Shadow AI: what to do when employees already use their own tools.
Banning AI tools pushes their use into personal accounts you can’t see. Find out what people use and why, offer an approved tool that is genuinely good, set clear data rules and turn the best unofficial uses into projects.
veridive5 min read
Ask a finance team how they reconcile supplier statements at month-end, and someone may turn their screen to show you a chat assistant in a browser tab, signed in with a personal email address. It works. Nobody approved it. Nobody in IT knows it exists.
That is shadow AI: AI tools used at work without the organization’s approval or visibility. It is a risk, and it is also the clearest signal you will get of where people want help. The answer is not a ban. Find out what people use and why, offer an approved tool that is genuinely good, set clear rules about data, and turn the best unofficial uses into proper projects.
Why do people use unapproved AI tools?
Because the tools help with real work, and the approved route is slow, unclear or missing. People use them to draft emails, summarize long documents, fix spreadsheet formulas, translate between Turkish and English and tidy exported data. Most are not trying to break rules. They are trying to finish their work, and nobody has told them which tools they may use, with which data.
What are the real risks?
In order of the damage they can do:
- Customer or employee data in personal accounts. Under consumer terms, the company has no agreement with the provider about retention, training use or where data is processed, and no way to delete it. When the employee leaves, the history leaves with them.
- Confidential documents. Contracts, pricing, board papers and source code, pasted in to be summarized or checked.
- Unchecked output used in decisions. A formula, a summary or a translation that looks right goes into a report, a reply or a decision, and nobody checks it because nobody knows AI was involved.
Why don’t bans work?
A ban without an alternative doesn’t stop use. It moves it to phones and personal laptops, where IT can’t see it or help, and it stops people asking questions, which removes your best source of information. Blocking a few websites on the office network is easy to route around.
A ban doesn’t stop AI use. It stops you from seeing it.
Rules about data work better than rules about tools. “Never paste customer or employee data into a personal account” is clear, enforceable and survives the next product launch. “Don’t use AI” is none of those.
How do you find out what is being used?
Run an amnesty-style survey: a short questionnaire, sent with a clear promise that answers will not be used against anyone. Then keep the promise. Ask:
- which tools people use, and through personal or company accounts;
- which tasks they use them for, and how often;
- what kind of data goes in;
- what an approved tool would need to do for them to switch.
Follow up with short conversations with a few heavy users; they usually have the most useful workarounds. IT can add an aggregate view of which AI services the network sees, but agree with HR and your DPO before anyone looks at individual activity. The output is a list of tasks, ranked by how often they happen and how sensitive the data is.
What should replace the unofficial tools?
Three things, in this order:
- An approved tool that is genuinely good. A company account under an enterprise agreement that settles retention, training use and processing region, with single sign-on and offboarding. If the approved tool is clearly worse than the free one, people go back. Our note on where your data goes explains why the agreement matters more than the brand.
- A short acceptable use policy. Which tools, which data, who checks output and when to disclose, on two pages. Our acceptable use policy template is a starting point.
- Training on real tasks. What the tool is good and bad at, how to check an answer, which data never goes in. It sticks when it uses the team’s own work, which is how we approach AI enablement.
Add a quick way to ask “may I?” and get an answer the same day, and a route for reporting a mistake without blame. Both follow the same logic as our guardrails: clear access rules, and a person deciding where it matters.
How do good unofficial uses become projects?
Someone’s clever prompt is a prototype nobody has measured. The path from there to a workflow project is short:
- Capture the task and the prompt, with the person who wrote it.
- Check how often the task happens, for how many people, and what it costs today.
- Name an owner for the workflow.
- Collect real examples with the answers an expert would accept.
- Decide: keep it as personal productivity under the policy, or build it into the workflow with data access, approval points and measurement.
Here is an illustrative case. The questionnaire answers show that three people in accounts payable paste supplier statements into personal chat accounts at month-end, with open items exported from the ERP, and ask for the mismatches. It saves them hours, but supplier data sits in personal accounts and nobody checks the matches systematically. The first step is immediate: the work moves to the approved tool, and nothing goes into personal accounts. The second is a scoped project: reconciling supplier statements against the ERP’s open items, with read-only access, each proposed match shown with its evidence, an accountant approving, and an evaluation set built from past month-ends. The three people who wrote the prompts become the domain experts, and their prompts become the first draft of the specification.
Questionnaire first
Run the amnesty questionnaire before you write any rules; the answers tell you which tool to approve and which workflows deserve a project. If the list is long, a Discovery Sprint is a structured way to rank it.
This note is general information, not legal advice.
Sources
- Guide on Generative Artificial Intelligence and the Protection of Personal Data (in 15 Questions), in Turkish Personal Data Protection Authority (KVKK) www.kvkk.gov.tr/Icerik/8547/uretken-yapay-zeka-ve-kisisel-verilerin-korunmasi-rehberi-15-soruda
- Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 National Institute of Standards and Technology (NIST) nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
Ask an assistant about this note