Shadow AI: Access ≠ Approval

— by

I’ve been talking to a lot of firms about their AI policies lately, and here’s the pattern I keep running into: the policy is written for a fight that already happened. It bans ChatGPT on personal devices. It says no client PII in AI, full stop. Good rules — but they’re aimed at a threat that isn’t the main one anymore.

Here’s the thing nobody’s policy accounts for: the AI isn’t showing up as a new app someone downloads. It’s showing up inside tools you already pay for, already approved, and already trust.

Your ecosystem grew before you noticed

Every organization already has an approved AI tool at this point. If you’re a Microsoft shop, you’ve probably got Copilot by default. Maybe you went and got an enterprise license for Claude or ChatGPT instead. Either way, you’re covered — on paper.

But the tool ecosystem around that one approved AI has been quietly expanding for years. One client of mine went through three different AI slide-generation tools over three years — someone would try one, it wouldn’t click with the rest of the team, they’d move to the next. Multiply that across every department and you’ve got a technology footprint nobody fully mapped, long before you get to the actual shadow AI problem.

Where shadow AI actually lives

The real shadow AI risk isn’t a new tool at all. It’s AI getting added into tools you already have. HubSpot has Breeze. Salesforce has its own agent layer. Every meeting platform now ships a transcript-and-summary feature. These vendors aren’t asking permission — they’re turning the feature on, putting it front and center, and measuring adoption as a success metric on their end.

That creates a problem your policy never anticipated: access is being treated as permission. You can write “no client PII in AI” as clearly as you want, but if your CRM’s built-in AI feature is on by default and someone asks it a question about a lead, it’s entirely reasonable that names, emails, and account details are now flowing into an AI model — not because anyone made an active decision, but because the vendor made it the path of least resistance.

And then there’s the part outside your control entirely

The other half of this is personal devices. Tools like Granola have gotten good enough, and cheap enough, that people are running personal subscriptions just because they’re convenient. Someone hops on a call from their phone, Granola’s listening in the background, and now there’s a transcript sitting in a personal cloud account your firm has never seen.

Run that forward: it’s a confidential client call, someone’s discussing an M&A deal, and the transcript of that conversation is now stored outside your organization’s control, on infrastructure you didn’t vet, under terms you never reviewed. That’s not a hypothetical — that’s the default outcome of “it’s just easier this way.”

Key takeaways

  • A list of banned AI apps is out of date the day you write it. Vendors are adding AI features faster than IT can inventory them.
  • The policy that survives is data-based, not tool-based — define what data can never touch any AI system, regardless of which product it’s wrapped in.
  • Personal-account use is your biggest blind spot. Any policy that only governs company-issued logins misses the half of the exposure happening on people’s phones.
  • Start with an audit, not a crackdown — surveys and expense report reviews will tell you more about actual usage than any pre-approved tool list.
  • Consider an amnesty window: ask people what they’re actually using, no penalty attached, so you’re building policy around reality instead of guesses.

Want the CPE credit? Take the full lesson on EverydayCPE and earn 0.2 CPE credits: Shadow AI: Access ≠ Approval

Today’s lesson


Leave a Reply

Discover more from EverydayCPE

Subscribe now to keep reading and get access to the full archive.

Continue reading