World Model Readiness
Engraved organisation instrument

For your company

Organisation & People

Module · What your staff already do with AI

The Shadow-AI Exposure Check

Every company has AI usage; the only question is whether it is visible. This module measures the gap between your policy and the reality on your staff's screens: visibility, rules people can follow, sanctioned alternatives, data exposure, and whether honesty is safe.

Question 1 of 5 · Usage is visible

Do you know which AI tools your employees actually use for work?

Not which tools are licensed: which are used. Browser chatbots, plugins, private accounts on company laptops. The gap between the two is where confidential data travels.

Question 2 of 5 · A usable rule exists

Is there a rule your staff can actually follow for what may go into public AI tools?

"Never use AI" is not a rule anyone follows. A usable rule names data categories: what is always fine, what needs approval, what never leaves. One page, not forty.

Question 3 of 5 · Sanctioned tool good enough

Do employees have a sanctioned AI tool that is actually good enough to use?

Shadow AI is a demand signal. If the sanctioned option is slower or worse than a private ChatGPT account, the ban loses to convenience every single day.

Question 4 of 5 · Data exposure is known

Do you know what categories of company data have already gone into public AI tools?

Assume the answer is not "nothing". Customer lists, source code, contract drafts and board papers are the usual suspects. The question is whether you know, or hope.

Question 5 of 5 · Honesty is safe

Can employees admit their AI use without fearing consequences?

Every measurement above depends on this one. If admitting usage is punished, your surveys measure fear, not reality, and the real exposure stays invisible.

For the statistics · one click each

Three questions for the public picture

These do not affect your score. They feed the anonymised, aggregated statistics; groups under 8 respondents are never shown.

What share of your staff uses AI tools for work at least weekly?

Under 10 percent
10 to 30 percent
30 to 60 percent
Over 60 percent
We do not know

Does your company block public AI tools?

Yes, blocked
Blocked, but bypassed
Not blocked
Considering it

Has confidential data already ended up in a public AI tool?

Not that we know of
We suspect so
Confirmed, minor
Confirmed, serious
We cannot tell

Your context

Used to calibrate the report. Company size and sector remain in the anonymized dataset; your email does not.

What the five levels look like

Every dimension in this assessment is scored 1 to 5. This is what the levels mean, dimension by dimension. The graded report diagnoses where your own answers land and what to do about it.

Usage is visible

  1. 1No idea
  2. 2Anecdotes only
  3. 3One-off survey
  4. 4Recent inventory
  5. 5Continuous visibility

At the low end: You are managing a risk you have never measured. Run an anonymous two-question survey this month; the honest answer will surprise you. What good looks like: Continuous visibility is rare and valuable. Feed it back into procurement so the sanctioned tools track what people actually reach for.

A usable rule exists

  1. 1No rule
  2. 2Vague appeal
  3. 3Written, unknown
  4. 4Written and known
  5. 5Known and enforced

At the low end: Without a usable rule every employee invents their own; the cautious lose productivity while the careless leak. Write the one-pager this week. What good looks like: A known, enforced rule with tooling support is the end state. Review it quarterly; the tool landscape will not wait for your policy cycle.

Sanctioned tool good enough

  1. 1Nothing sanctioned
  2. 2Evaluation running
  3. 3Pilot for a few
  4. 4Rolled out broadly
  5. 5Rolled out, preferred

At the low end: Every week without a sanctioned option pushes more work into private accounts. An imperfect approved tool beats a perfect ban. What good looks like: When the sanctioned tool is the preferred tool, shadow usage collapses on its own. Keep it competitive; that is the whole game.

Data exposure is known

  1. 1No idea
  2. 2Assume the worst
  3. 3Spot checks
  4. 4Partial monitoring
  5. 5Systematic monitoring

At the low end: Hope is not a control. Start with one focused question in the survey from question 1: "what have you pasted in?", with amnesty attached. What good looks like: Systematic visibility of outbound data is exceptional. Pair it with the amnesty culture from question 5 so monitoring does not drive usage underground.

Honesty is safe

  1. 1It is punished
  2. 2Don't ask, don't tell
  3. 3Tolerated quietly
  4. 4Encouraged with rules
  5. 5Celebrated and shared

At the low end: Punishment does not stop usage; it stops reporting. Declare an amnesty before you measure anything, or the numbers will lie to you. What good looks like: A culture that shares AI wins openly turns staff into sensors: they will tell you about new tools and new risks before any audit does.