Professional reviewing an AI-assisted workflow in a modern office

Artificial intelligence is already part of your organization’s daily work: even if leadership has not formally approved an AI program.

An employee may use ChatGPT to summarize a client email. A project manager may upload meeting notes to an online assistant. A staff member may ask Microsoft Copilot to rewrite a sensitive message or analyze a spreadsheet. These actions often begin as reasonable attempts to save time.

They can also create shadow AI: the use of AI tools without appropriate organizational approval, visibility, or safeguards.

Shadow AI is not necessarily a sign of careless employees. It is usually a sign that your team sees a practical opportunity and lacks clear guidance. The right response is not to block every AI tool. It is to create a secure path for adoption through policy, training, technical controls, and human accountability.

This is the next step in our AI & Automation series. In our previous article, Human-in-the-Loop AI: How to Adopt AI Safely in Your Organization, we explored how people should remain responsible for reviewing and approving AI-supported work. That same framework provides a practical way to address shadow AI.

What Shadow AI Looks Like In Your Organization

Shadow AI includes more than employees using ChatGPT.

It may involve:

  • Public AI assistants such as ChatGPT, Gemini, or Claude
  • Personal accounts used for business tasks
  • Consumer versions of Microsoft Copilot
  • AI browser extensions
  • Meeting transcription and summarization tools
  • AI-powered writing, design, recruiting, or research applications
  • AI features added to existing software without formal review
  • Custom automation or scripts created by employees

The distinction between approved and unapproved AI is important. Microsoft Copilot, for example, may be appropriate in a properly licensed and configured Microsoft 365 environment. That does not mean every Copilot experience, personal account, or third-party plug-in automatically follows your organization’s data permissions.

The question is not simply, “Are employees using AI?”

The better questions are:

  • Which tools are they using?
  • What information are they entering?
  • What decisions are influenced by the output?
  • Who reviews the result before it is used?
  • Does the vendor meet your security and compliance requirements?

Why Shadow AI Creates Business Risk

Sensitive Data May Leave Your Control

Employees may paste information into an AI tool without realizing that the data is leaving your managed environment.

Examples include:

  • Client or patient information
  • Member or donor records
  • Employee data
  • Contracts and legal documents
  • Financial reports
  • Project plans and engineering specifications
  • Credentials, API keys, or internal system details
  • Proprietary processes and intellectual property

Once information is submitted, your organization may not know where it is stored, how long it is retained, who can access it, or whether it is used to improve a provider’s model. These questions matter especially for healthcare practices, legal organizations, accounting firms, nonprofits, and businesses handling confidential client information.

Security tools that protect email, endpoints, and file servers may not provide complete visibility into data entered into personal AI accounts. This creates a gap between your formal security program and the way work is actually being performed.

Compliance Requirements May Be Bypassed

AI adoption can affect privacy, confidentiality, retention, and vendor-management obligations.

If your organization handles protected health information, payment information, personally identifiable information, or sensitive client records, an unapproved AI tool may not provide the contractual or technical protections you require. In some cases, using the tool may conflict with internal policies, client agreements, or industry expectations.

The NIST AI Risk Management Framework emphasizes the need to identify, measure, and manage AI-related risks throughout the technology lifecycle. That does not require a complicated process for every experiment. It does require a consistent method for evaluating how a tool handles data and how its output will affect people and operations.

AI Output Can Be Incorrect

AI tools can produce confident but inaccurate answers. They may invent citations, misunderstand context, omit important details, or make flawed calculations.

That creates operational risk when employees use AI to:

  • Draft legal or compliance language
  • Summarize medical or client information
  • Prepare financial analysis
  • Respond to customers or members
  • Evaluate candidates
  • Create technical instructions
  • Make recommendations about projects or services

The risk is not limited to obviously wrong answers. An output can appear polished and reasonable while still containing a subtle error. Without human review, that error may reach a client, employee, patient, board member, or regulatory body.

As IBM explains in its overview of shadow AI, organizations need visibility and governance that account for both security concerns and the business reasons employees adopt these tools.

Digital shield representing data protection and secure AI safeguards

How To Detect Shadow AI Without Blocking Innovation

The first step is a candid review: not a punitive investigation.

Tell employees that leadership wants to understand how AI is being used so the organization can support productive work safely. Ask practical questions:

  1. Which AI tools do you use for work?
  2. What tasks do they help you complete?
  3. Do you use a personal or organizational account?
  4. What types of information do you enter or upload?
  5. How do you verify the output?
  6. What approved tools would make your work easier?

You can also work with your IT or managed services partner to review:

  • Application and browser activity
  • New software and browser extensions
  • Identity and sign-in records
  • Microsoft 365 audit data
  • Unusual file downloads or uploads
  • Data-loss prevention alerts
  • AI applications connected to business accounts
  • OAuth permissions granted to third-party tools

The goal is not to monitor every employee’s private activity. The goal is to identify business data flows and applications that create avoidable risk.

