Shadow AI vs Sanctioned AI
Defining Shadow AI vs Sanctioned AI
Shadow AI is any AI tool an employee uses at work without IT approval or oversight. Sanctioned AI is a tool the business has reviewed and set rules around. The tool is rarely the problem. The risk comes from data going in without anyone checking where it goes or who else can see it.
It's already happening
Most clients have staff using free AI tools today, usually on personal accounts with no link to the business's own security controls.
The tool isn't the risk
A public chatbot is not inherently dangerous. The risk is data leaving without anyone checking where it goes or how long it is kept.
Consumer and enterprise terms differ
Consumer AI tools often train on submitted data unless a user opts out. Enterprise tiers usually have clearer no-training and retention terms.
How Client Data Leaks Into Public AI Tools
Prompts and Pasted Text
A staff member pastes a client contract or pricing sheet into a prompt for a quick summary. It looks like faster work, not a data transfer, but it is one.
File Uploads
Spreadsheets, PDFs, and documents get uploaded to AI tools for cleanup or analysis, often on personal accounts with no link to business security controls.
Browser Extensions
Free browser extensions can quietly send page content and text to a third-party model in the background, with no visible warning to the user.
IDE Plugins
Coding assistants built into development tools can send source code and comments to external models, exposing client intellectual property.
Already Leaked Data?
If a contract was pasted into ChatGPT's free tier, use its settings to request deletion, then move that tool to the blocked list and route the team to the enterprise, no-training version instead.
Discover, Build, Enforce, and Prove It
Five steps that turn shadow AI from an unknown risk into a managed, reportable control, without adding new software to the stack.
-
01Discover Which AI Tools Are In Use
See every AI domain contacted from customer devices, on or off the network, using DNS-layer visibility already built into Web Protection.
-
02Build a Policy Staff Will Follow
A workable policy names Microsoft Copilot or an enterprise ChatGPT plan as approved, blocks client names, financials, and source code from prompts, and gives one person new-tool approval.
-
03Enforce at the DNS Layer
Block unapproved AI tools and allow-list approved ones per client, from one centrally managed platform rather than per-tenant configuration.
-
04Reinforce With Awareness Training
Pair enforcement with ongoing training so staff understand why a rule exists, reducing the chance they look for a way around it.
-
05Report to Prove Governance
Give clients and auditors a monthly summary of blocked domains and policy exceptions as evidence that AI use is actively managed.
Shadow AI Frequently Asked Questions
Shadow AI is the use of AI tools at work, such as public chatbots, browser extensions, or coding assistants, without IT's knowledge or approval. It is the AI version of shadow IT: not malicious, but ungoverned.
The tool is rarely the issue. The risk comes from what is typed or uploaded into it, and whether the account in use retains and trains on that data. An enterprise, no-training account carries far less risk than the free consumer version.
DNS-layer filtering can see and block the domains an AI tool needs to reach before any data leaves the device. It cannot see what is typed inside an approved tool, so it works alongside a policy and training, not instead of them.
If a contract or spreadsheet was pasted into a tool like the free version of ChatGPT or Gemini, go to that account's privacy settings and submit a deletion request. Most consumer AI tools offer this, though processing can take a few days. Then move that specific tool to a blocked list and point the team to an enterprise, no-training version instead.
For most SMB clients, no. Most SMBs are AI deployers rather than high-risk providers under the EU AI Act, so a short, specific usage policy covering approved tools and off-limits data is normally enough. This is general guidance, not legal advice.
Request a Demo