What shadow AI is
Shadow AI is the use of AI tools without the organisation's knowledge or approval: pasting a contract into a public chatbot, summarising customer emails with a browser extension, or uploading a spreadsheet to an AI analysis site. The intent is usually good. The risk is that confidential or personal information leaves your control.
Find it
- Ask. An anonymous survey of AI use is often the most revealing step.
- Review network and identity logs for AI services.
- Check browser extensions and third-party app consents.
Write a policy people will follow
- Classify information. State plainly which kinds of information may never go into external AI tools.
- Approve tools. List the AI tools that are approved, for which uses and with which settings.
- Require verification. People remain responsible for checking AI outputs.
- Disclose where it matters. Say when AI use must be disclosed to customers or colleagues.
- Provide a request path for new tools, with a fast answer.
Give people a better option
The most effective control is an approved tool that is genuinely useful, such as an enterprise AI service with no-training terms or a private assistant over internal knowledge. People choose the safe path when it is also the easy one.
