Your staff already use AI. The question is whether you know what they sent
Somebody in your company pasted a customer contract into a chatbot last week to get a summary. Somebody else used one to rewrite a difficult email to a supplier. Somebody in finance tried it on a spreadsheet of figures they should not have exported.
None of them were being reckless. It helped, it was fast, and nobody had told them where the line was. That is shadow AI, it is the current state in most mid-sized companies, and the interesting question is not whether it is happening.
Why banning it does not work
It is invisible. Personal accounts, personal phones, browser tabs. Blocking a domain moves the behaviour rather than stopping it, and moves it somewhere you can see even less.
The benefit is real. People are not doing this to be difficult. They are doing it because a task that took forty minutes now takes five, and asking them to give that up requires a better reason than because the policy says so.
Enforcement is impossible without surveillance. The monitoring needed to genuinely enforce a ban is more intrusive than most companies want to be, and creates its own problems.
The ban ages badly. These tools are being built into the software you already pay for. A policy that says no AI will be violated by your existing suppliers within a year, at which point the whole document loses authority.
What is actually at risk
Worth being specific, because vague warnings produce vague compliance.
Confidentiality obligations. Contracts with customers frequently restrict where their information may be processed. Pasting it into an unapproved service can breach an agreement your company signed.
Personal data. Under GDPR the company is the controller. Which processor, on what legal basis, with what retention, and whether it leaves the country — these are questions with an owner, and the owner is not the employee who pasted it.
Confidential material becoming training data. Consumer tiers vary in what they retain and use. The terms are usually readable and rarely read.
Accuracy with consequences. A summary that misses a clause, a figure that gets transposed. The risk is not the tool; it is the tool being trusted for something nobody checked.
What a workable policy contains
Approved tools people actually want to use. The policy fails on the day it makes the sanctioned route worse than the unsanctioned one.
Data classes, in plain language. Not confidential and not confidential. Something like: internal drafts fine, anything with a customer name in it goes only to the approved tool, anything under a specific contractual restriction goes nowhere. Written so a person can apply it in ten seconds.
A log, on the approved route. What was asked, what material was used, by whom. Not to police people — to be able to answer the question when a customer or an auditor eventually asks it.
Human approval for anything outbound. Assistance that drafts is useful and safe. Assistance that sends is the part that produces the incident.
An amnesty. Say out loud that people who have been using these tools are not in trouble. Without that the first version of the policy gets you compliance theatre and no information about what has actually been happening.
The version that works
Give people something good, tell them where the line is in language they can apply, log the approved route, and keep a person between the machine and anything irreversible.
That is not a technology project. It is four decisions and a document, and it is worth more than any tool a company could buy this year.
- shadow AI
- policy
- data protection
- workplace