Managing shadow AI, employees using unapproved AI tools with company data, starts with an honest inventory of what is already in use, since a policy written without that information usually misses the tools people actually rely on every day. Run an anonymous survey or review network and browser usage data to find which AI tools employees have adopted on their own, then evaluate each against data security and compliance requirements rather than banning all of them outright, since a blanket ban typically pushes usage further underground instead of eliminating it. Approve a small set of vetted tools with clear data handling guarantees and offer those as sanctioned alternatives, since employees usually turn to unapproved tools because no approved option existed for their specific task. Combine this with a clear written policy stating which data categories can never be entered into any external AI tool, customer PII, financial figures, source code, along with visible enforcement, since a policy nobody reads or checks has little practical effect on behavior. Revisit the approved list quarterly, since new tools and updated terms of service both change the underlying risk calculus regularly. Nanobase AI helps companies run this discovery and build the sanctioned-tool policy that follows it, rather than leaving shadow AI to be discovered during an incident.
Start by finding out what is already happening
Most shadow AI policies get written before anyone checks what employees are actually using, which means the policy misses the tools people rely on daily and addresses risks that were never the real ones. Three detection methods work better than assumption: an anonymous survey that removes the fear of admitting unapproved tool use, a review of network and browser usage logs where IT already has visibility, and a scan of expense reports for AI tool subscriptions employees paid for personally and expensed. An honest inventory nearly always turns up more tools, and more categories of sensitive data flowing into them, than leadership expects going in.
A risk-tiering approach instead of a blanket ban
Banning every unapproved tool outright typically pushes usage further underground rather than eliminating it, since employees who found real value in a tool tend to keep using it quietly rather than give it up. Evaluating each discovered tool against a consistent set of criteria produces a more workable outcome:
| Criterion | Low risk | High risk |
|---|---|---|
| Data retention policy | Clear, time-limited, documented | Vague, indefinite, or undisclosed |
| Training on customer input | Explicit opt-out available | Used by default with no opt-out |
| SSO / access control | Supports enterprise SSO | Personal accounts only |
| Data residency | Meets company's regional requirements | Unknown or non-compliant |
| Vendor stability | Established vendor, clear terms | Unclear ownership or terms |
Tools scoring low risk across these criteria are candidates to formally sanction; those scoring high risk need either a stricter internal alternative offered in their place or explicit exclusion communicated with a clear reason, not just a silent ban.
Building the sanctioned list
- Rank discovered tools by how many employees actually use them, not by how risky they appear at first glance.
- Evaluate the top tools against the risk-tiering criteria above.
- Approve a small set with clear data handling guarantees, prioritizing tools that already cover the most common employee needs.
- Publish the approved list somewhere employees actually check, alongside the internal AI usage policy, rather than burying it in a compliance portal nobody visits.
- Revisit the list quarterly, since new tools and updated vendor terms of service both shift the underlying risk calculus regularly.
Enforcement that doesn't rely on fear
A policy that only threatens consequences without offering a viable sanctioned alternative tends to produce compliance theater rather than real behavior change, since employees will find workarounds when the sanctioned option genuinely cannot do what they need. Pairing enforcement with a real feedback channel, where an employee can request evaluation of a new tool rather than being stuck with only what is already approved, keeps the sanctioned list relevant and reduces the incentive to go around it. Visible, proportionate enforcement matters too; a policy that is never actually checked has little practical effect regardless of how it reads on paper.
Why shadow AI risk keeps growing, not shrinking
New consumer AI tools launch continuously, and the browser extensions, meeting note-takers and writing assistants that quietly integrate AI features are often adopted by employees who do not think of them as "AI tools" in the first place, which makes a one-time discovery exercise insufficient on its own. This is also where regulatory exposure under frameworks like the EU AI Act tends to enter through the back door, since an unapproved tool processing regulated data is a compliance gap regardless of who chose it. Building shadow AI discovery into a recurring cadence, not a single project, matches the pace at which new entry points for sensitive data actually appear.
Frequently asked questions
Should we just block all unapproved AI tools at the network level?
Blocking without offering a sanctioned alternative tends to push usage to personal devices instead of eliminating it, which is often harder to monitor than tool use on company infrastructure. Pairing any block with a genuinely useful approved alternative produces better real-world compliance than blocking alone.
How often should we run a shadow AI discovery exercise?
Quarterly is a reasonable cadence for most companies, since new tools launch continuously and usage patterns shift as employees discover new options. An annual review alone tends to miss tools that rose and were already deeply embedded in workflows by the time the next review happens.
What is the biggest risk from shadow AI specifically?
Sensitive data, customer PII, financial figures, source code, entered into a tool with no enterprise data protection agreement, effectively leaving company control the moment it is typed in. This is usually a bigger practical risk than the AI output itself being wrong.
How Nanobase AI helps
Nanobase AI helps companies run this discovery exercise and build the resulting sanctioned-tool policy, rather than leaving shadow AI to be discovered during a security incident or a compliance audit. This work is typically bundled with the broader governance setup, including an AI usage policy and staff training, so discovery leads directly to a workable, enforced policy.
Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.