AI SECURITY RESEARCH NOTE · NO ERS

Shadow AI and Enterprise Data Governance: What 22.4M Prompts Reveal

This source is retained for threat and defensive-evidence research, but AITBM does not manufacture a deployment score where no assessable system boundary exists.

Why this analysis has no ERS

There is no assessed AI deployment. The brief is a cross-vendor population study — Harmonic's telemetry over 22,458,240 prompts and uploads across 665 tools, plus Cyberhaven, Verizon DBIR and IBM breach-cost figures — measuring how enterprise data flows out through employee use of unmanaged third-party AI accounts. The systems receiving the data (ChatGPT, Gemini, Claude, Copilot, Perplexity and 660 others) are not deployments the assessed organisation configures, and the brief supplies no evidence about any of their intrinsic security properties; it measures the volume and category of data leaving governed paths. AITBM scores a specific system in a specific configuration, and 'shadow AI' is precisely the condition of there being no assessed configuration to score. Forcing an architecture class, tier, IVP or ORP onto a 665-tool population would fabricate a system that does not exist. The findings belong instead as evidence inputs to the assessment of the organisation's *governed* AI paths — chiefly Pr-3 (data minimisation), Cn-1 (scope enforcement at the egress boundary), Tr-3 (audit trail completeness), Cn-5 (account and workload identity) and the ORP Attack Surface dimension.

Classification: Research · source date 2026-06-24

AIDEFEND evidence routes

AIDEFEND defences → AITBM sub-metrics

Identifiers are quoted as they appear on the AIDEFEND in Action brief (retrieved 2026-08-13); the sub-metric mapping is AITBM's own, from the specification's AIDEFEND tables reconciled at catalogue data version 2026.08.05. AIDEFEND renumbers identifiers between releases, so the data version travels with every mapping and neither side's IDs should be cited without one. A mapping identifies a possible evidence route; a recommendation does not prove that the control was implemented or effective and receives no scoring credit by itself.

TechniqueDefence PriorityEvidences
AID-M-001.004AI Service & Embedded SaaS AI DiscoveryParent AID-M-001 (AI Asset Inventory & Mapping). Discovery of externally hosted and embedded AI services is the prerequisite for every other control here; in an AITBM assessment of a governed deployment it would feed Tr-4 lineage and Cn-5 account/workload identity evidence.HighCn-5 Fa-3 Tr-4
AID-I-002.002Secure External AI Service ConnectivityParent AID-I-002 (Network Segmentation & Isolation for AI Systems). Applies only where devices and connections sit inside a governable path; would evidence egress-boundary controls in a governed-deployment assessment.HighCn-4
AID-H-029.001Data-Use Policy Schema, Tagging & ClassificationParent AID-H-029 (AI Data-Use Authorization & Lifecycle-Stage Boundary Enforcement). Machine-readable data-use tags are the direct Pr-3 evidence source for any AITBM assessment of the organisation's approved AI route.HighPr-1 Pr-3 Pr-4
AID-H-029.002Lifecycle-Stage Authorization GateParent AID-H-029. A fail-closed pre-inference gate; the brief notes it governs only controlled enterprise paths and is not an answer for fully bypassed routes.HighPr-1 Pr-3 Pr-4
AID-D-005.001AI System Log Generation & CollectionParent AID-D-005 (AI Activity Logging, Monitoring & Threat Hunting). Structured, redacted logs capturing tool, account type, data category, destination and policy decision are the Tr-3 evidence artefact.MediumCn-7 Tr-3
AID-D-005.002AI Detection Rule Lifecycle, Delivery & HealthParent AID-D-005. Rule health and delivery assurance; in ACI terms this is C_monitor evidence for a governed deployment rather than an IVP score.MediumCn-7 Tr-3
AID-DV-002Honey Data, Decoy Artifacts & Canary Tokens for AIParent AID-DV-002 maps directly to Pr-1 in the reconciled AIDEFEND dataVersion 2026.08.05 crosswalk. Its practical value here is attribution evidence after the fact, not prevention.MediumPr-1

Related AITBM rubrics

Sources