AI Security

Shadow AI: How to Secure the AI Tools Your Employees Are Already Using Without Your Permission

Infinity Network Support TeamJune 29, 20269 min read
Back to Blog

Your employees are using ChatGPT, Copilot, and dozens of other AI tools at work right now — with or without IT approval. Here is how to get visibility, set policy, and prevent data leaks before they happen.

A 2025 survey found that 75% of knowledge workers use AI tools at work. Of those, fewer than half are using tools that their IT department has reviewed or approved. The rest are using consumer AI services — ChatGPT, Claude, Gemini, Perplexity — and feeding them whatever data they need to complete their tasks, including customer information, financial data, and proprietary business content.

This is not a future risk. It is happening in your organization right now. The question is not whether to address it — it is how to address it without killing productivity or driving usage further underground.

What Data Is Actually at Risk

The risk is not that AI tools are malicious — it is that consumer AI services are designed for individual use, not enterprise data handling. When your employee pastes a customer contract into ChatGPT to summarize it, that text may be retained by OpenAI for model improvement unless the user has opted out (and most have not). When they paste financial projections into a free AI tool, those numbers may be stored on servers with no data processing agreement in place.

  • Customer PII (names, addresses, contact information)
  • Financial data (revenue figures, pricing, forecasts)
  • Legal documents (contracts, NDAs, litigation materials)
  • Proprietary code and technical documentation
  • HR data (employee records, compensation, performance reviews)
  • Regulated data (PHI under HIPAA, cardholder data under PCI DSS)

Getting Visibility: What AI Tools Are Being Used

Before you can govern AI tool usage, you need to know what is being used. Several approaches provide visibility:

  • DNS filtering logs — most AI services use distinct domains that appear in DNS query logs
  • Web proxy or CASB (Cloud Access Security Broker) logs — show which cloud services are being accessed
  • Browser extension inventory — many AI tools are accessed via browser extensions that appear in endpoint management consoles
  • Employee survey — sometimes the simplest approach; ask what tools people are using and why

Building an AI Acceptable Use Policy

An AI acceptable use policy does not need to be lengthy, but it must be specific. Generic "use good judgment" policies are not enforceable. Your policy should address:

  • Approved AI tools — a specific list of tools that have been reviewed and approved for work use
  • Data classification rules — which data categories can and cannot be shared with AI tools (e.g., no customer PII, no regulated data, no confidential financial information)
  • Approved use cases — what tasks AI tools can be used for (drafting, summarizing public information, coding assistance) vs. prohibited uses
  • Output review requirements — AI-generated content must be reviewed before use in customer-facing or legal documents
  • Incident reporting — how to report if an employee believes they have shared sensitive data with an unauthorized AI tool

Sanctioned AI Tools: What to Look For

When evaluating AI tools for enterprise use, the key data handling questions are: Does the provider offer a Data Processing Agreement (DPA)? Is your data used to train the model? Where is data stored and for how long? Does the tool comply with relevant regulations (HIPAA, GDPR, SOC 2)? Microsoft 365 Copilot, for example, operates within your Microsoft 365 tenant boundary and is covered by Microsoft's enterprise data protection commitments — a significant advantage over consumer AI tools.

Technical Controls to Enforce AI Policy

  • DNS/web filtering to block unapproved AI services
  • DLP (Data Loss Prevention) rules to detect and block sensitive data being pasted into web forms
  • CASB policies to monitor and control cloud application usage
  • Endpoint management to block unauthorized browser extensions
  • Microsoft Purview Information Protection to classify and protect sensitive documents that cannot be shared with AI tools
Infinity Network Support helps South Florida businesses build AI governance programs — from usage discovery and policy development through technical controls and employee training. If you are concerned about shadow AI in your organization, contact us for an AI risk assessment.
Share X LinkedIn Facebook
INS

Infinity Network Support Team

Managed IT & Cybersecurity Specialists

Serving small and mid-sized businesses in Miami & South Florida with managed IT support, cybersecurity, and compliance services.

Free Download

The AI Governance Playbook

How to adopt AI safely in 2026 — free guide for South Florida businesses.

Download Free (PDF)

Related Articles

AI Security

What Is an LLM Firewall — and Does Your Business Need One?

7 min readRead
AI Security

AI-Powered Phishing: Why Your Old Email Security Isn't Enough Anymore

8 min readRead
AI Security

Deepfake Voice Calls and CEO Fraud: The AI-Powered Scam Every CFO Should Know

6 min readRead

Have Questions? We're Here to Help.

Our team of South Florida IT specialists is ready to answer your questions and help protect your business.