Shadow AI Risk Assessment: How to Score Employee Use of Public AI Tools
Approved and blocked are often too crude for enterprise AI risk. A practical model evaluates identity risk, data risk, tool risk, action risk, and governance risk together.
By AgentID Editorial Team • 9 min read.
August 12, 2026
Key takeaways
Approved and blocked are often too crude to describe enterprise AI risk.
A useful Shadow AI assessment can score identity, data, tool, action, and governance risk.
Capability is often the most important variable as AI moves from answering to reading, writing, executing, and transacting.
Scoring becomes useful when policy decisions can act on it.
Risk is not just the tool. It is who, what data, what authority, and what governance context exist together.
TL;DR
Approved and blocked are often too crude to describe enterprise AI risk.
A practical Shadow AI assessment can evaluate five dimensions: Identity Risk, Data Risk, Tool Risk, Action Risk, and Governance Risk.
This is an illustrative governance framework, not an official regulatory methodology or certification model.
The Five-Dimension Model
Assign each dimension a score from 1 to 5. Identity risk looks at whether the AI identity is enterprise-managed or personal. Data risk ranges from public to regulated or highly sensitive. Tool risk depends on configuration and controls. Action risk ranges from generate to execute, transact, or delegate. Governance risk asks whether the use is approved, owned, logged, enforced, and reviewed.
Scoring and Example Thresholds
A simple score is Total risk = I + D + T + A + G, with a maximum of 25.
Score
5-9
Risk
Low
Typical response
Allow plus basic logging
Score
10-14
Risk
Medium
Typical response
Warn or monitor
Score
15-19
Risk
High
Typical response
Mask, restrict, or approval
Score
20-25
Risk
Critical
Typical response
Block or require formal exception
| Score | Risk | Typical response |
|---|---|---|
| 5-9 | Low | Allow plus basic logging |
| 10-14 | Medium | Warn or monitor |
| 15-19 | High | Mask, restrict, or approval |
| 20-25 | Critical | Block or require formal exception |
Illustrative Examples
An enterprise-managed account generating public copy with mature controls and approved governance can score low. A personal chatbot analyzing customer names can score high. A coding assistant with repository context plus credentials can score critical.
These examples show why AI tool risk alone is not enough. The same model can create dramatically different risk depending on identity, data, authority, and governance context.
The Most Important Variable: Capability
Agentic systems make action risk increasingly important. AI that answers is different from AI that reads, which is different from AI that writes, executes, delegates, or transacts.
Impact depends heavily on what connected systems the AI can access and what authority it has.
How AgentID Can Operationalize the Model
A scoring framework becomes useful when policy decisions can act on it. Low-risk interactions can be allowed, medium-risk interactions warned, high-risk interactions masked or approval-gated, and critical-risk interactions blocked.
AgentID's browser and runtime layers are designed around translating AI risk policies into technical control and traceable evidence.
Copyable Assessment
For every material AI use, record Identity Risk, Data Risk, Tool Risk, Action Risk, Governance Risk, total score, owner, purpose, sanctioned status, required control, review date, and evidence.
Next step
Continue from the article into the product layer
If this topic matches a problem your team is actively working through, the clearest next page is the canonical product layer behind these resources.