Skip to content
    AI+ Pro
    ← All posts
    Governance

    Shadow AI: your staff already pasted it into ChatGPT

    Blocking the tools does not remove the demand, it removes your visibility. What actually works is giving people the same models somewhere you can see.

    August 12, 20264 min readCH Peh · CEO, Straits AI Group

    Somewhere in your organization this week, someone pasted a customer contract into a chatbot to get a summary before a meeting. They were not being reckless. They were being efficient, on a deadline, with a tool that works. That is the whole problem: shadow AI is not a discipline failure, it is a supply failure. Demand for the capability arrived years before most organizations supplied a sanctioned way to meet it.

    Why the ban does not hold

    The standard first response is to block the domains. It is fast, it is visible to the board, and it fails quietly. Blocking a domain on the corporate network does not touch the personal phone sitting next to the laptop, and it does not touch the home connection where a third of the work now happens. What a block reliably achieves is the end of your visibility: the behaviour continues, and you stop being able to see it, measure it or improve it.

    The second response is a policy document. Policies matter, but a policy without a supported alternative is an instruction to work slower than the person in the next seat. People resolve that conflict the way people always have.

    A control that pushes an activity off your network has not reduced the risk. It has reduced the evidence.

    What the risk actually is

    It is worth being precise, because the vague version of this fear leads to vague controls. There are three distinct exposures, and they need different answers.

    • Retention. Text pasted into a consumer product may be stored on infrastructure you have no contract with, in a jurisdiction you did not choose, for a period you cannot set.
    • Training. Some consumer tiers use submitted content to improve models by default. The setting exists, but it is per-account, and you cannot audit whether every employee found it.
    • Attribution. When an answer turns out to be wrong and it has already gone to a client, there is no record of what was asked, which model answered, or what it was given to work from.

    Notice that only the first two are about confidentiality. The third is about accountability, and it is the one that tends to surface in a review months later, when nobody can reconstruct how a document came to say what it said.

    Supply, then govern

    The approach that holds is unglamorous: make the sanctioned path the fastest path. If the internal workspace has the same frontier models people are already reaching for, opens as quickly, and does not require a ticket, the incentive to route around it disappears on its own. You are not competing with the consumer tools on features. You are competing on friction.

    Once the work is happening somewhere you control, the governance you wanted becomes possible rather than theoretical. Access follows the roles you already maintain. Every query has a record. The documents stay in your storage, and only the passages relevant to a question are ever sent to a model. When someone changes role, their access changes with it, in one place.

    The objection, and the honest answer to it

    The reasonable pushback is that an internal platform cannot match the pace of the consumer products. Six months ago that was a stronger argument than it is now. The frontier models are available through the same APIs to everyone; what differs is the wrapper around them. A workspace that routes to the current models — commercial and open-weight, several at once — is not a lagging copy of the consumer tool. It is the same models with an audit log attached.

    Where the objection still bites is in the long tail of consumer features: the voice mode, the phone app, the browser extension. Be honest internally about which of those your staff actually use for work, because the answer is usually narrower than the objection implies, and pretending otherwise costs you credibility on the parts that matter.

    The pattern in regulated industries

    Organizations that answer to a regulator tend to arrive at this problem from the other end. They did not have a period of quiet, informal adoption; they had a hard block from day one, and now they have a workforce that has fallen behind peers who did not. The gap shows up in recruitment before it shows up anywhere else.

    For them the sequence is inverted but the destination is the same. The deployment question comes first — private cloud, isolated tenant, or on-premise — because nothing else can be discussed until the data-residency answer exists. Once it does, the adoption problem is the ordinary one, with the advantage that nobody has to be talked out of a habit first.

    What six months later looks like

    The measurable change is not that people stopped using consumer tools. Some will keep a personal account for personal things, and that is fine. The change is that the work moved: the contract summary, the client email, the analysis of the spreadsheet nobody wants to open. Those happen in a place with a record.

    The second change is that the conversation with the auditor gets shorter. Not because the risk went to zero — it did not — but because "we do not permit it" is replaced by a description of controls, a log, and a list of who has access to what. One of those positions can be defended.

    What to do on Monday

    Start by finding out what is actually happening, without punishing anyone for answering honestly. A short, anonymous question to a few teams — what are you using, and what for — usually produces a more accurate picture than any network log, because it captures the phone.

    Then pick the two or three tasks that came up most often and make sure the sanctioned workspace does those well on day one. Adoption is won on the specific job somebody has to finish this afternoon, not on the breadth of the platform.

    Finally, say out loud that the old behaviour is understood and is not being punished. Shadow AI persists in organizations where admitting to it is expensive. It ends in organizations where the better option is simply there.

    More from this journal

    Continue reading

    See AI+ Pro in practice

    A secure homebase for the work your teams are already doing.

    Explore the platform