Governing Bring Your Own AI: A Parameterized Maturity Model Dare Bello, John Hastings
arXiv:2609.05236v1 [cs.CR] 4 Sep 2026
The Beacom College of Computer & Cyber Sciences Dakota State University Madison, SD, USA [email protected], [email protected]
Abstract—Employees are increasingly using personally owned generative AI tools such as ChatGPT, Gemini, and Claude for their daily work. This practice is known as Bring Your Own AI (BYOAI), which is a distinct form of Shadow AI in which employee-authenticated personal accounts are used outside of enterprise identity and security controls. Existing frameworks were designed for AI tools managed by organizations, and their coverage does not extend to unmanaged AI tools used with a personal account. In addressing these issues, we developed a governance model through a systematic review of the literature that produces a risk taxonomy and a framework-engagement profile. We also developed a parameterized governance model that measures how much a level of governance maturity reduces residual risk. A five-level maturity ladder is coupled to a technical control architecture through a chain in which the coverage of the control layer influences the security outcomes. Our study of a curated corpus of 30 records (24 research studies and 6 framework documents) indicated that the most prominent categories identified were data exposure and compliance, and framework engagement was inconsistent. Three mutually supporting pillars (technical, governance, and human) were established to support safeguards. Additionally, the results of the model demonstrated that prohibition-based solutions will result in residual risk levels close to those achieved through baseline solutions. Under the specified parameterization, layered controlbased solutions substantially reduce modeled exfiltration risk and increase enforceable coverage. Index Terms—BYOAI, Shadow AI, AI governance, Risk modeling, Governance maturity, Systematic review, NIST AI RMF, AI TRiSM, Security awareness.
I. I NTRODUCTION Personal generative AI tools have become part of daily work, and employees have adopted personal systems such as ChatGPT, Gemini, and Claude to draft content, summarize documents, help with coding, and support analysis. This trend is similar to previous trends from Bring Your Own Device (BYOD) and Shadow IT, in which employees used their own device or technology before formal governance was implemented [1, 2]. The use of employee-driven technology usually emerges due to perceived inadequacies in organizational resources, such as speed, availability, or alignment with actual workflow requirements [3, 4]. Shadow AI, the unauthorized or unmonitored use of AI within organizations, has gained attention as a growing concern among many stakeholders with documented risks around data leakage, misaligned model behavior, and accountability
gaps [2, 5, 6]. Unlike earlier forms of Shadow AI, BYOAI represents a new form of shadow AI because it involves the use of personal accounts owned by employees and authorized by employees that operate outside of organizational identity systems, network monitoring, and security controls [5, 7]. These personal accounts on unapproved AI tools create variable output that is shaped by unknown training data, thereby introducing bias, hallucinations, or factual inconsistencies into work products [8]. In addition, they can inadvertently expose sensitive organizational data to external systems [5, 9]. The current frameworks for managing AI related risks, including the NIST AI Risk Management Framework, various responsible-AI guidelines, and AI Trust, Risk and Security Management (AI TRiSM) controls, provide valuable conceptual and technical guidelines [10–12]. However, they were developed with AI owned by an organization in mind and do not directly address the visibility and control gaps associated with BYOAI. Prior BYOAI research work generally provides conceptual perspectives and has tended to present governance ratings as asserted values rather than as outputs of a stated, reproducible process. This paper addresses both gaps by developing a governance model grounded in a systematic literature review and expressing its scoring through a parameterized model whose numbers are generated by a script rather than assigned manually. The contribution is threefold: (i) an evidence-based BYOAI risk taxonomy and a framework-engagement profile derived from a systematic literature review; (ii) a five-level governance maturity ladder coupled with a technical-control architecture; and (iii) a parameterized governance model that measures how governance maturity flows through a chain of control coverage, security outcomes, and residual framework gap, supplemented by a retrospective mapping of four previously documented real incidents and one healthcare-sector pattern. The model is defined as directional and deterministic rather than empirical as parameters are literature-derived where sources exist and stated as explicit assumptions otherwise, and empirical validation is left to future work. Our study is guided by four research questions: • RQ1 (Risk): Which risk categories most accurately characterize BYOAI within organizations? • RQ2 (Frameworks): How completely do existing governance frameworks cover BYOAI risks, and where do they
fall short? RQ3 (Safeguards): Which technical and governance controls most reduce residual BYOAI risk? • RQ4 (Maturity): How does a parameterized maturity model quantify an organization’s progression from restrictive to optimized governance? •
