AI Acceptable Use Policy Benchmark: How 15 Sectors Govern 11,890 Generative AI Tools (Shadow AI Governance Statistics, 2026)
Abstract
How strict should an AI acceptable use policy be? This dataset benchmarks generative AI policy across fifteen sectors by applying each sector's AI governance profile to one shared register of 11,890 active AI tools (snapshot 26 September 2026). The sectors are defense and critical infrastructure, K-12 schools, government, banks and financial services, insurers, healthcare, pharma and life sciences, law firms, accounting firms, managed service providers (MSPs), manufacturing, general business, higher education, software companies and marketing agencies. For every sector, each AI tool is classified as block, allow with controls (enterprise licence, SSO, DLP or audit logging) or allow, the three decisions an AI risk management or shadow AI program has to make. What the benchmark shows:- Strictness varies eightfold: 81.6% of AI tools are blocked under the defense profile, 71.5% for K-12 schools, 49.3% for government, and just 10.0% for marketing agencies.- Most regulated sectors (finance, insurance, healthcare, pharma, legal, accounting) cluster at 39–47% blocked, with more than half of AI tools allowed only with controls.- Any two sectors disagree on 41.3% of AI tools on average; only 13.4% of tools are treated the same everywhere.- For K-12 AI policy, 35.4% of decisions come from subcategory rules (for example AI essay writers, voice cloning, AI companions) rather than broad category defaults. Included: sector decision totals, the default AI policy per sector for 18 tool categories, decisions per sector and category, a 105-pair sector disagreement table, cross-sector agreement, and the full K-12 AI policy matrix with rationale for 165 subcategories. Useful for AI governance frameworks, AI compliance benchmarking, CISO and IT policy planning, AI in education research and responsible AI studies. No domains or per-tool decisions are included. The profiles are normative recommendations, not a survey of current practice.