Shadow AI in the company: how to govern AI use without slowing productivity
I will tell it as I encounter it in most companies. On any given morning, someone in security looks at the proxy logs and 200 people appear using ChatGPT, Claude and half a dozen AI assistants that no one has approved. That is shadow AI in the company: AI switched on at every desk without IT or compliance being aware.
The automatic reflex is usually to block everything. Bad idea. That door leads to people using their personal phone, uploading documents to worse tools and no one being able to see anything. The good news is that shadow AI in the company can be governed without slowing productivity. The bad news is that it requires uncomfortable conversations with management, HR and the employees themselves.
In this article I tell you how I approach it: what signals I look at, what mistakes I have seen repeated and what 90-day plan works in practice. No magic recipes, with things you can do on Monday.
What shadow AI in the company is and why it has soared
Shadow AI is the use of artificial intelligence tools by employees without the IT department having approved them, nor compliance having reviewed them. It is a close cousin of classic shadow IT, but with two differences that make it more dangerous: the speed of adoption and the type of data it touches.
From shadow IT to shadow AI
Shadow IT took weeks to appear: someone installed a personal Dropbox, another paid for a SaaS with their card. With shadow AI in the company, the curve is in hours. Today someone discovers a new assistant, tomorrow the whole team uses it. The friction to adopt is practically zero.
Why employees bypass the policy
They do not bypass the policy out of bad faith, they bypass it because the assistant saves them two hours a day. If your policy does not offer a reasonable internal alternative, people look outside. I have seen this in banking, in healthcare and in public administration. And it is logical: you cannot ask someone to give up a useful tool “just because”.
Concrete risks you have on the table
When I talk about shadow AI in the company with a management committee, I ground it in three risks that are understood without jargon. If you explain them badly, management does not understand the urgency. If you explain them well, they understand this is not paranoia, it is management.
Leakage of confidential data
Every time an employee pastes a contract, a customer database or a piece of proprietary code into a public assistant, that information can end up in logs your organisation does not control. Some providers do not train on that data, others do. Without a policy, they cannot be told apart.
Automated decisions without traceability
The most dangerous thing about shadow AI is not the leak, it is the decision. When a salesperson asks an assistant to evaluate a customer and puts that score into the CRM, the organisation is making decisions about people with a system no one audited. This, moreover, clashes with several articles of the EU AI Act.
Conflicts with the GDPR and the EU AI Act
If you process personal data with an assistant that is not in your RoPA, you have a problem with the GDPR. If it processes them for a decision that affects the subject, the problem grows with the AI Act. Shadow AI in the company is one of the cross-cutting risks I review in the article on IT regulations 2026: small in appearance, big when the audit arrives.
How to detect shadow AI without becoming the police
This is where many teams go wrong. They activate aggressive surveillance, employees feel investigated and everyone learns to hide it better. My approach is mixed: discreet telemetry plus open conversation.
Signals in the proxy, DLP and SaaS Management
The corporate proxy shows you which AI domains have traffic. DLP tools detect patterns of mass data pasting. And a SaaS Management tool tells you which AI subscriptions someone is paying for with a company card. With those three data points cross-referenced you have a decent map of shadow AI.
Surveys and conversations, not just telemetry
Telemetry tells you what is used, not why. I always accompany it with a short, anonymous employee survey: what tool they use, for what task and what it saves them. You get two surprises: you discover brilliant uses that deserve to be made official and others that flash red on the risk map.
A realistic governance framework for shadow AI in the company
Once you have the map, it is time to bring order without slowing productivity. The framework I apply has five pieces. Not one more, not one less. The more complex you make it, the less it is followed.
Catalogue of authorised AI tools
A short, public list of which assistants are approved, for which cases and with which data. If an employee wants to use something else, they can request it. This is the opposite of “everything prohibited by default” and, in my experience, it lowers shadow AI in the company by 60 to 80% in three months.
Corporate sandbox and synthetic data
Give the curious a place to experiment without risk: a sandbox with synthetic data representative of the real data. Advanced teams appreciate it and conservative ones are reassured. This aligns well with the responsible AI principles I apply in other projects.
Mandatory training and acceptable-use sign-off
A short annual training session (60-90 minutes) and a signed acceptable-use policy. Without this, any internal claim is weak. It is the legal leg of the framework and the one most neglected. I connect it with the rest of cybersecurity risk management so it does not remain an isolated patch.
Common mistakes when banning AI in the company
Mistake number one is a total block with no alternative. People keep using AI, just on their personal phone and off your radar. The second is setting up a painfully slow approval committee: if you take six weeks to authorise a tool, people do not wait. The third, not measuring anything afterwards: without metrics, you do not know whether your framework works.
And a fourth mistake I see more and more: treating shadow AI as a security-only problem. It is not. It is a problem of badly channelled productivity and, therefore, of management. If the CISO goes alone, it does not work. They have to go with management, HR and employee representatives.
90-day plan to govern shadow AI in the company
If you ask me where to start on Monday, this is the plan I apply. Three phases of one month each. No faster and no slower.
Month 1: diagnosis. Cross-reference proxy, DLP and SaaS Management data. Launch an anonymous survey. Produce a map with three categories: acceptable uses, uses to make official, uses to cut. Do not publish anything yet.
Month 2: minimum framework. Publish the catalogue of authorised AI tools. Launch a sandbox with synthetic data. Prepare the short training. Negotiate with management a realistic budget for corporate licences of the 2-3 most used assistants.
Month 3: execution and metrics. Activate the training and the acceptable-use sign-off. Measure three KPIs: percentage of trained employees, number of unauthorised tools detected and average approval time for new ones. Review every fortnight. Just as with risk management in IT projects with GenAI, without metrics there is no management, there are wishes.
To go deeper into how to define that policy internally, the ENISA guide on artificial intelligence is a good starting point with European vocabulary.
Frequently asked questions about shadow AI in the company
It is the use of artificial intelligence tools by employees without IT or compliance approval. It includes public assistants, AI browser plugins and paid services contracted with a company card outside the official catalogue.
Three main ones: leakage of confidential data to uncontrolled providers, automated decisions without traceability, and conflicts with the GDPR and the EU AI Act when personal data is processed or decisions are made about people.
Cross-reference three sources: proxy or corporate browsing logs, DLP alerts about data sent to unapproved domains and SaaS Management tools. Complement it with an anonymous survey asking what AI tools the team uses and why. Detection that blames fails; detection that listens finds the real cases in a week.
Banning without an alternative makes the problem worse because people migrate to their personal phone. The formula that works is to offer a catalogue of authorised tools, a sandbox to experiment and an agile process to authorise new ones, accompanied by training and an acceptable-use sign-off.
With a diagnosis cross-referencing proxy, DLP and SaaS Management plus an anonymous employee survey. Then, publish a catalogue of authorised tools and a sandbox with synthetic data. In 90 days you can have a basic framework running with clear metrics.
Do you have to apply this under DORA, NIS2 or ENS? Tell me about it.
Book 20 minutes