Research
A Bring-Your-Own-AI Governance Model Finds Prohibition-Based Policies Leave the Most Residual Risk
arXiv 2609.05236 defines BYOAI as the distinct form of Shadow AI where employee-authenticated personal ChatGPT, Gemini, or Claude accounts are used outside enterprise identity and security controls, which existing organization-managed AI frameworks do not cover. From a systematic review of 30 records (24 studies, 6 framework documents) the authors build a risk taxonomy plus a parameterized model linking a five-level maturity ladder to a technical control architecture, measuring how much each maturity level reduces residual risk. Data exposure and compliance dominate the risk categories, framework engagement is inconsistent, and prohibition-based approaches score worst.
↳ Follow the thread