Source-linked AI summary
Governing Bring Your Own AI: A Parameterized Maturity Model
Dare Bello, John Hastings
TL;DR
BYOAI exposes a governance gap because personal AI accounts operate outside enterprise controls, while existing frameworks were designed for organization-managed AI. The paper combines a systematic review with a parameterized maturity model, finding that layered controls reduce modeled residual risk and increase enforceable coverage, whereas prohibition remains near baseline.
Problem
Existing AI governance frameworks do not directly address the visibility and control gaps created by employee-owned personal AI accounts.
Method
The paper combines a systematic literature review with a five-level maturity ladder and parameterized model linking technical-control coverage to security outcomes and framework gap.
Results
CGS rises from 1.3 to 4.3 while residual FGI falls from 0.77 to 0.08 as TCCS increases across maturity levels.
Takeaways & Limitations
Effective BYOAI governance is layered across technical, governance, and human pillars; prohibition alone leaves residual risk near baseline.
Takeaways & Limitations
The model is directional and parameterized rather than empirical, and the corpus was curated without claiming exhaustive search coverage.
Abstract
from arXiv · showhide
Employees are increasingly using personally owned generative AI tools such as ChatGPT, Gemini, and Claude for their daily work. This practice is known as Bring Your Own AI (BYOAI), which is a distinct form of Shadow AI in which employee-authenticated personal accounts are used outside of enterprise identity and security controls. Existing frameworks were designed for AI tools managed by organizations, and their coverage does not extend to unmanaged AI tools used with a personal account. In addressing these issues, we developed a governance model through a systematic review of the literature that produces a risk taxonomy and a framework-engagement profile. We also developed a parameterized governance model that measures how much a level of governance maturity reduces residual risk. A five-level maturity ladder is coupled to a technical control architecture through a chain in which the coverage of the control layer influences the security outcomes. Our study of a curated corpus of 30 records (24 research studies and 6 framework documents) indicated that the most prominent categories identified were data exposure and compliance, and framework engagement was inconsistent. Three mutually supporting pillars (technical, governance, and human) were established to support safeguards. Additionally, the results of the model demonstrated that prohibition-based solutions will result in residual risk levels close to those achieved through baseline solutions. Under the specified parameterization, layered control-based solutions substantially reduce modeled exfiltration risk and increase enforceable coverage.
I. INTRODUCTION
BYOAI is a distinct Shadow AI problem because employee-owned accounts operate outside enterprise identity, monitoring, and security controls. The paper responds with an evidence-based taxonomy, framework profile, maturity ladder, and parameterized governance model.
- Shadow AI creates risks involving data leakage, misaligned model behavior, and accountability gaps.
- BYOAI uses employee-owned personal AI accounts outside organizational identity systems, network monitoring, and security controls.
- Existing AI governance frameworks offer useful guidance but do not directly address BYOAI’s visibility and control gaps.
- The paper develops an evidence-based risk taxonomy and framework-engagement profile from a systematic literature review.
- The paper couples a five-level governance maturity ladder with technical controls and a parameterized model of residual risk.
- The study asks which risks characterize BYOAI, how completely frameworks cover them, which controls reduce residual risk, and how maturity can be quantified.
II. BACKGROUND AND RELATED WORK
BYOAI extends Shadow IT concerns because personal AI accounts limit organizational visibility into data handling, model behavior, and retention. The paper positions its control architecture as a complementary response to incomplete framework coverage.
- BYOAI differs from earlier shadow technologies because personal accounts limit insight into shared data, storage, reuse, and output effects.
- Existing frameworks provide foundational elements but do not fully cover BYOAI conducted through employee-owned accounts.
- The paper’s model quantifies residual risk at each maturity level through a chain from technical-control coverage to security outcomes and framework gap.
- The technical pillar includes DSPM, CASB, DLP, SSPM, IAM, CIEM, and SWG control families.
- Runtime inspection and AI TRiSM functions support upper maturity levels by monitoring interactions and abnormal model behavior.
- Higher maturity levels progressively combine control families rather than relying on a single control.
III. RESEARCH METHODOLOGY
The study combines a systematic literature review with a design-science artifact. The review establishes the evidence base, while the model uses those findings and explicit assumptions to examine how maturity affects residual risk.
- The systematic literature review produces a BYOAI risk taxonomy and framework-engagement profile.