II. BACKGROUND AND R ELATED W ORK BYOAI builds on previous patterns of employee-driven technology adoption. BYOD has demonstrated the rapid entry of personal devices into workplace ecosystems prior to having effective governance in place, raising questions about data ownership and device management [3]. Shadow IT expanded on this by introducing the use of unmonitored cloud-based applications that were used to bypass rigid approval processes [1]. Shadow AI has been shown to demonstrate the same types of concerns associated with shadow IT in terms of risks, including unverified datasets, unreliable models, unregulated exposure to sensitive data, and inconsistent access controls [2, 5, 6]. Sector-specific research has been conducted within the healthcare, financial services, and education sectors and each has shown that the use of unregulated AI poses an increased level of risk due to the level of regulatory and confidentiality requirements [5]. BYOAI differs because the accounts are personal rather than corporate. An organization typically will have limited insight into what their employees share with external AI systems, how those systems store or reuse the data, or whether the generated output influences decision-making, which could go against established company policies. Because AI systems transform, store, and reuse information rather than merely transmitting it, the governance implications extend beyond device management to model behavior, output reliability, and long-term retention by third-party providers. Employee-led adoption is also motivated by sociotechnical mismatch: employees turn to personal tools when approved systems are slow, unavailable, or not suitable for the task, and prohibition without a usable alternative tends to convert visible experimentation into concealed use [3, 4, 13]. Existing frameworks provide foundational elements, but not coverage. The NIST AI RMF 1.0 outlines lifecycle-oriented risk management for AI within organizational control [10]. AI TRiSM framework provides model monitoring, runtime inspections, and adversarial defense, but assumes visibility into model operations that personal accounts do not provide [12]. Responsible-AI and ethical frameworks emphasize fairness and transparency, but focus on institutional AI development rather than personal use [11, 14]. Previous work specific to BYOAI introduces governance policies and control domains but stops short of quantifying framework alignment or control coverage [5, 7]. The BYOAI-Gov framework of Anthuvan et al. [1] derived from a 45-article systematic review and a 345-respondent multi-regional survey, is the most similar previous study. In contrast to this paper, it defines BYOAI as a governable “workplace behavior” and provides a behavior-aware framework
with three components: user archetypes; task-risk zoning; and an organizational maturity layer. Our study and theirs are related but distinct. While BYOAI-Gov provides governance postures for organizations based on an author synthesis of what will be effective, we provide a reproducible quantification of the amount of residual risk that remains at each maturity level, using a deterministic, parameterized chain — technicalcontrol coverage score (TCCS), to security outcomes, to a Framework Gap Index (FGI), to a Composite Governance Score (CGS). Central to this is our FGI, which measures how much of a framework’s nominal coverage stays enforceable under BYOAI: because AI frameworks assume organizationowned systems, only a fraction of that coverage holds when accounts are employee-owned, a dimension BYOAI-Gov does not model. We therefore treat the larger body of behavioral evidence presented by BYOAI-Gov as supplementary to, rather than supplanting, our smaller but reproducible and quantified control-coverage model. A. Technical Controls Relevant to BYOAI Governance Most of the concrete BYOAI risk surface appears where data and access leave the organization’s visibility, so data, identity, and cloud-facing controls matter as much as policy. Seven control families anchor the technical pillar. Data Security Posture Management (DSPM) continuously maps where sensitive information resides and how it moves across cloud services, letting security teams spot outbound flows to AI endpoints, tie them to classification rules, and flag assets at risk of being copied into external models. Cloud Access Security Brokers (CASB) sit between users and cloud services to observe and control traffic, flagging or blocking unapproved GenAI destinations and enforcing rules when content labeled confidential is pushed to third-party AI tools. Data Loss Prevention (DLP) inspects content as it leaves endpoints, mail systems, or web gateways; when employees paste source code, client records, or internal documents into personal AI tools, DLP can alert, require justification, or block the transfer. SaaS Security Posture Management (SSPM) targets how SaaS applications are configured rather than individual transactions, surfacing the misconfigured sharing settings, overpermissive integrations, and unmanaged AI plug-ins through which BYOAI often appears. Identity and Access Management (IAM) and Cloud Infrastructure Entitlement Management (CIEM) govern who can reach what data and under what conditions; they do not control personal AI accounts directly, but tighter scoping of permissions shrinks the pool of high-value information available to be copied into external models. Secure Web Gateways (SWG) enforce restrictions on specific AI domains known to store or reuse user-submitted content. Above these, runtime inspection and AI TRiSM functions— monitoring inputs and outputs and checking for abnormal model behavior—inform the upper maturity levels, where AI
A. Search Strategy Three sources were searched: IEEE Xplore, Scopus, and Google Scholar with a structured Boolean query for semantic discovery. The query combined three concept blocks with AND, with synonyms within each block combined using OR: (i) the phenomenon (“shadow AI,” “BYOAI,” “bring your own AI,” “unsanctioned AI,” “unauthorized AI,” “shadow IT”); (ii) the technology (“generative AI,” “large language model,” “LLM,” “GenAI,” “agentic AI”); and (iii) the governance angle (governance, risk management, compliance, data protection, oversight). The searches were restricted to the title, abstract, and keyword fields and to 2018–2026.
Identification
This study combines a systematic literature review (SLR) with a design-science artifact. The review establishes an evidence-based risk taxonomy and a framework-engagement profile for BYOAI; the model then uses these findings, together with stated modeling assumptions, to demonstrate how governance maturity affects residual risk. Because BYOAI activity occurs largely outside enterprise logging, primary telemetry is scarce; a review-plus-model design is therefore appropriate, and every reported value is traceable either to the coded corpus or to an explicitly labeled assumption.
