HomeBlogAI & Trends
AI & Trends

Shadow AI: your teams already use ChatGPT, govern it instead of banning it

In most companies we audit, more than half of employees use an AI assistant without management knowing. Banning does not work. Here is what we have seen succeed: a short policy, approved tools and one simple rule about data.

Sylvie Wendkuni NITIEMA
Sylvie Wendkuni NITIEMAFounder & Data Scientist, DataSAI
Published 9 September 2026 9 min read - reads - comments
Shadow AI: your teams already use ChatGPT, govern it instead of banning it
Shadow AI is not a discipline problem, it is an unmet need.
Table of contents
The essentials in 30 seconds
  • Shadow AI is the use of AI tools not approved by the company, often with a personal account and internal data.
  • A ban moves the problem to the personal phone. It does not remove it.
  • Three measures are enough to regain control: a two-page policy, approved professional accounts and a clear rule on what never leaves.
  • The real risk is not the tool, it is pasting a contract, a client list or source code into a consumer chat window.

What we actually find in companies

During our audits we ask teams a simple question, with management out of the room: "Who uses an AI assistant at least once a week for work?" More than half the hands go up in almost every organisation, including those that have formally banned these tools. The uses are ordinary and useful: rewording an email, summarising minutes, preparing a presentation, fixing a formula, translating a document.

The problem is not there. It is in what comes with the request: the minutes contain client names, the formula comes from a margin file, the translated document is a contract under negotiation. With a free personal account, that data leaves the company without any framework.

58%
of employees surveyed in our audits use an AI assistant every week
1 in 3
admits having pasted internal data into it
2 pages
the length of a policy people actually read

Why bans fail

Banning a tool people find useful always produces the same result: they carry on, but on their phone, off the company network, with zero visibility. You go from a measurable risk to an invisible one. Companies that tried an outright block generally see usage drop for two or three weeks, then return to its initial level, this time under the radar.

The other, less visible effect is human: the most curious employees, often the most productive, feel treated as suspects. They are exactly the people you need to make your AI projects succeed.

What works: three measures, in this order

A two-page policy, not a thirty-page rulebook

The policy must fit on two pages and answer three questions: which tools are allowed, which data must never go in, and who to ask when in doubt. Everything else is noise. We have it signed during a forty-five-minute awareness session, with examples taken from the company's daily life.

Approved professional accounts

The business offers of the major providers contractually guarantee that your data is not used to train models, and provide central administration. The cost per user is small compared with a single client data leak. Provide an official tool and most parallel usage disappears by itself.

A short, memorable rule on data

We use a three-level classification with colours. Green: public data or data without identity, free use. Amber: internal data, allowed only in approved tools. Red: personal data, contracts, trade secrets, sensitive source code, never in an assistant, unless in a private deployment approved by security.

The thirty-second test

Before pasting text into an assistant, ask: "Would I email this to a stranger?" If the answer is no, it is red.

The role of management

Team meeting about the use of AI tools
A policy lives if managers use it themselves and talk about it in team meetings.

A policy that stays on the intranet changes nothing. What changes behaviour is a manager who shows how they use the approved assistant, who shares a good prompt in a meeting, who recalls the colour rule when they see a slip. The companies where Shadow AI recedes are those where official use becomes visible and valued.

"People do not need a ban. They need to know where the line is, and a tool that lets them stay on the right side of it."

Conclusion

Shadow AI is a signal, not a fault: your teams found time savings the company was not offering them. Answer with a framework rather than a wall. A short policy, approved tools and a memorable data rule bring usage back into view, and turn a diffuse risk into a collective advantage.

FAQ

Should we block consumer AI sites on the network?

Only if you provide an approved alternative the same day. Blocking without an alternative pushes usage to personal devices, where you see nothing.

What data can go into a business offer?

Amber-level internal data, within what your contract and security policy allow. Red data (personal, contractual, secrets) stays out of any external assistant.

How do we measure real usage?

With an anonymous five-question survey, repeated every six months, rather than network monitoring that misses personal phones and destroys trust.

What does the AI Act say about this?

Since February 2025 the regulation requires "AI literacy" among staff: companies must ensure that employees who use AI systems have a sufficient level of understanding. A policy and an awareness session are the first building block.

Shadow AIGovernanceConfidentialityChatGPTPolicy
Sylvie Wendkuni NITIEMA
Sylvie Wendkuni NITIEMA
Founder & Data Scientist · DataSAI
Over ten years in AI and data consulting (Big 4, telecoms, finance). She helps companies deploy AI in production and leads the DataSAI Academy.
Take action

Let's write your AI policy in a week

Assessment of real usage, tool selection, a two-page policy and an awareness session for your teams.

Book a free session →