Shadow AI: What to Do When Employees Use ChatGPT with Company Data
Shadow AI is the use of AI tools your company never approved, most often employees pasting work content into personal ChatGPT accounts. About 55% of employees admit to doing it, and roughly 35% of the data they paste in is sensitive. The answer is not a ban, which pushes usage onto phones where you cannot see it. The answer is a 30-day program: discover what is in use, decide what is allowed, write the policy, stand up a sanctioned tool, and train your team on the difference.
How common is shadow AI, really?
More common than almost any IT director estimates before measuring it. UHY's middle market research found that about 55% of employees use AI tools their employer never approved. That is not a fringe behavior. That is a majority of your workforce.
The content is the bigger problem. Cyberhaven data summarized by IntuitionLabs shows roughly 35% of the information employees paste into AI tools qualifies as sensitive: source code, client records, financials, personnel matters. Employees are not doing this to cause harm. They are doing it because the tools work, and because nobody gave them a sanctioned alternative.
Meanwhile, governance lags far behind usage. A Netrio mid-market survey found 82% of mid-market firms have AI in production, but only 26% have it scaled with governance in place. That 56-point gap is where the incidents happen. Usage without rules is the default state at most companies right now, which means the companies that close the gap first hold a real advantage.
What happens to the data your team pastes into ChatGPT?
It depends entirely on the account. On consumer plans with default settings, prompts can be retained and used to improve the model. Your client's contract terms, your pricing model, your patient scheduling notes: once pasted, that content has left your control and your audit trail. You cannot produce it, delete it, or account for it.
That creates three concrete exposures:
- Contract exposure. Most client agreements and business associate agreements restrict where covered data can go. A personal AI account is a subprocessor nobody agreed to.
- Regulatory exposure. If an employee pastes a Massachusetts resident's personal information into an unapproved tool, that transfer sits outside the written information security program that 201 CMR 17.00 requires you to maintain.
- Disclosure exposure. Cyber insurance applications and enterprise security questionnaires now ask how you govern AI. Answering "we do not know what our employees use" is not an option, and answering falsely is worse.
Note what is not on that list: the model itself misbehaving. The realistic risk in 2026 is not an AI leaking your secrets to a competitor on request. It is your data resting in systems you cannot see, govern, or attest to.
Why does banning ChatGPT fail?
Because a ban does not reduce usage. It reduces visibility. Block the domain on the corporate network and usage moves to personal phones, home laptops, and whichever of the hundreds of lookalike AI tools your firewall has never heard of. Your exposure stays the same or gets worse, and your monitoring goes to zero.
Bans also fight your own interests. Your employees adopted these tools because they save real hours on drafting, summarizing, research, and code. A company that prohibits AI while competitors govern it pays twice: once in lost productivity, once in the resentment that drives quiet workarounds. The Netrio numbers above tell the story. The winners are not the firms that said no. They are the 26% that said yes with rules.
The goal is not zero AI usage. The goal is zero ungoverned AI usage.
What should you do in the next 30 days?
This is the program we run with clients, condensed. A mid-sized company can execute it in four weeks with existing staff.
- Week 1: Discover. Pull 30 days of DNS and web gateway logs and match them against a list of known AI domains. Check your identity provider for OAuth grants to AI apps. Then run a short anonymous survey with explicit amnesty: which tools, which tasks, how often. You will find 3 to 10 times more usage than you expected. That number is your baseline, not your scandal.
- Week 2: Decide. Sort what you found into three buckets: approve, approve with conditions, and block. Be honest about which data classes are in scope. "No client data in any AI tool" is a rule people will break. "Client data only in the approved tool" is a rule people can follow.
- Weeks 2 to 3: Write the acceptable use policy. Keep it to two pages. Name the approved tools, name the prohibited data types, give five worked examples of allowed and disallowed prompts, and state what an employee should do after a mistake: report it, no punishment for self-reporting. A policy nobody fears is a policy people actually follow.
- Week 3: Enable a sanctioned path. Buy enterprise seats for one general-purpose AI tool with no-training commitments, single sign-on, and retention controls. This is the step most companies skip and the one that makes everything else work. People stop using shadow tools when the sanctioned one is just as good and one click away.
- Week 4: Train. One 45-minute session: what the policy says, why it exists, live demonstration of the approved tool doing real work from your business. Close with the amnesty message again. Then repeat the discovery scan quarterly and watch the shadow number fall.
Who should own this, and what does it cost?
Somebody has to be named. In companies with 25 to 500 employees, the realistic owner is the IT director or a fractional security leader, with a business sponsor above them who can settle the policy arguments IT should not settle alone: which client data classes are off limits, and what the sanctioned tool budget is.
The costs are smaller than most executives expect. Enterprise AI seats run roughly $25 to $60 per user per month, and you rarely need them for everyone in the first wave. Discovery uses tools you already own. The policy is two pages. Training is one session. The whole program usually costs less than a single month of the productivity your team is already generating with the shadow tools, and far less than one breach notification.
Measure two numbers quarterly: the count of unapproved AI domains seen in your logs, and the share of active employees on the sanctioned tool. The first should fall while the second rises. When those lines cross, shadow AI has stopped being your problem.
Key takeaway: You cannot ban your way out of shadow AI, and you cannot ignore it onto someone else's risk register. Measure it, write a two-page policy, give people an approved tool that actually works, and re-measure every quarter. Companies that do this convert their biggest ungoverned risk into their biggest productivity gain in about 30 days.
Frequently asked questions
Is it safe for employees to use ChatGPT at work?
It can be, on the right terms. Enterprise plans for ChatGPT, Copilot, Gemini, and Claude offer contractual commitments that consumer accounts do not, including no training on your data. The risk comes from personal accounts on default settings handling client data, employee records, or regulated information. Provide a sanctioned tool and a clear policy, and most of the risk goes away.
How do we find out which AI tools employees are already using?
Three sources cover most of it: network and DNS logs from your firewall or secure web gateway, SaaS discovery through your identity provider's OAuth grant list, and an anonymous employee survey. Surveys work better than most IT teams expect when leadership promises amnesty. A shadow AI discovery exercise typically takes one to two weeks.
Do we need an AI acceptable use policy if we already have an IT policy?
Yes. Generic IT policies predate generative AI and rarely answer the questions employees actually have: which tools are approved, what data can go into them, and what happens when they make a mistake. A one to two page AI acceptable use policy closes that gap, and insurers and enterprise customers increasingly ask for it by name.
Next step
If you want a full picture of your AI exposure, our AI security assessment covers shadow AI discovery, LLM and vendor risk, data flows, and an acceptable use policy you can ship. Fixed fee, defined deliverables.
Not ready for an engagement? Take the free Business AI Maturity Assessment and get a scored baseline across six dimensions, including people, culture, and shadow AI exposure.