Records identified for BYOAI relevance through database searching (IEEE Xplore, Scopus, Google Scholar) and citation chasing
Records screened by title, abstract, and full text against predefined inclusion criteria (Section III-B) Screening
III. R ESEARCH M ETHODOLOGY
irrelevant, off-topic, or non-substantive. The screening yielded 30 included records, comprising 24 research studies and 6 framework or standard documents evaluated as objects of analysis, as shown in the PRISMA-style flow (Fig. 1). The complete review corpus is represented in [1–30]. We acknowledge as a limitation that because identification was drawn from a curated collection rather than a single reproducible database export, exhaustive-search completeness cannot be claimed.
Records excluded: off-topic to BYOAI governance; non-substantive sources Reports assessed for eligibility (full text retrieved) Reports excluded (n = 1): endpoint-detection paper, not BYOAI governance
Included
interactions are treated as auditable events rather than opaque tools. Early maturity levels use only a few of these families; higher levels progressively add more and assume they operate in combination.
Studies included in review (N = 30): 24 research studies + 6 framework/standard documents; risk-eligible M = 24
Fig. 1. PRISMA-style flow of records through identification, screening, and inclusion.
D. Coding Procedure B. Inclusion and Exclusion Criteria Inclusion criteria were defined before selection. A record was included if it addressed unapproved, personal, or shadow use of AI in an organizational context, or a governance framework or technical control directly applicable to that context; was a peer-reviewed article, conference paper, a scholarly working paper, or substantive report from a recognized body (e.g. NIST, OWASP, ISO); was published 2018–2026; and was available in English. Records were excluded if they were purely technical AI/ML papers with no governance dimension, Shadow-IT papers with no AI element (unless used solely as behavioral grounding), non-substantive sources (blogs, vendor marketing), duplicates, or papers where AI use was incidental. C. Screening and the Corpus IEEE Xplore, Scopus, and Google Scholar were used to search for candidate articles, and it was supplemented with backward and forward citations from previously identified papers. The articles were then compiled into a curated body of work based on relevance to BYOAI. Since our initial search was performed in a larger context of working literature, we did not report an unfiltered database yield; instead, identification is defined as the set of BYOAI-relevant records carried forward for screening. Candidate records were initially screened using their titles, abstracts, and full texts, excluding those deemed
The extraction process for each study identified within this systematic review was coded using an organized extraction form with respect to the six categories contained within the BYOAI Risk Taxonomy and the four framework families(NIST AI RMF, AI TRiSM, ethical/responsible AI frameworks and technical controls). Rule 1, Risk coding. A risk category was coded as present only when a study substantively examined that construct, not when it was mentioned in passing. A study could be included for behavioral or contextual value, but could not contribute to the risk-frequency counts. Rule 2, Framework coding. A framework was coded only when a study substantively evaluated, applied, compared, or operationalized it; a mere citation was insufficient. This distinction between mentioning and using a framework yields a more defensible and reproducible basis for the framework analysis. Reporting consequence. Because standards and framework documents are evaluated as objects of analysis rather than risk studies, they are excluded from the risk-frequency denominator. Of the N = 30 included records, M = 24 were riskeligible; risk frequencies (Table I) are reported against M , while the framework engagement(Table II) is reported against N.
TABLE I BYOAI R ISK C ATEGORY F REQUENCY (M = 24 R ISK -E LIGIBLE S TUDIES ) Risk Category # Studies % of M Data Exposure / Privacy 14 58 Compliance / Legal 11 46 Governance Drift / Visibility 10 42 Hallucination / Output Risk 9 38 IP / Confidentiality 6 25 Bias / Fairness 6 25 % of M = proportion of the 24 risk-eligible studies coding each category.
TABLE III M ATURITY L EVELS M APPED TO THE T HREE C ONTROL P ILLARS Level L1 Prohibition L2 Awareness L3 Guardrails
Technical —
L4 Integrated
+ CASB, SSPM, named IAM (runaccountability; time/TRiSM) HITL verification + CIEM; full integration continuous monitoring, auto-enforce.
TABLE II F RAMEWORK E NGAGEMENT ACROSS I NCLUDED S TUDIES (N = 30) Framework # Studies % of N Technical Controls 9 30 Ethical / Responsible AI 8 27 NIST AI RMF 6 20 AI TRiSM 3 10 % of N = proportion of all 30 included records engaging each framework.
