Governance

Your Staff Are Already Using AI. What Do You Do Now?

Shadow AI is not a discipline problem. It is a signal that people found a tool faster than you found a policy. Here is how to close the gap without a witch hunt.

Somebody in your organization pasted something into an AI tool this week. They were not being reckless. They had a deadline, and the tool was right there, and nobody had ever told them not to.

That is where most organizations actually are. Not at the start of an AI rollout, but somewhere in the middle of one that nobody authorized. The mistake leaders make is treating this as a discipline problem. It is a sequencing problem: your people found the tool before you finished the policy. The fix is to close that gap, not to punish the people who noticed the gap first.

Why it happened

AI tools crossed a line that most workplace software never crosses. There is no install, no license request, no IT ticket. Anyone with a browser and an email address is three clicks from a capable assistant. Meanwhile, the approval process for new software at most organizations takes weeks and requires somebody to write a justification.

Put those two facts next to each other and the outcome is not surprising. It is arithmetic. Nobody with a Thursday deadline waits three weeks for a Tuesday tool.

The reframe: shadow AI tells you exactly where the friction in your work is. People do not go around the process for fun. They go around it on the tasks that are slow, repetitive, or badly supported. That map is worth having.

Start by finding out what is true

You cannot govern what you have not measured, and you will not measure it if people are afraid of the answer. So do not open with an audit.

Ask about tasks, not tools. A short anonymous survey with three questions gets you more than a forensic sweep:

The third question is the valuable one. It tells you what to approve. If eleven people say they used AI to draft the same kind of routine email, you have just found something worth building a sanctioned workflow around.

Then fill in the picture from the places that already know: expense reports showing AI subscriptions, browser or network logs if you have them, and the simple act of asking managers what they have seen. You are not building a case. You are building a baseline.

Separate the two risks, because they are not the same

Everything that gets called an AI risk falls into one of two piles, and mixing them makes the whole conversation useless.

RiskWhat it looks likeWhat controls it
Something went outClient records, staff data, unreleased financials, or protected information typed into a tool the organization has no agreement withA rule about inputs — what may never be entered, regardless of which tool
Something wrong came backInvented citations, wrong figures, confidently incorrect guidance, or copy that misstates what your organization doesA rule about review — who checks output before it reaches a customer, a regulator, or a decision

The first risk is permanent and is not undone by an apology. The second is recoverable if a human is in the path. Most organizations write pages about the second and nothing usable about the first, because the second is easier to talk about.

Write the one page before you write the policy

A full AI use policy takes weeks and involves legal review, and you should do it. But a full policy that arrives in November does nothing about what happens in September. Publish a one-page interim standard now. It needs four things and nothing else:

  1. The never list. Specific categories that do not go into any AI tool: client and customer records, personnel files, anything covered by a confidentiality agreement, credentials and keys, financials before release. Name your own categories in your own words. Vague language here is what produces breaches.
  2. The approved list. Which tools people may use today, and under which account. Naming even two approved tools moves activity out of personal accounts you cannot see.
  3. The review rule. A person reviews and takes responsibility for anything that leaves the organization or informs a decision about a person. Assistance is fine. Unreviewed publication is not.
  4. The name. One person to ask when something is not covered, with their email on the page. This is the part most drafts leave out, and it is the part that determines whether anyone follows the rest.
The test for the never list: read each line to someone who does not work in your department. If they cannot tell you whether a specific document on their desk belongs to that category, the line is too abstract to follow.

Say something about the past, once

People who already used AI on work are waiting to find out whether they are in trouble. Until you answer that, they will keep quiet, and quiet is the expensive outcome. Say something clear and say it once: here is the standard going forward, here is what to do if you think something sensitive already went out, and here is what happens when you tell us.

Whether past use carries consequences is a decision for your leadership and your counsel, and the answer depends on what actually left the building. But the mechanism is not in doubt. Every organization that ends up finding out about a serious disclosure early finds out because someone felt safe enough to raise their hand.

Then close the gap that caused it

An interim standard buys you a few months. It does not fix the underlying condition, which is that your approval process is slower than the tools it is trying to approve. Two things move that:

A faster path to yes. A lightweight review for low-risk tools — what data touches it, who the vendor is, what the terms say about training on your inputs — that returns an answer in days rather than a quarter. If people can get a real answer quickly, most of them will ask.

Baseline training that is actually about their work. Not the history of machine learning. What may not be entered, how to tell when output is wrong, when a human has to sign off, and when to escalate. People who understand why the never list exists apply it to situations the list never anticipated. People who only memorized the list do not.

What good looks like six months out

Not zero AI use. Zero is not a goal anyone is going to hit, and organizations that claim it are usually the ones with the least visibility. What good looks like is that the use is visible: named tools, organizational accounts, a written standard people can quote, a person who owns the question, and a habit of asking before rather than confessing after.

You get there by treating the first honest conversation as the win it is.

Questions people ask

What is shadow AI?

Shadow AI is any use of an AI tool for work that the organization has not reviewed or approved. Most of it is a personal account opened on a phone or a home browser to get through a task faster. It is the AI version of shadow IT, and it usually shows up before any policy does.

Should we block AI tools at the firewall?

Blocking at the network moves the activity to personal devices, where you cannot see it at all. Blocking is a reasonable temporary control while you decide what to approve, but treating it as the permanent answer trades a visible risk for an invisible one.

How do we find out what people are actually using?

Ask, in a way that is safe to answer honestly. A short anonymous survey about tasks rather than tools gets far better data than an audit, because nobody self-reports into a disciplinary process. Expense reports and browser telemetry fill in the rest.

Do we have to discipline people who already used AI on work?

That is a decision for your leadership and counsel, not a technical question, and it depends on what actually left the organization. What is predictable is the effect: punish the first honest disclosure and you will not get a second one.

What is the fastest thing we can do this week?

Publish one page that names what may never be entered into any AI tool, names the tools people may use today, and names one person to ask. That single page removes most of the guessing, and you can write the longer policy afterward.

Find the credential that matches your role

Published standards, verifiable numbers, and a stated prerequisite for every credential. Review what each one requires before you enrol.

See the credentials Take the readiness check

Keep reading