- The design-science model uses review findings and stated assumptions to demonstrate how governance maturity affects residual risk.
- The review-plus-model design addresses the scarcity of primary telemetry because BYOAI activity occurs largely outside enterprise logging.
A. Search Strategy
The review searched multiple scholarly sources with structured criteria and citation chaining, then screened records into a curated corpus. The included corpus contained 30 records, but exhaustive-search completeness was not claimed.
- Search Strategy: The search used IEEE Xplore, Scopus, and Google Scholar with Boolean concept blocks covering BYOAI, generative AI, and governance.
- Search Strategy: Records were included when they addressed organizational shadow or personal AI use or directly applicable governance and controls, subject to publication and language criteria.
- Search Strategy: Candidate records were supplemented through backward and forward citation searching before screening.
- Search Strategy: 30 records were included, comprising 24 research studies and 6 framework or standard documents.
- Search Strategy: The review does not claim exhaustive search completeness because identification came from a curated collection rather than one reproducible database export.
D. Coding Procedure
The review used predefined coding rules to distinguish substantive treatment of risks and frameworks from passing mentions. It analyzed risk frequencies among 24 risk-eligible studies and framework engagement across all 30 included records.
- The extraction form coded six BYOAI risk categories and four framework families.
- Risk categories counted only when studies substantively examined them, excluding passing mentions from frequency counts.
- Frameworks counted only when studies evaluated, applied, compared, or operationalized them, making the analysis more reproducible.
- 30 included records comprised 24 risk-eligible studies and 6 framework or standard documents.
- Risk frequencies used M = 24 as the denominator, whereas framework engagement used N = 30.
A. BYOAI Risk Categorization Frequencies (RQ1)
The literature review found that data exposure and privacy leakage received the greatest attention, while framework engagement was uneven and no single framework served as a complete answer. Safeguards therefore combine technical, governance, and human pillars across maturity levels.
- Risk frequencies: Data exposure and privacy leakage dominated the reviewed risk literature, while compliance, governance drift, and hallucination formed the next prominent cluster.
- Framework engagement: Framework engagement was uneven: technical controls and responsible-AI frameworks appeared most often, AI TRiSM comparatively rarely, and NIST AI RMF moderately.
- Framework engagement: The enforceable share of nominal framework coverage under BYOAI fell to roughly one quarter.
- Three-pillar safeguards: BYOAI safeguards are organized into interdependent technical, governance, and human pillars because no single control form addresses all identified risks.
- Maturity ladder: The maturity ladder advances all three pillars in parallel, with Levels 3–4 combining technical controls and governance mechanisms and Level 5 adding continuous oversight and learning.
B. Model Design and Parameter Provenance
The model is a deterministic, parameterized representation that quantifies technical-control coverage and its modeled relationship to enforceability and governance scores. Governance and human effects remain qualitative because the paper does not assign them unsupported mitigation weights.
- Parameter provenance: The model is directional and parameterized rather than empirical, using fixed author-selected parameters without distributions or repeated runs.
- Parameter provenance: Governance and human pillars are treated qualitatively because their effects cannot be parameterized like the technical layer without manufacturing unsupported precision.
- Metric definitions: Technical Control Coverage Score measures the share of seven canonical control families active at a maturity level.
- Metric definitions: The Framework Gap Index measures enforceable rather than nominal coverage because employee-owned accounts limit framework enforceability.
- Metric definitions: As maturity rises, technical controls close a compensable fraction of the baseline framework gap in proportion to TCCS.
- Metric definitions: The enforceability formulation yields FGI0 ≈ 0.77, meaning only ≈23% of nominal framework coverage is enforceable at baseline.
- Sensitivity analysis: The sensitivity analysis varies α across [0.15, 0.40] and CGS weights across the valid simplex, with direction invariant and only magnitude varying.
- Metric definitions: The Composite Governance Score combines risk mitigation, governance alignment, and technical deployment using weights (w1, w2, w3) = (0.40, 0.30, 0.30).
D. Model Results (RQ4)
The parameterized maturity model shows that increasing technical-control coverage raises governance scores and lowers residual framework gaps. These directional trends remain monotonic across the tested applicability factors and valid CGS weightings.
- CGS rises from 1.3 to 4.3 while residual FGI falls from 0.77 to 0.08 as maturity increases.The model traces these changes across five maturity levels while TCCS increases from 0% to 100% by construction.