L5 Optimized
DSPM (limited scanning) DSPM, DLP, SWG
Governance policy / ban only informal guidance approved workflows
Human — — role-specific training; sanctioned pathway —
reporting-andlearning culture
V. G OVERNANCE A RTIFACT AND PARAMETERIZED M ODEL IV. R EVIEW F INDINGS A. BYOAI Risk Categorization Frequencies (RQ1) Table I reports how frequently each risk category was substantively examined in the 24 risk-eligible studies. Data exposure and privacy leakage dominate, appearing in well over half the corpus, followed by a cluster of compliance, governance-drift, and hallucination risks. Intellectual-property and bias concerns appear less frequently, often embedded within broader discussions of data protection or ethics. This distribution reflects where the reviewed literature concentrates its attention; it indexes research emphasis rather than realworld incidence. B. Framework Engagement (RQ2) Table II reports how many included studies substantively engaged each framework family, applying Rule 2. Technical controls and ethical/responsible-AI frameworks are engaged most often, while AI TRiSM is engaged by comparatively few studies and NIST AI RMF by a moderate number. This uneven engagement indicates that the literature treats no single framework as a complete answer to BYOAI, and that the frameworks most oriented toward model internals are least represented in a setting where the model is not organizationowned. The magnitude of this gap—not just its unevenness—is quantified as the Framework Gap Index in Section V, where the enforceable share of nominal framework coverage under BYOAI falls to roughly one quarter. Table II reports framework engagement (whether a study substantively evaluates or applies a framework), a direct coding output. The finer framework-by-risk coverage matrix used as an input to the model (Section V) is an analytical assessment defined by the authors informed by the reviewed literature, and is labeled as such rather than presented as a coding result.
A. Three-Pillar Control Model (RQ3) The reviewed evidence confirms that BYOAI cannot be governed solely by any single form of control. Therefore, we organize safeguards into three complementary pillars. The technical pillar (DSPM, CASB, DLP, SSPM, IAM, CIEM, SWG) governs where data and access leave organizational visibility. The governance pillar provides policy and legal or contractual controls (e.g., vendor no-training clauses and business associate agreement gating) as well as providing the necessary mechanisms to assign accountability and to provide human-in-the-loop verification. The human pillar addresses the sociotechnical drivers of adoption (role-specific and workflow embedded training, sanctioned enablement that creates compliant use as the most convenient option, nearmiss reporting, and creating a culture in which compliant use is modeled rather than penalized). The three pillars are interdependent since each addresses types of risk that the other two pillars do not: technical controls prevent data egress but not fabricated output; governance assigns accountability but it does not change behaviors; and human controls reduce the incentive to reach for personal tools in the first place. The ladder advances all three pillars in parallel, summarized in Table III. Early levels rely on policy or informal guidance alone, leaving the drivers of BYOAI unaddressed, while Levels 3–4 combine technical controls with governance mechanisms such as human-in-the-loop verification and human-pillar enablement. Level 5 integrates all three pillars under continuous oversight and a reporting-and-learning culture that reduces the incentive for BYOAI rather than simply blocking it. B. Model Design and Parameter Provenance The model is deterministic and parameterized, not empirical: it shows directionality of the effect rather than measured magnitudes, without parameter distributions or repeated runs (Section VIII). We deliberately limit our focus to only the
technical pillar where there exists a defendable coverage metric for its control families. The Technical Control Coverage Score (TCCS) is used to measure this. The governance and human pillars are handled qualitatively throughout this paper because their effects (training efficacy, accountability, cultural change) cannot be parameterized like the technical layer, and assigning them mitigation weights would manufacture unsupported precision. Their role is captured in the maturity ladder and the case mapping rather than in the numeric output. The model represents a causal chain where the governance level determines what control families are active; the active stack determines technical-control coverage (TCCS); coverage determines security outcomes (exfiltration risk, detection latency, attack-surface breadth); and those outcomes, with framework coverage, determine the residual FGI and composite CGS. Each control family reduces residual risk in each axis area that it primarily addresses, based on a Zero-Truststyle model that assumes no single control provides end-toend protection. Model parameters fall into two provenance classes: values informed by published research or industry reports, and explicitly stated modeling assumptions. These include per-family mitigation weights (DLP, CASB, IAM sector studies), detection-latency anchor (breach-dwell time reporting), framework coverage assessment, and coded risk frequencies (Section IV). C. Metric Definitions The Technical Control Coverage Score is the share of the seven canonical control families – DSPM, CASB, DLP, SSPM, IAM, CIEM, and SWG active at a maturity level: active control families . (1) TCCS = 7 Rather than nominal coverage, the Framework Gap Index measures the gap in enforceable coverage under BYOAI. Because the frameworks target AI owned by organizations, only a fraction α of their nominal best-of-framework coverage is enforceable when the account is owned by employees. The baseline gap (Level 1) is α · coverednominal FGI0 = 1 − , α = 0.25. (2) total As maturity rises, technical controls restore enforceability, closing a compensable fraction of the baseline gap in proportion to TCCS: FGI(ℓ) = FGI0 · 1 − 0.90 · TCCS(ℓ) . (3) This avoids a pitfall: a nominal measure would report high baseline coverage and contradict the paper’s premise. The enforceability form instead yields a large baseline gap (FGI0 ≈ 0.77, only ≈23% enforceable) that narrows only as controls deploy, consistent with the finding that frameworks alone do not govern AI owned by employees. The Composite Governance Score combines risk mitigation R (mean fractional reduction across the three outcome axes), governance alignment C = 1 − FGI, and technical deployment T = TCCS: CGS = 1 + 4 (w1 R + w2 C + w3 T ),
(4)
TABLE IV S ENSITIVITY E NVELOPE OF FGI AND CGS ACROSS α ∈ [0.15, 0.40] AND CGS W EIGHT V ECTORS ON THE VALID S IMPLEX (BASELINE , PLUS R-, C-, AND T- HEAVY E XTREMES ). D IRECTION IS I NVARIANT; ONLY M AGNITUDE VARIES .
