- Shadow AI is the use of AI tools not approved by the company, often with a personal account and internal data.
- A ban moves the problem to the personal phone. It does not remove it.
- Three measures are enough to regain control: a two-page policy, approved professional accounts and a clear rule on what never leaves.
- The real risk is not the tool, it is pasting a contract, a client list or source code into a consumer chat window.
What we actually find in companies
During our audits we ask teams a simple question, with management out of the room: "Who uses an AI assistant at least once a week for work?" More than half the hands go up in almost every organisation, including those that have formally banned these tools. The uses are ordinary and useful: rewording an email, summarising minutes, preparing a presentation, fixing a formula, translating a document.
The problem is not there. It is in what comes with the request: the minutes contain client names, the formula comes from a margin file, the translated document is a contract under negotiation. With a free personal account, that data leaves the company without any framework.
Why bans fail
Banning a tool people find useful always produces the same result: they carry on, but on their phone, off the company network, with zero visibility. You go from a measurable risk to an invisible one. Companies that tried an outright block generally see usage drop for two or three weeks, then return to its initial level, this time under the radar.
The other, less visible effect is human: the most curious employees, often the most productive, feel treated as suspects. They are exactly the people you need to make your AI projects succeed.
What works: three measures, in this order
A two-page policy, not a thirty-page rulebook
The policy must fit on two pages and answer three questions: which tools are allowed, which data must never go in, and who to ask when in doubt. Everything else is noise. We have it signed during a forty-five-minute awareness session, with examples taken from the company's daily life.
Approved professional accounts
The business offers of the major providers contractually guarantee that your data is not used to train models, and provide central administration. The cost per user is small compared with a single client data leak. Provide an official tool and most parallel usage disappears by itself.
A short, memorable rule on data
We use a three-level classification with colours. Green: public data or data without identity, free use. Amber: internal data, allowed only in approved tools. Red: personal data, contracts, trade secrets, sensitive source code, never in an assistant, unless in a private deployment approved by security.
Before pasting text into an assistant, ask: "Would I email this to a stranger?" If the answer is no, it is red.
The role of management
A policy that stays on the intranet changes nothing. What changes behaviour is a manager who shows how they use the approved assistant, who shares a good prompt in a meeting, who recalls the colour rule when they see a slip. The companies where Shadow AI recedes are those where official use becomes visible and valued.
"People do not need a ban. They need to know where the line is, and a tool that lets them stay on the right side of it."
Conclusion
Shadow AI is a signal, not a fault: your teams found time savings the company was not offering them. Answer with a framework rather than a wall. A short policy, approved tools and a memorable data rule bring usage back into view, and turn a diffuse risk into a collective advantage.
FAQ
Should we block consumer AI sites on the network?
Only if you provide an approved alternative the same day. Blocking without an alternative pushes usage to personal devices, where you see nothing.
What data can go into a business offer?
Amber-level internal data, within what your contract and security policy allow. Red data (personal, contractual, secrets) stays out of any external assistant.
How do we measure real usage?
With an anonymous five-question survey, repeated every six months, rather than network monitoring that misses personal phones and destroys trust.
What does the AI Act say about this?
Since February 2025 the regulation requires "AI literacy" among staff: companies must ensure that employees who use AI systems have a sufficient level of understanding. A policy and an awareness session are the first building block.