The IT leader's guide to shadow AI: how to say yes safely and make it stick

Published

Quote on AI with "Blocking doesn’t remove AI. It just makes it invisible," credited to Karl Bagci, Director of IT and Information Security, Exclaimer.

Key takeaway

  • You can block a tool on the corporate network. You can't stop someone opening it on their personal phone 

  • Blocking without an alternative doesn't remove AI. It just makes it invisible to IT 

  • Only 30% of IT leaders cite loss of control as a barrier to self-service technology, rising to 39% among CTOs and CIOs, according to Exclaimer's IT research report 

  • A good AI policy needs three things: a named approved tool, clear rules on what data can go into it, and a visible escalation path when something goes wrong 

  • Data loss prevention tools that automatically obscure sensitive information before it reaches an AI model are the next serious layer of protection 

  • Saying yes doesn't increase risk. It makes the risk visible and governable, which is the only version of this problem you can actually manage 

You can block a tool. You can't stop someone using it on their personal phone. That's the whole problem with how most organizations handle shadow AI, and it's the reason the instinct to block reliably fails.  

Text on a blue background stating: "You can block a tool. You can’t stop someone using it on their personal phone."Shadow AI is what security teams call AI use that happens outside any policy or oversight. An employee pasting a document into a personal ChatGPT account, or running work through a browser extension nobody in IT approved. The fix isn't a ban. It's giving people a sanctioned route: a named tool, a clear policy, and a visible path to escalate when something goes wrong. 

 

Why does blocking AI always fail? 

The instinct to block makes sense on paper. If a tool isn't approved, isn't audited, and might send company data to a third party, stopping people from using it looks like the responsible call.

Here's what actually happens when you block a tool without giving people an alternative. They don't stop using AI. They move to a personal device, a personal account, or a browser extension nobody in IT knows exists.

Blocking without an alternative doesn't remove AI. It just makes it invisible to IT. You haven't removed the risk. You've removed your visibility into it, which is a worse position than the one you started in. 

Infographic showing 30% of IT leaders and 39% of CTOs/CIOs cite loss of control as a barrier to self-service tech. Source: Exclaimer IT Research Report.

What does a sanctioned AI policy actually contain? 

We adopted ChatGPT at Exclaimer, used it for a while, and decided it wasn't as good as Claude, so we moved everyone onto Claude instead. That's the model for how a sanctioned route should work: one named tool, rolled out company-wide, replacing whatever people had been reaching for on their own. 

A policy that makes this stick needs three specific elements: 

  • A named tool. A specific product, with a specific account, that people actually have access to. 

  • Clear data rules. What can go into it, what can't, and what the consequences are for getting that wrong. 

  • A visible escalation path. Somewhere to flag a problem or a gray area, so people don't have to guess. 

We said yes instead of no. "Yes, here's how you do it safely," rather than "No, you absolutely can't." Once that path exists, the shadow AI problem doesn't vanish, but it becomes something IT can actually see and manage, rather than something running invisibly on a phone in someone's pocket.

Where is this heading next? 

The genuinely interesting frontier here is data loss prevention built directly into AI tools.

Some products can now automatically detect and obscure sensitive information (an email address, a phone number) before it's pasted into a model at all. That's a real step forward, and it's the layer that turns "we have a policy" into "we have a policy that enforces itself." I'd rather have that structural protection sitting underneath a sanctioned tool than rely entirely on people remembering the rules. 

 

Doesn't saying yes just increase your exposure? 

This is the fair objection, and it deserves a straight answer rather than a dismissal. Sanctioning a tool does mean company data flows through a third-party model. That's real. But the alternative isn't zero exposure. It's exposure you can't see.

An unsanctioned tool on a personal device has no policy, no audit trail, and no one in IT who knows it's being used at all. A sanctioned tool has all three. Saying yes doesn't completely remove the risk, but it does convert an invisible, unmanaged risk into a visible, governable one. And that trade is worth making every time. 

Transparency always wins. Transparency builds trust, and trust is what makes people actually follow the policy instead of routing around it. If you haven't yet named your organization's approved AI and IT policy framework, that's the first fix, not the tenth. An AI problem you can see is one you can manage. One you can't see already has the run of your organization, whether you've acknowledged it yet or not.