- The steepest model transitions occur when data-centric controls enter at Level 3 and identity and cloud-access controls integrate at Level 4.DSPM and DLP first enter at Level 3; identity and cloud-access controls integrate at Level 4.
- Across α∈[0.15, 0.40] and valid CGS weightings, FGI decreases and CGS increases monotonically at every maturity level.The parameter sweep changes curve magnitude but not direction, including R-, C-, and T-heavy extremes.
- The model’s monotonic behavior is structural because α affects only the Level-1 baseline FGI0 and nonnegative weights preserve CGS’s rise.Thus, the tested parameterization cannot reverse the TCCS-driven decline in FGI.
VI. RETROSPECTIVE CASE MAPPING
The retrospective mapping examines documented incidents and a healthcare pattern through the risk taxonomy and maturity ladder. It frames the cases as conditional analyses of where layered controls would intercept different risks, not as evidence that the framework prevented them.
- The case analysis maps four documented incidents and one healthcare-sector pattern onto the risk taxonomy and maturity ladder.The analysis is retrospective and conditional rather than an execution of the framework against the incidents.
- The cases are organized around layering, technical interception, governance interception, and situations requiring both control layers.The recurring lesson is that no single layer is sufficient.
- Figures 2 and 3 accompany the case mapping with maturity-progressions and normalized security-outcome views.Figure 2 presents governance metrics across levels, while Figure 3 presents normalized exfiltration risk, detection latency, and attack surface.
- In the Samsung case, employees submitted proprietary source code, defect-detection algorithms, and a confidential transcript to ChatGPT within roughly twenty days.The incident illustrates data exfiltration involving Data Exposure/Privacy and IP/Confidentiality risks.
B. Governance-Layer Interception: Legal Sector
The legal and cross-case evidence shows that governance-layer controls are needed for failures that data-centric technical controls cannot detect. The discussion therefore treats effective BYOAI governance as a layered portfolio spanning technical, governance, and human measures.
- The Mata v. Avianca incident involved fabricated judicial decisions and sanctions, a failure that DLP and CASB cannot detect because no sensitive data leaves the organization.The passage identifies human-verification workflows at Levels 4–5 as the relevant governance-layer response.
- Technical controls would flag Samsung and banking data egress, while the employee behavior producing those events belongs to the human pillar.The cases connect data-egress interception with the need to address employees’ time-pressured adoption of capable personal tools.
- A majority of surveyed users reportedly use unsanctioned tools despite knowing policy, and most workplace AI users first adopt the tool outside work.These findings support treating behavior and sanctioned pathways as part of the governance problem.
- Governance controls are the only layer that reaches legal-sector failures that leave no technical trace.This contrasts with technical controls that can intercept data egress but not output-reliability failures.
- Prohibition without a sanctioned pathway and training can convert visible use into concealed use rather than addressing the underlying exposure pathway or task need.The maturity ladder consequently advances technical, governance, and human pillars together.
- The discussion identifies prohibition as the weakest posture, while technical visibility remains foundational but cannot reach output-reliability or input-confidentiality failures.CGS, FGI, and TCCS trends are presented as support for phased identity and data-centric investments alongside the other pillars.
VIII. LIMITATIONS AND FUTURE WORK
The model is directional and parameterized rather than empirical, and its evidence base and coding scope constrain how its results should be interpreted. Future work therefore calls for empirical instantiation using observed security measurements.
- Model scope: The model uses fixed author-selected parameters without distributions or repeated runs, so it is a parameterized scoring model rather than a stochastic simulation.Sensitivity analysis over α and the CGS weights confirmed that the reported trends were direction-invariant.
- Evidence base: Single-researcher coding precluded inter-rater reliability, although explicit coding rules make the scheme reproducible in principle.The authors identify independent double-coding with a formal agreement statistic such as Cohen’s κ as a priority for future work.
- Model scope: The model quantifies only the technical pillar, while governance and human pillars are treated qualitatively or as analytical inputs.Mitigation weights, applicability, detection latency, and attack-surface measures are modeled rather than observed, and case mapping is retrospective and conditional rather than a prevention test.
- Future work: Future work should test the model in controlled environments using observed exfiltration rates, detection latencies, and attack-surface measures instead of assumed parameters.The proposed setup includes a local LLM, simulated corporate document store, scripted employee interactions, and a detection layer across three environments.