FGI (min) FGI (max) CGS (min) CGS (max)
L1 0.63 0.86 1.11 1.88
L2 0.55 0.75 1.63 2.29
L3 0.39 0.53 2.61 3.11
L4 0.14 0.20 3.77 4.23
L5 0.06 0.09 4.07 4.66
with (w1 , w2 , w3 ) = (0.40, 0.30, 0.30). Because C reflects enforceable alignment, an ungoverned Level 1 environment scores near the floor (CGS ≈ 1.3), which is not misleadingly high. D. Model Results (RQ4) Figures 2 and 3 trace the model’s behavior at the five maturity levels. By construction, stacking control families raises TCCS from 0% to 100% across the ladder; this rise is a design property of the maturity mapping (Table III). The model’s substantive output is how that coverage propagates through the chain: as TCCS rises, CGS climbs from 1.3 to 4.3 on a 1–5 scale, while residual FGI falls from 0.77 to 0.08, so that only about a quarter of the nominal framework coverage is enforceable under ungoverned BYOAI, and technical controls progressively restore it. The steepest transitions occur entering Level 3, when data-centric controls (DSPM, DLP) first come online, and Level 4, as identity and cloud-access controls integrate. Exact per-level values follow deterministically from the parameters and equations specified above. Because the direction of these trends is structurally guaranteed rather than tuned, we swept the applicability factor α across [0.15, 0.40] and the CGS weights across the valid simplex, including R-, C-, and T-heavy extremes. Across all combinations, FGI decreases and CGS increases monotonically at every level (Table IV); the parameters shift the magnitude of the curves but never their direction. This invariance is structural: α enters only through the Level-1 baseline FGI0 and cannot reverse the TCCS-driven decline, while any nonnegative weights summing to one preserve the monotonic rise of a composite of three increasing quantities. The envelope is widest at Level 1 (FGI 0.63–0.86; CGS 1.11–1.88) and narrows by Level 5 (FGI 0.06–0.09; CGS 4.07–4.66), where deployed controls dominate the parameter choice. VI. R ETROSPECTIVE C ASE M APPING This section maps four documented incidents and one healthcare-sector pattern of non-sanctioned or personal AI use onto the risk taxonomy and maturity ladder. The analysis is retrospective and conditional: the framework was not executed against these incidents, and no claim is made that it would have prevented them. The cases are organized by layering thesis, technical-layer interception, governance-layer interception, and cases requiring both because the recurring lesson is that no single layer is sufficient.
TABLE V C ROSS -C ASE M APPING TO R ISK AND THE T HREE C ONTROL P ILLARS Case (sector, year) Samsung (tech, 2023) Mata (legal, 2023) Heppner (legal, 2026) Comm. Bank (bank, 2026) Healthcare (pattern)
Primary risk Data Exp.; IP Hallucination IP/Confid. Compliance Compliance
Pillar(s) needed Technical + Human Governance Governance + Human Technical + Governance Technical + Governance
B. Governance-Layer Interception: Legal Sector
Fig. 2. Governance maturity progression. CGS on its native 1–5 scale (left axis); TCCS (%) and FGI×100 share the right axis. TCCS increases by construction; CGS and FGI move accordingly across levels.
Two legal-sector incidents illustrate risks that data-centric controls cannot detect. In Mata v. Avianca (2023), an attorney filed a brief with fabricated judicial decisions produced by ChatGPT; the court imposed sanctions [32]. This engages Hallucination/Output Reliability, which DLP and CASB cannot catch because nothing sensitive leaves the organization; only a governance-layer human-verification workflow (Levels 4– 5) helps, corroborating the Section IV finding that technical controls do not cover hallucination. In Heppner (2026), a court ruled that the case-strategy materials a defendant entered into a consumer AI assistant were not protected by attorney-client privilege or work-product doctrine [33], creating confidentiality and discoverability exposure. Here, the act of input is itself the harm; the safeguards are governance-layer usage rules and training. Together, the pair shows that the legal sector needs governance controls at both the input and output ends of AIassisted work. C. Both Layers Required: Banking and Healthcare
Fig. 3. Security outcomes decline as maturity increases: exfiltration risk, detection latency, and attack surface (normalized).
A. Technical-Layer Interception: Samsung (2023) After Samsung allowed ChatGPT use in 2023, three engineers submitted proprietary semiconductor source code, defect-detection algorithms, and a confidential meeting transcript within roughly twenty days; the company responded with a blanket ban [31]. Although this case used an authorized rather than a private account application, it illustrates the data exfiltration process that is fundamental to BYOAI. The above case involves two risk areas: Data Exposure/Privacy and IP/Confidentiality. The organization was at maturity Levels 1 – 2, as evidenced by their outright ban — also a Level 1 posture. Data-focused controls introduced across maturity Levels 3–4 (DSPM, DLP, SWG, then CASB) are the types of tool that can flag or block similar attempts to send such files or data. Unfortunately, the technical solution is incomplete, as engineers can find an alternative to sanctioned options simply because they can complete their task more effectively via an unauthorized tool, and banning the tool does nothing to eliminate the reason engineers chose to use it. The human pillar, a sanctioned capable pathway plus role-specific training, is what would reduce recurrence, and its absence is why prohibition alone is the weakest posture.
