Allowed data: up to public (public information only while the vendor may train on inputs).
    • Name a business owner and add the tool to the AI portfolio tracker.
Block
1
Replace
3
Approve
2
Users to move
425
How the rules decide
  1. Stop if restricted data goes into a tool with no enterprise plan.
  2. Stop if the vendor trains on inputs, the data is not public and there is no enterprise plan.
  3. Stop if confidential or restricted data is used and nobody knows whether the vendor trains on it.
  4. Stop if business value is 2 or less and the data is not public.
  5. A stop becomes Replace when an approved alternative exists, otherwise Block.
  6. Without a stop, when an approved alternative exists: value 3 or less, or non-public data that would need a second enterprise plan → Replace.
  7. Otherwise Approve with conditions (plan, training opt-out, allowed data, owner).

These defaults are a starting point, not a standard — align them with your own data policy.

d. Approved-tools catalog

Generated from your triage decisions: approved tools with conditions, “use this instead” for replaced tools, and what is not allowed. Publish it on your intranet.

# Approved AI tools — our organization

_Last updated 2026-10-05. Ask IT before using any AI tool that is not on this list._

## Approved

| Tool | Vendor | Conditions |
| --- | --- | --- |
| Image generator | Vendor U | Get written confirmation that your inputs are not used for training (or switch training off). Allowed data: up to public (public information only while the vendor may train on inputs). Name a business owner and add the tool to the AI portfolio tracker. |
| AI slide designer | Vendor S | Use only the enterprise plan, with SSO and the vendor's no-training setting confirmed in the contract. Allowed data: up to confidential. Name a business owner and add the tool to the AI portfolio tracker. |

## Use the approved alternative instead

| Instead of | Use | Why |
| --- | --- | --- |
| Consumer chat assistant (free plan) | Approved enterprise assistant | Non-public data is safe here only on an enterprise plan, and an approved tool (Approved enterprise assistant) already covers the need: move users there rather than buying a second enterprise plan. |
| Code assistant (personal accounts) | Approved code assistant | Non-public data is safe here only on an enterprise plan, and an approved tool (Approved code assistant) already covers the need: move users there rather than buying a second enterprise plan. |
| PDF summarizer extension | Approved enterprise assistant | The vendor trains on inputs and there is no enterprise plan that switches this off — non-public data would leave your control. |

## Not allowed

- **AI meeting note-taker** — Confidential data, and nobody has confirmed whether the vendor trains on it.

## Need something that is not here?

Tell IT what you are trying to do. We review requests for new AI tools and add good ones to this list.

Export the full kit (discovery, triage, catalog)

The scores are calculated in code. AI only explains them — check anything important.

Sign in to save your work privately and come back to it. Export works without an account.

The other signature tool →🗂️ AI portfolio & vendor tracker