Somewhere in your business right now, someone is pasting something into an AI chatbot. A contract they want summarised. A spreadsheet of customer records they want cleaned up. An awkward email to a client they want help rewriting. A block of code from an internal system that will not compile.
They are not being reckless. They are trying to get their work done, using a tool that is genuinely good at helping them do it. That is precisely what makes shadow AI harder to manage than the shadow IT problems that came before it.
Why This Is Different From Previous Shadow IT
When employees started using personal Dropbox accounts for work files, the fix was relatively clean: provide a sanctioned alternative, block the unsanctioned one, move on. Shadow AI resists that approach for three reasons.
- The benefit is immediate and obvious. A task that took forty minutes takes five. Employees are not going to give that up because a policy told them to, and frankly they should not have to.
- It is invisible in the places you normally look. No software gets installed. No new device joins the network. It is a browser tab, indistinguishable from any other, and increasingly it is a feature quietly embedded in software you already pay for.
- The boundary is genuinely blurry. "Help me phrase this" is harmless. "Summarise this client agreement" may not be. Most employees cannot reliably tell you where the line falls, because nobody has told them.
What Actually Goes Wrong
The risk here is not hypothetical, but it is also not the Hollywood version. Realistically, four things go wrong.
Confidential data leaves your control
The core issue is simple: information pasted into a third-party service has left your environment. Where it goes next depends entirely on that provider's terms: whether it is retained, how long for, who can access it, and whether it may be used to train future models. Those terms vary enormously between consumer and business tiers of the very same product, and most employees have never read either.
You inherit obligations you did not agree to
If the pasted content includes personal data, health information, payment details or material covered by a client confidentiality agreement, you may have created a disclosure you are contractually or legally answerable for. The employee did not intend a disclosure. That rarely matters afterwards.
Confident, plausible, wrong output
AI tools produce fluent text regardless of whether the underlying claim is correct. Used as an assistant by someone who can evaluate the output, this is fine. Used as an authority by someone who cannot (a quoted figure, a cited regulation, a legal interpretation), it introduces errors that are unusually hard to catch, precisely because they read so well.
Credentials and keys in the paste buffer
When someone pastes a configuration file or a stack trace to ask why something is failing, connection strings, API keys and internal hostnames frequently come along for the ride.
The accounting reality
Most shadow AI use runs through personal accounts, which means it does not appear on any invoice you control. You cannot audit it, you cannot apply your retention rules to it, and when the employee leaves, whatever they put in there leaves with them, still sitting in an account you have no access to.
Why Banning It Backfires
The instinct is to block the domains and issue a policy. It is an understandable instinct, and it fails in a specific, predictable way.
Blocking the well-known sites at the firewall does not remove the demand. It just moves the activity to phones, home machines and the growing set of AI features embedded inside tools you have already approved. You lose the one thing you actually had: some visibility into what people are doing.
Worse, a blanket ban makes the employee's decision binary. Rather than asking whether a particular document is appropriate to share, they are simply breaking a rule they think is unreasonable, which means they stop telling you anything at all.
A policy that employees quietly route around is worse than no policy, because it produces the illusion of control while removing your visibility.
A Workable Approach
1. Find out what is actually happening
Before writing anything, get a realistic picture. Which tools are in use, by which teams, for what kinds of work? Ask openly rather than investigating quietly. You will get far better information, and you will need cooperation for everything that follows. Most businesses find the usage is broader and more mundane than they expected.
2. Provide a sanctioned option
This is the step that makes the rest work. Business and enterprise tiers of the major AI services typically offer materially different data handling from their consumer counterparts, commonly including commitments not to train on your content, administrative controls, and audit visibility. If you provide a good tool through a business account, the incentive to use a personal one largely evaporates.
3. Classify by data, not by tool
Write guidance around what may be shared, not which product is allowed. Something close to three tiers works for most businesses:
- Fine to share: public marketing copy, general drafting, publicly documented technical questions, brainstorming.
- Approved tools only: internal documents, non-sensitive business data, anything customer-adjacent but not identifying.
- Never: credentials and keys, personal or health data, payment details, anything under client confidentiality, unreleased financials, legal matters under privilege.
Concrete examples beat abstract categories. "Do not paste a customer list" lands where "exercise appropriate judgement regarding sensitive data" does not.
4. Make review mandatory for anything that leaves
AI-generated content that goes to a client, a regulator or the public needs a human who is accountable for its accuracy. Not a proofread, but an actual check of the claims by someone qualified to evaluate them.
5. Revisit it regularly
This area moves quickly. Tools change their data-handling terms, and AI features keep appearing inside software you already own, often enabled by default. A policy written once and filed away will quietly stop matching reality within a couple of quarters.
Where to Start
If none of this exists in your business yet, the first move is not a document. It is a conversation with your team about what they are already using and what it is genuinely helping them do. You will learn more in twenty minutes of honest discussion than from any amount of network log analysis, and you will find out which tools are worth paying for properly.
The businesses handling this well are not the ones with the strictest rules. They are the ones that gave people a good sanctioned option, explained clearly what must never be shared, and made it easy to ask when something falls in between.
Need an AI Policy That People Will Actually Follow?
We help businesses work out what is already in use, choose tools with appropriate data protections, and put practical guardrails in place.
Talk to Our Team