A named banking incident and a healthcare pattern require governance and technical controls together. In a community bank (2026), an employee used a personal account and device to upload customer names, Social Security numbers, and dates of birth to an unapproved AI application; the institution treated the event as material and filed an SEC Form 8-K [34], then blocked unapproved AI domains and tightened data access. This BYOAI event exercises Compliance/Legal and Data Exposure, and its remediation reveals the required layers: domain blocking (CASB/SWG) and access tightening (IAM) alongside a governance pathway giving employees a compliant tool. Both layers must be repeated on a scale in healthcare, where personnel paste protected health information into consumer tools that generally do not sign a BAA under the Health Insurance Portability and Accountability Act (HIPAA) [35]; a BAA-gated approval process (governance) must be enforced by classification and DLP (technical), as neither suffices alone. Synthesis of three pillars. Reading through the pillars, the cases show that the layer positioned to intercept a risk is rarely the layer that addresses its cause. Technical controls would have flagged the Samsung and banking data egress, but the behavior that produced them, employees reaching for capable personal tools under time pressure, is a human-pillar problem: survey evidence on shadow adoption reports that a majority use unsanctioned tools despite knowing the policy, and that
most workplace AI users first adopt the tool outside work [1, 13]. Governance controls are the only layer that reaches the Mata and Heppner failures, which leave no technical trace. And no pillar substitutes for another: prohibition without a sanctioned pathway and training merely converts visible use into concealed use. The maturity ladder therefore advances all three pillars together, and the central finding, that effective BYOAI governance is layered, extends from two layers to three once the behavioral driver of adoption is taken seriously. All counterfactual statements are conditional descriptions of where controls would be positioned, not claims that the framework would have prevented the actual events; details are drawn from public reporting and, where available, primary artifacts (the court ruling in Mata, the SEC Form 8-K in the banking case). VII. D ISCUSSION Reading through RQ1–RQ4, the review and model tell a consistent story. Data-centric risks dominate (RQ1), and four of the five mapped cases turn on regulated or proprietary data leaving organizational control. The engagement of the framework is uneven (RQ2): technical controls and ethical frameworks are used the most, AI TRiSM the least, and no framework is treated as complete. The maturity model (RQ3– RQ4) shows why layering matters: because TCCS rises by construction as controls stack, the model’s substantive output is that CGS rises and FGI falls in step—but meaningfully only once controls combine, echoing Zero-Trust reasoning that no single control, and once the human pillar is included no single pillar, suffices. Two cautions are followed. First, prohibition (Level 1) leaves residual risk near baseline because it does not address the motivations that drive personal AI use; the case evidence reinforces this, since several organizations reached bans that addressed the tool rather than the exposure pathway or the need for the underlying task. Second, partial governance provides partial protection only, and a false sense of security itself is a risk. Because FGI falls most when technical controls supplement frameworks, security teams can use CGS, FGI, and TCCS trends to justify phased, identity, and data-centric investments while preserving productivity. For practitioners, the three pillar view implies that prohibition alone is the weakest posture, that technical visibility (DSPM linking identity, classification, and cloud-access telemetry) is foundational but cannot reach output-reliability or input-confidentiality failures, and that the maturity ladder should advance all three pillars together as a portfolio rather than a menu. VIII. L IMITATIONS AND F UTURE W ORK This model is directional and parameterized rather than empirical. It uses fixed parameters selected by the authors without distributions or repeated runs, so it is a parameterized scoring model, not a stochastic simulation; we do, however, report a sensitivity analysis over α and the CGS weights (Table IV) confirming the reported trends are direction-invariant. Risk frequencies derive from 24 risk-eligible studies in a curated
