Somewhere in your business this week, someone pasted a customer email into a free chatbot and asked it to write a polite version of “no”. Someone else dropped a supplier contract into a summariser because the meeting was in nine minutes. Neither will mention it to you.

This is shadow AI: the ordinary consequence of putting a useful tool one click away from every employee. Most organisations discover it the way most people discover a tree well — suddenly, upside down, and later than would have been helpful.

The question is not whether your people are using AI. They are. It is whether you know what they are feeding it, and what it may touch on the way back.

Why the rope gets ducked in the first place

It is tempting to file shadow AI under recklessness. It is almost never that — it is two reasonable things colliding.

The first is that the tools are good at the boring middle of knowledge work: drafting, summarising, rewriting, explaining. Someone with a two-hour job and a free tool that does most of it in ten minutes is not holding a governance workshop first.

The second is that asking permission is slow. Raise your hand and you get a security questionnaire, a procurement conversation and a date in three weeks. Keep it down and you get your afternoon back.

When the sanctioned route takes three weeks and the unsanctioned one takes three seconds, you have not written a policy. You have designed a shortcut.

What the exposure actually looks like

Ask a board what worries them about shadow AI and you get something vague about data. Here is the specific version, in ascending order of how bad the week gets.

The paste

Customer records, pricing, contracts, an entire board pack — pasted into a consumer tool by someone trying to work faster. The data leaves your tenant, governed from there by terms nobody has read, on an account you do not own and cannot audit.

The integration nobody reviewed

Worse, and quieter. A team connects a clever tool to a real system — a mailbox, a CRM, an ERP — because it needs context to be useful. Nine months after the fifteen-minute trial, the trial is load-bearing, the person who set it up has changed jobs, and the connection still has write permission because read-only broke one thing once.

The agent that kept its keys

The newest, and the one that scales badly. An agent is given a broader scope than it needs, because narrowing it meant raising a ticket, and quietly keeps it. It works fine for months. Then it does something reasonable-looking at scale at three in the morning, and the only record is a log nobody configured.

The chat window is the smallest of these, and the only one most policies mention.

Why banning it does not work

The instinctive response is to close the mountain: block the domains, send the all-staff email, add a line to the handbook, consider it handled.

Then three things happen. People move to their phones, where you have no visibility. The valuable uses die alongside the reckless ones, so you take the cost of caution and none of the benefit. And you lose the ability to find anything out, because honesty is now a disciplinary matter.

A blanket ban is avalanche control by closing the resort. Nobody gets caught in a slide, and you also have no patrol, no forecast, and a car park full of people who drove four hours and are reading the map for a way in. Some will find one.

There are real cases for prohibition — specific data classes, regulated processes, tools whose terms you have read and rejected. Closed runs are fine. A closed mountain is an admission that nobody wanted to decide.

Find out what is in use, without starting a witch hunt

You cannot govern what nobody will admit to, so discovery has one job before any other: make telling the truth the easy option.

Say the quiet part out loud, in writing, from someone senior enough that it counts: we know AI tools are in use, we are not looking for blame, we want to know what is working so we can make it safe and official. Then do not punish the first person who answers; the exercise is priced on that one moment.

Then look in four places:

  • Ask, department by department. Not a survey nobody fills in — a twenty-minute conversation about what is slow and what people found to make it faster.
  • Check the expense claims. Subscriptions on personal cards are the most reliable shadow AI detector ever built, and finance has the data.
  • Look at what is connected. Consented applications, OAuth grants, API keys, browser extensions, integrations into core systems. Where the write access hides.
  • Use the tooling you already pay for. Microsoft Purview’s Data Security Posture Management for AI surfaces “other AI apps” detected through browser activity and categorised as generative AI in the Defender for Cloud Apps catalog — third-party assistants included.

The output is not a naughty list. It is a shortlist of things people found valuable enough to go around you for — the best-qualified automation pipeline you will ever be handed free. Several are worth doing properly.

Consumer tools and governed tools are not the same product

This distinction does most of the work in an acceptable use policy, and almost nobody explains it to staff. From the user’s chair the two are identical: a box, a cursor, an answer. Everything behind it differs.

QuestionConsumer accountGoverned enterprise tool
Who holds the contractThe employee, personallyYour organisation
Whose identity is usedA personal login you cannot seeCorporate identity and controls
Where the data sitsOutside your tenantInside your compliance boundary
Can you audit itNoYes, if configured
When someone leavesThey keep account and historyAccess goes with the rest
Who is accountableUnclearA named process owner

Microsoft is explicit about the enterprise side: under enterprise data protection, prompts, responses and data accessed through Microsoft Graph are not used to train foundation models, and the same contractual commitments that cover Exchange and SharePoint apply. The point is not that one badge is magic: with a governed tool there is a commitment to point at, and with a personal account there is nobody to ask.

So the message to staff is not “AI is dangerous”. It is: use the one we pay for, because it is the same tool with your employer’s name on the contract instead of yours.

Write the page people will actually read

Most AI acceptable use policies fail the same way: eleven pages, written to protect the organisation from its own staff, answering none of the questions an employee has at the moment they are about to paste something. They are the laminated sign at the bottom of the lift that everybody skis past.

If your policy cannot be read in five minutes and remembered in one, it is not a policy. It is evidence that you had one.

A policy that gets followed does six things, in business language rather than legal:

  • Names the approved tools. Actual product names, not “approved solutions”. If people have to work out what they may use, they guess generously.
  • Says what must never go in. Specific to your business: customer records, pricing, unreleased financials, credentials, anything under NDA. “Confidential information” means nothing at 4pm on a Friday.
  • States where a human must decide. Anything a customer sees, anything that moves money, anything that posts to a system of record.
  • Tells people to check the output. The person who sends it owns it, whatever generated it.
  • Covers connections, not just chat. No connecting an AI tool to a business system without review. The clause that actually protects you, and the one usually missing.
  • Names a human. A person or a channel, with a response time. “Ask first” only works if there is somewhere to ask that answers this week.

That is a page. A page and a half if your regulator has opinions. Anything beyond it belongs in a standard your architects read, not the document four hundred people must internalise.

Put one more thing in writing: what happens when someone gets it wrong. If the answer is punishment, you have reinstated the incentive to hide. Patrol would rather you radioed in from the wrong side of the rope than waited politely for dark.

Governance is the fast line, not the queue

Done properly, governance makes you faster, which is the part a CFO should care about most. Not in a compliance-brochure way — measurably faster, because “can I use this?” stops being “wait three weeks” and starts being “that one is approved, here is the login”.

In an ungoverned organisation nothing compounds. Every new tool is a fresh argument from first principles, every integration a bespoke security review, and the twelfth request costs exactly what the first one did.

The organisations moving fastest with AI are not the ones with the loosest rules. They are the ones where the rules are clear enough that nobody has to stop and ask what they are.

Avalanche control is not there to keep you off the slope. It is why the gate opens at nine instead of the run staying roped all season. Patrol does the work before the queue forms so that everyone behind them goes straight down it. Governance is the same trade.

It pays off where the stakes are highest. Once AI touches systems of record — your ERP, your CRM, your finance stack — what it may read, what it may write and who approved that stop being policy questions and become architecture questions. Answer them on paper first and that part comes cheaper. When the next platform lands on your desk, you already have the questions to ask it.

The honest summary

Shadow AI is not a sign that your people are careless. It is a sign that they found something useful before you finished deciding how to feel about it.

What you owe them is a clear map: which runs are open, which are closed and why, and a number to call when something looks wrong. Give people that and most will stay in bounds, because in bounds is where the lifts are.

Leave the map blank and they will still ride. You just will not know where.