Governed AI for Operators Governance and risk

Free preview Lesson 6 of 10 10 min read

Finding and governing shadow AI

Somewhere in your business, right now, an employee is pasting something into an AI tool nobody approved. It is probably not malicious. It is almost certainly faster than the sanctioned alternative, which may not exist. This is shadow AI: the AI capability running inside your organization without anyone in charge knowing it is there. You cannot govern what you cannot see, and the first job of governance is not writing a policy. It is finding out what is already happening.

The temptation is to respond by banning tools. That instinct is understandable and it does not work. A ban moves the behavior off the corporate network and onto personal devices, where you lose even the little visibility you had. Worse, a blanket ban penalizes the large share of AI use that is low-risk and genuinely useful in order to stop the small share that is dangerous. The senior move is to get ahead of what is happening, not to pretend you can stop it by decree. This lesson is a method for doing that.

Step one: run a real discovery

You do not know what is in use, and assuming you do is how this goes wrong. Discovery means building an actual inventory from several angles, because no single source sees everything.

  • Ask people directly, without punishment. Run a short, anonymous survey asking which AI tools employees use for work and what they use them for. Make it explicit that the goal is to support them, not to catch them. If people fear consequences, they will not tell you the truth, and an inaccurate inventory is worse than none because it gives you false confidence.
  • Audit what you are already paying for. Comb your software spend and expense reports for AI subscriptions, including small personal-card charges. Individual seats bought outside procurement are a common blind spot.
  • Look at the tools you already own. Many established platforms have switched on AI features in routine updates that nobody explicitly enabled. Check whether your existing systems are now sending data to a model you never evaluated.
  • Pull network or proxy logs if you have them. Traffic to known AI endpoints tells you what tools are in use even when nobody reported them. This catches browser extensions and consumer apps that a survey misses.

Most organizations are surprised by the length of the list. Browser extensions, AI features buried inside tools they already trusted, and consumer accounts reached from personal devices all tend to surface. Finishing this step, actually completing the inventory, is where the majority of teams stall. Everything after it is comparatively easy.

Step two: assess the risk of each item

Not all shadow AI carries the same weight, and treating it as if it does wastes effort you need for the genuinely risky cases. Sort each tool using the same logic you used for risk tiers earlier in the course: look at the sensitivity of the data going into it and the cost of a bad outcome, and let the higher of the two set the level.

  • Low. The tool touches only public or non-sensitive information. Someone brainstorming from a public article or drafting a generic outline. The main exposure is output quality, not data loss. These are not your problem to solve first.
  • Elevated. The tool touches internal but unregulated data, and the risk turns on the vendor’s retention terms and whether any data-processing agreement exists. An AI feature reading internal documents sits here. Recoverable, but worth formalizing.
  • High. The tool receives regulated or personal data, customer records, health or financial information, source code, or anything covered by a law or a contract, especially through a personal account with no enterprise controls. This is where a single incident becomes expensive and hard to reverse.

The assessment does not need to be elaborate. A spreadsheet with the tool name, the data types it touches, whether a data agreement is in place, and an assigned level is enough to start acting. Precision matters less than coverage. Every tool from discovery should get a row.

Step three: bring it under governance without killing productivity

Here is the part that separates governance from prohibition. For each risk level, the response is different, and the aim throughout is to keep the value while removing the exposure.

  • Sanction the low-risk tools outright. Stop spending governance energy on things that pose little real risk. Tell people clearly they are approved. This buys you credibility for the restrictions that follow, because employees can see you are not just saying no to everything.
  • Formalize the elevated ones. Get a data-processing agreement in place, switch on enterprise settings, turn off any training on your data, and add the tool to an approved list. The tool stays; the exposure comes down.
  • Replace the high-risk behavior with a governed path. If people are using a consumer account to process customer data, the answer is not to ban the behavior, because the behavior is productive. The answer is to give them a sanctioned version, an enterprise deployment with an agreement in place and data boundaries configured, that does the same job safely. Ban the exposure, not the capability.

The principle underneath all three is that people route around controls only when the sanctioned option is worse than the shadow one. Make the governed path the productive path and the shadow usage dries up on its own, because there is no longer a reason to reach for the unapproved tool.

This is also where an acceptable-use policy becomes concrete rather than aspirational. A policy that works is short and specific about four things: which tools are approved and for what, which data categories may never enter any AI system regardless of tool, what an employee does when they want something new, and who owns enforcement. “Use AI responsibly” gives no guidance. “Never paste customer records into any tool not on this list” does.

Step four: keep it current

Shadow AI is not a one-time cleanup. New tools appear, vendors add AI features in updates, and new hires bring habits from their last employer. An inventory is accurate the day you build it and starts drifting immediately.

Governance that lasts has a cadence. A periodic review of new tools entering the business. Ongoing monitoring for traffic to AI endpoints you have not seen before. A simple intake path so an employee who wants a new tool can raise a hand instead of quietly adopting it. And a regular refresh of the policy itself, so it keeps pace with what people are actually doing rather than describing a world that no longer exists.

Where this fits

This lesson pairs closely with the audit trails work just before it: once you have brought shadow tools under governance, the logging discipline from that lesson is what keeps them visible over time. It also builds directly on the risk tiers and approval gates you set earlier, applying the same sorting logic to tools you did not deploy on purpose. The hard part of shadow AI is that manual discovery is point-in-time, accurate when you run it and stale soon after. The Command Center build addresses that by making the sanctioned tools the ones that are already logged and permissioned, so the productive path and the governed path are the same path. If you want a starting read on where your own exposure sits, the free tools on the site are a practical first pass before you commit to a full program.

Want the full course when it opens?

No spam. Unsubscribe anytime.