30-record corpus assembled from a broader collection rather than an exhaustively logged database export, so complete search coverage is not claimed. Coding was performed by a single researcher, precluding inter-rater reliability; the reported percentages therefore index relative emphasis across the corpus rather than precise population estimates, and the small denominator (M = 24) means individual proportions should be read as approximate. The explicit coding rules in Section III (the present/absent decision rule and the substantiveengagement rule) constrain each judgment and make the scheme reproducible in principle; independent double-coding with a formal agreement statistic (e.g., Cohen’s κ) is a priority for future work. The model quantifies only the technical pillar, while the governance and human pillars, along with the framework-by-risk coverage matrix that feeds the FGI, are treated qualitatively or as analytical input. Mitigation weights, the applicability factor α, and the detection-latency and attack-surface axes are modeled rather than observed, and the case mapping is retrospective and conditional rather than a test of prevention. Reported values are therefore meaningful in direction and relative magnitude rather than as absolute measurements. Finally, the corpus is weighted toward sources published through 2023–2026, whereas organizational AI governance is evolving rapidly; some control gaps identified here may already be addressed at more mature organizations, while others remain open, so the risk landscape should be read as a snapshot of the reviewed period rather than a current-state census. These limitations motivate the next steps. The most direct is empirical instantiation in a controlled lab, a local LLM, a simulated corporate document store, scripted employee interactions representing the risk taxonomy, and a detection layer, run across the three environments to replace assumed parameters with observed exfiltration rates, detection latencies, and attack-surface measures. Extending the sensitivity analysis to the per-family mitigation weights and to distributional rather than point parameter estimates would characterize uncertainty around the current single-point estimates. Further work includes survey and interview validation of the taxonomy, longitudinal case studies tracking organizations as they climb the ladder, adversarial and regulatory-shift scenarios, and privacypreserving detection of personal AI use. IX. C ONCLUSION BYOAI introduces visibility gaps, compliance exposure, and inconsistent model behavior that current frameworks address only partially. This paper contributes a governance model grounded in a systematic review and expressed through a reproducible parameterized model, complemented by a retrospective mapping of four documented incidents and a healthcare-sector pattern. The evidence shows that effective BYOAI governance is cumulative and layered across three complementary pillars, technical, governance, and human. Prohibition alone leaves residual risk near baseline; integrated data- and identity-centric controls reduce exfiltration risk, shorten detection latency, and restore enforceable coverage;
but only the addition of accountability structures and humanpillar enablement reaches the output-reliability, confidentiality, and adoption-driver risks that technical controls cannot. AI T OOLS U SED Overleaf’s AI writing assistant was used during the preparation of this manuscript to assist in grammar and spelling.
[17] [18]
[19]
R EFERENCES [1] [2]
[3] [4] [5]
[6] [7] [8] [9] [10] [11] [12] [13] [14]
[15] [16]
T. Anthuvan et al., “Bring your own AI (BYOAI) in the workplace: Patterns, pitfalls, and the BYOAI-Gov toolkit for behavior-aware governance,” SSRN, Working Paper, 2025. DOI: 10.2139/ssrn.5394886 T. Chin, Q. Li, F. Mirone, and A. Papa, “Conflicting impacts of shadow AI usage on knowledge leakage in metaverse-based business models: A Yin-Yang paradox framing,” Technol. Soc., vol. 81, p. 102 793, 2025. DOI : 10.1016/j.techsoc.2024.102793 S. Bankins, A. C. Ocampo, M. Marrone, S. L. D. Restubog, and S. E. Woo, “A multilevel review of artificial intelligence in organizations,” J. Organ. Behav., vol. 45, no. 2, 2024. DOI: 10.1002/job.2735 E. Brynjolfsson, D. Li, and L. R. Raymond, “Generative AI at work,” NBER, Working Paper 31161, 2023. DOI: 10.3386/w31161 A. Y. Balogun et al., “The ethical and legal implications of shadow AI in sensitive industries: A focus on healthcare, finance and education,” J. Eng. Res. Rep., vol. 27, no. 3, pp. 1–22, 2025. DOI: 10.9734/jerr/ 2025/v27i31414 J. Ross, L. Hibbert, and E. Moss, “Shadow AI: Governance, risk, and organisational resilience,” in Int. Conf. Artif. Intell., Comput., Data Sci. Appl. (ACDSA), 2025. DOI: 10.1109/ACDSA65407.2025.11166415 N. van der Meulen and B. H. Wixom, Bring your own AI: How to balance risks and innovation, MIT Sloan Management Review, 2024. T.-H. Kim, “Security challenges and ethical considerations in the adoption of generative AI technology,” J. Korean Inst. Inf. Technol., vol. 23, pp. 31–42, 2025. IBM Security, “X-Force Threat Intelligence Index 2026,” IBM, Tech. Rep., 2025. [Online]. Available: https://www.ibm.com/forms/mkt1f268 National Institute of Standards and Technology, “Artificial intelligence risk management framework (AI RMF 1.0),” Tech. Rep. NIST AI 1001, 2023. DOI: 10.6028/NIST.AI.100-1 L. Floridi et al., “AI4People: An ethical framework for a good AI society,” Minds Mach., vol. 28, pp. 689–707, 2018. DOI: 10 . 