You should also look for indirect indicators. An employee may not report using AI, but unusually polished content, unexplained workflow changes, new browser extensions, or repeated uploads to unfamiliar services may warrant a conversation.

Bring AI Under Governance

A secure AI program should be understandable enough for a busy employee to follow. Your policy should define four basic categories of information:

  • Public: Information approved for public release
  • Internal: Routine business information that should remain within organizational systems
  • Confidential: Client, member, employee, financial, legal, or proprietary information
  • Restricted: Credentials, regulated data, protected health information, payment data, and information subject to contractual limitations

Then establish a clear approved-use policy.

1. Publish An Approved Tools List

Identify the AI tools your organization supports and explain which account employees should use. Do not assume that a tool is safe simply because it is popular.

For each approved tool, review:

  • Data retention and deletion practices
  • Whether customer data is used for model training
  • Encryption and access controls
  • Administrative visibility
  • Contractual protections
  • Integration with your existing systems
  • Availability of audit logs
  • Support for multifactor authentication

Vendor review should be documented and repeated when the product’s features or terms change.

2. Require Multifactor Authentication

Every approved AI account should be connected to your identity and access policies. Require multifactor authentication (MFA), use organizational accounts, and remove access when an employee leaves or changes roles.

Where possible, use single sign-on and role-based permissions. An AI application should not have more access to your files or systems than the employee needs to perform the task.

3. Apply Data Controls

Use the security capabilities already available in your technology environment.

Depending on your systems and risk profile, controls may include:

  • Microsoft 365 sensitivity labels
  • SharePoint and OneDrive permissions
  • Data-loss prevention policies
  • Endpoint protection
  • Secure web filtering
  • Conditional access
  • Mobile and device management
  • Logging and alerting
  • Restrictions on third-party application access

Your Microsoft 365 services should support your AI governance strategy: not operate separately from it.

4. Train Employees On Practical AI Use

Training should address real work, not just abstract policy language.

Show employees how to:

  • Remove unnecessary personal information
  • Use placeholders instead of names or account numbers
  • Avoid entering passwords, keys, or confidential documents
  • Ask AI to summarize approved information rather than upload entire files
  • Check calculations, citations, and factual claims
  • Escalate uncertain or sensitive use cases
  • Report accidental disclosure promptly

Make it easy to ask, “Can I use AI for this?” Employees are more likely to follow policy when the approved path is clear and responsive.

Business leaders and an IT advisor reviewing an AI policy and technology dashboard

Use Human-in-the-Loop AI As The Operating Model

Governance should not turn every AI task into a committee meeting. Instead, classify use cases according to their potential impact.

Low-Risk Assistance

Examples include brainstorming, formatting, summarizing public information, or creating an initial draft of an internal document.

A person should still review the result before external use.

Moderate-Risk Work

Examples include drafting client communications, organizing operational data, prioritizing service requests, or summarizing internal documents.

A qualified employee should evaluate the output, correct errors, and approve the final result.

High-Risk Or Regulated Decisions

AI should not independently make decisions involving health, employment, legal rights, finances, eligibility, privacy, or access to important services.

These workflows require direct human control, documented review, and appropriate legal or compliance guidance.

This is the practical value of the human-in-the-loop model: AI can assist with speed and scale, but people remain accountable for context, judgment, and consequences.

A Practical 30-Day Starting Plan

Your organization can begin with a focused, manageable process:

  1. Inventory current AI use through a confidential employee survey and technical review.
  2. Identify sensitive data flows and the highest-risk tools or activities.
  3. Publish interim rules explaining what employees may and may not enter into AI systems.
  4. Select one or two approved use cases that offer clear operational value.
  5. Require MFA and organizational accounts for approved tools.
  6. Create human-review procedures for each use case.
  7. Train employees on data handling and output verification.
  8. Review results, corrections, and incidents before expanding adoption.

Your cybersecurity solutions should include this kind of ongoing evaluation. AI governance is not a one-time policy exercise; it is part of managing how your organization uses technology.

Secure AI Solutions Should Enable Better Work

Blocking every AI tool may appear simple, but it rarely addresses the underlying demand. Employees may continue using unsanctioned tools from personal devices or accounts, with even less visibility.

A better strategy is to provide secure AI solutions that align with your organization’s mission, technology environment, and risk profile. That means combining policy, training, identity protection, data controls, vendor review, and human oversight.

Elite IT helps organizations in Washington, DC, Maryland, and Virginia evaluate AI use, strengthen cybersecurity, manage Microsoft 365 environments, and build technology roadmaps that support long-term goals. We approach AI as part of your broader business strategy: not as a disconnected software purchase.

Contact Elite IT to discuss how your organization can bring shadow AI under governance while giving your team a secure, practical way to innovate.