TIER 1
Employee shadow AI
Individual employees use personal accounts, personal devices, or browser-based access to AI tools for work tasks without IT approval, organizational visibility, or any assessment of what organizational data is being processed. This is the most visible tier and the one most organizations have begun to address with policy and monitoring. The governance response is policy and technical enforcement: acceptable use policies that specifically address AI, DLP controls extended to browser-based AI usage and clipboard flows, and CASB visibility into which AI tools are accessing organizational data from corporate endpoints.
Evidence
Reco reported that 71 percent of office workers used AI tools without IT approval. Its 2025 report also identified long persistence windows for unsanctioned tools. Public reporting on Samsung engineers pasting proprietary source code into ChatGPT remains a canonical early shadow AI example.