1007 / s11023-018-9482-5 P. P. Ray, “A review of TRiSM frameworks in artificial intelligence systems: Fundamentals, taxonomy, use cases, key challenges and future directions,” Expert Syst., vol. 43, no. 3, 2026. DOI: 10.1111/exsy.70213 J. Waters-Lynch, D. W. E. Allen, J. Potts, and C. Berg, “Managing generative AI in firms: The theory of shadow user innovation,” SSRN, Working Paper, 2024. DOI: 10.2139/ssrn.4754950 UNESCO, “Recommendation on the ethics of artificial intelligence,” UNESCO, Tech. Rep., 2021. Accessed: Aug. 21, 2026. [Online]. Available: https : / / unesdoc . unesco . org / in / rest / annotationSVC / DownloadWatermarkedAttachment / attach import 75c9fb6b - 92a6 4982-b772-79f540c9fc39? =381137eng.pdf National Institute of Standards and Technology, “NIST Privacy Framework 1.1 (initial public draft),” Tech. Rep. NIST CSWP 40 ipd, 2025. DOI : 10.6028/NIST.CSWP.40.ipd A. Bodnari and J. Travis, “Scaling enterprise AI in healthcare: The role of governance in risk mitigation frameworks,” npj Digit. Med., vol. 8, 2025, Art. no. 272. DOI: 10.1038/s41746-025-01700-4
[20]
[21] [22] [23] [24] [25]
[26] [27] [28] [29] [30]
[31]
[32] [33]
[34] [35]
B. W. Wirtz, J. C. Weyerer, and I. Kehl, “Governance of artificial intelligence: A risk and guideline-based integrative framework,” Gov. Inf. Q., vol. 39, no. 4, 2022. DOI: 10.1016/j.giq.2022.101685 A. Habbal, M. K. Ali, and M. A. Abuzaraida, “Artificial intelligence trust, risk and security management (AI TRiSM): Frameworks, applications, challenges and future research directions,” Expert Syst. Appl., vol. 240, p. 122 442, 2024. DOI: 10.1016/j.eswa.2023.122442 E. Papagiannidis, P. Mikalef, and K. Conboy, “Responsible artificial intelligence governance: A review and research framework,” J. Strateg. Inf. Syst., vol. 34, no. 2, p. 101 885, 2025. DOI: 10.1016/j.jsis.2024. 101885 L. Tangi, A. P. R. Müller, and M. Combetto, “A silent partner: The shadow presence of generative artificial intelligence in public administrations,” in Electronic Participation (ePart 2025), ser. Lecture Notes in Computer Science, vol. 15978, 2026, pp. 69–86. DOI: 10 . 1007/978-3-032-02515-9 5 R. Mahanti, “Introduction to governance, corporate governance, and compliance,” in Data Governance and Compliance, Springer, 2021. DOI : 10.1007/978-981-33-6877-4 1 National Institute of Standards and Technology, “Risk management framework for information systems and organizations,” Tech. Rep. NIST SP 800-37 Rev. 2, 2018. DOI: 10.6028/NIST.SP.800-37r2 K. Downer and M. Bhattacharya, “BYOD security: A study of human dimensions,” Informatics, vol. 9, no. 1, p. 16, 2022. DOI: 10 . 3390 / informatics9010016 T. W. Kwan, “Navigating the risks of shadow AI,” ITNOW, vol. 66, no. 2, pp. 42–43, 2024. DOI: 10.1093/itnow/bwae054 A. O. Akinade, P. A. Adepoju, A. B. Ige, and A. I. Afolabi, “Cloud security challenges and solutions: A review of current best practices,” Int. J. Multidiscip. Res. Growth Eval., vol. 6, no. 1, pp. 26–35, 2025. DOI : 10.54660/.ijmrge.2025.6.1.26-35 National Institute of Standards and Technology, “Artificial intelligence risk management framework: Generative AI profile,” Tech. Rep. NIST AI 600-1, 2024. DOI: 10.6028/NIST.AI.600-1 OWASP, OWASP Top 10 for large language model applications 2025, 2024. [Online]. Available: https://genai.owasp.org/llm-top-10/ Y. Zeng et al., AI risk categorization decoded (AIR 2024): From government regulations to corporate policies, arXiv:2406.17864, 2024. A. Diro et al., “Workplace security and privacy implications in the GenAI age: A survey,” J. Inf. Secur. Appl., vol. 89, p. 103 960, 2025. DOI : 10.1016/j.jisa.2024.103960 M. Hornung and S. Smolnik, “AI invading the workplace: Negative emotions towards the organizational use of personal virtual assistants,” Electron. Mark., vol. 32, pp. 123–138, 2021. DOI: 10.1007/s12525021-00493-0 S. Ray, Samsung bans ChatGPT among employees after sensitive code leak, Forbes, 2023. [Online]. Available: https://www.forbes.com/sites/ siladityaray/2023/05/02/samsung- bans- chatgpt- and- other- chatbotsfor-employees-after-sensitive-code-leak/?utm source=chatgpt.com Mata v. Avianca, Inc. 678 F. Supp. 3d 443 (S.D.N.Y. 2023), 2023. E. X. Guo, United states v. heppner, Harvard Law Review Blog, Published Mar. 23, 2026. No. 25-cr-00503-JSR (S.D.N.Y. 2026), Mar. 2026. [Online]. Available: https://harvardlawreview.org/blog/2026/03/ united-states-v-heppner/ CB Financial Services, Inc., Current report (form 8-k), U.S. Securities and Exchange Commission, Filed May 7, 2026. Analyzed in Wilson Sonsini Goodrich & Rosati (analysis, 2026), May 2026. S. Alder, Healthcare workers violating patient privacy by uploading sensitive data to GenAI and cloud accounts, HIPAA Journal, May 2025.