W-9 Elena Cho.pdf
Form W-9
Request for Taxpayer ID
- Name
- Elena Cho
- SSN
- 219-09-9999
- Address
- 14 Mercer St
Human-initiated Shadow AI
Employees use unsanctioned models through the browser, desktop apps, computer-use sessions, and cowork tools. They paste, screenshot, or upload prohibited or sensitive material. Cortex detects that activity and can block it.
Policy library
Catches: SSN pasted into a personal ChatGPT tab.
Catches: .env or wire key dropped on the composer.
Catches: A W-9 scan dropped or screenshotted into ChatGPT.
Catches: Positions leave through a personal tab after MCP deny.
On her desktop
ChatGPT
Maya VossSupport
Elena Cho's onboarding is blocked on a missing W-9.
I can extract name, TIN, and address if you share the form.
Compliance wants it on the file today. The scan is on my desktop.
A clear scan is enough. I will type the fields and flag anything unreadable.
Need this W-9 cleaned for her onboarding file.
Attach the form and I will extract the fields.
Clean this W-9 for onboarding
↑Observed
Agent-initiated Shadow AI
At runtime or through assigned tasks, agents access prohibited or sensitive data and either read it or run inference over it: Claude Code, Codex, Grok, and similar tools. Cortex detects these accesses and can block them.
Policy library
Catches: Claude Code reads Elena Cho's book after MCP deny.
Catches: Codex cats .env to debug a Fedwire batch.
Catches: A Grok agent sends the Northshore CIM from Slack.
$ claude
> Pull Elena Cho's full book and give me the position weights, custody account IDs, and anything marked client-confidential.
ReadRESTRICTEDclient-book.xlsx
Restricted file
client-book.xlsx
POL-04 blocked
Policy denied the MCP read. The agent does not receive the client book.
$
Human-initiated and agent-initiated Shadow AI are evaluated against the same policy library. Cortex detects both. When the request is on a controlled path, it can block the read or the inference.
Cortex inventories people, agents, and surfaces from capture. Each row is a session: who initiated it, which model it reached, and the sensitive data that went with it.
Priya NairReleases
Cursor · MCP · client book
Maya VossSupport
Chrome · chatgpt.com
Ravi KapoorRisk
Slack · #deal-room
Kavya DesaiSupport lead
Chrome · chatgpt.com
Policy can deny an MCP connection or a managed tool call. The same client book can be pasted or screenshotted into ChatGPT. Cortex observes that second channel on the capture path.
Priya NairReleases
client_book.positions
01 · Managed path
BlockedCursor · FactSet MCP
POL-04 denied the client-book read.
02 · Unsanctioned path
ObservedChrome · ChatGPT
The same positions were pasted into a prompt.
Each captured session is tagged with a data class. A review can start from personal data, tax records, restricted work product, or secrets, instead of a raw usage count.
Personal data
pii.ssnName, SSN, date of birth
POL-14 · GDPR · GLBA NPI
Tax and account identifiers
tax.w9W-9 scan, TIN, custody account
POL-22 · IRS · PCI
Restricted work product
deal.maCIM, client book, non-public research
POL-19 · confidentiality · MNPI
Secrets and credentials
secretAPI keys, tokens, .env values
POL-31 · credential exposure
Reconstruct Shadow AI activity across human-operated tools, cloud agents, and self-hosted workloads, then carry the same evidence into risk and compliance review.
Human-operated AI
Browser and desktop tools people already use. ChatGPT, Claude, Grok, Cursor, and the rest of the consumer surface.
On-device sensor
Cloud workloads
Hosted agents, provider APIs, and MCP paths: Slack agents, OpenAI, Gemini, GitHub.
Your cloud
Self-hosted
Run capture in your VPC or on-prem. Same inventory, same data classes, inside your boundary.
Your VPC or on-prem
We will map one supported surface and compare approved versus unauthorized egress.