In this blog post How to Control Shadow AI Before It Exposes Your Business Data we will explain how to find unapproved AI use, reduce data leakage and give employees safer ways to work.

Your staff are probably already using AI, whether you approved it or not. They may be pasting meeting notes into ChatGPT, uploading contracts to a document summariser or connecting an AI assistant to Microsoft 365 without understanding what information it can access.

This is known as shadow AI: AI tools, accounts and features used without formal approval or oversight. The goal is not to stop employees from becoming more productive. It is to prevent sensitive business information from quietly moving into systems you cannot see, assess or control.

How shadow AI works behind the scenes

Most generative AI tools run as cloud services. When an employee enters a prompt, uploads a file or connects an application, that information leaves the employee’s device and is processed by an external provider.

The risk depends on the service, account type, settings and contract. A consumer AI account may handle business information differently from an enterprise service with stronger privacy, access and data retention controls.

There is another risk that is easier to miss. Some AI applications ask employees to approve an OAuth connection, which is the permission screen that lets one cloud service access information in another. A useful-looking assistant may request access to email, calendars, files or contacts and retain that access after the employee stops using it.

Shadow AI is therefore not simply a list of websites to block. It is a data, identity, device and governance issue.

Why blocking every AI tool usually fails

A blanket ban can look safe on paper, but it often pushes AI use further underground. Employees switch to personal devices, private email addresses or mobile applications because they are still expected to complete the same work quickly.

A better approach is to create a controlled path. Decide which tools are suitable, what information can be used with them and which activities need additional approval.

This builds on the governance foundations covered in our guide to preparing your business for Copilot and AI agents. Shadow AI control turns those governance decisions into practical day-to-day safeguards.

1. Discover what employees are already using

You cannot manage what you cannot see. Start by building an evidence-based picture of AI activity rather than sending another staff survey and hoping people remember every tool they have tried.

For organisations using Microsoft 365, Microsoft Defender for Cloud Apps can help identify cloud applications being accessed across the business. It can highlight generative AI services, usage patterns and the relative risk of different applications.

Microsoft Purview, which helps organisations identify and protect sensitive information, can provide further visibility into how data is being used with supported AI services. Depending on your licensing and setup, this can help identify risky interactions involving personal, financial or confidential information.

Your initial review should answer five questions:

  • Which AI applications are employees accessing?
  • Which departments and roles are using them?
  • Are staff using personal or company-managed accounts?
  • What files or sensitive information could be leaving the business?
  • Which applications have ongoing access to Microsoft 365 data?

This discovery phase often prevents unnecessary spending as well. You may find several teams paying separately for tools that perform the same task.

2. Give employees an approved AI option

Employees turn to shadow AI because they have a job to complete. If the approved process is slow, confusing or less useful than the public tool they found online, they will work around it.

Create a short list of approved services for common tasks such as drafting, research, meeting summaries, document review and software development. The list may include Microsoft 365 Copilot, an enterprise version of ChatGPT, Claude or a controlled AI application built in Azure.

Approval should be based on the business use, not the popularity of the product. Review how the provider handles prompts, uploaded files, retention, user access, administration, audit records and personal information.

Keep the guidance simple. Staff should be able to answer, within a minute, which tool they can use and what information they must not enter.

3. Protect the data instead of relying on memory

Training is important, but even careful employees make mistakes. Someone working against a deadline can paste a customer list or contract clause into the wrong browser window before they realise what happened.

Data loss prevention policies provide a stronger safety net. These policies recognise sensitive information and can audit, warn or block actions such as pasting text or uploading files to an unmanaged AI service.

Microsoft Purview and Microsoft Edge for Business can be configured to control how sensitive information moves from managed devices into cloud applications. Microsoft Intune, which manages and secures company devices, can also restrict unapproved applications and apply consistent settings across Windows, Apple and mobile devices.

Controls should match the risk. A public marketing brief may only require a warning, while payroll data, health information, legal advice or customer records should normally be blocked from unapproved AI services.

The business outcome is fewer accidental disclosures without forcing every harmless request through the IT department.

4. Review connected applications and AI agents

Browser history tells only part of the story. Review applications that employees have connected to Microsoft 365 and examine the permissions they were granted.

An AI scheduling tool may need calendar access, for example, but it probably does not need to read every file in SharePoint. Remove unused applications, reject excessive permissions and require administrator approval for higher-risk connections.

This becomes even more important with AI agents, which can perform actions rather than simply produce text. Our guide to controlling the security risks of AI agents explains how excessive access can turn a small mistake into a much larger incident.

For agents handling different customers or sensitive workflows, workspace isolation can keep files, tools and tasks separated. In plain English, one agent should not be able to wander through information that belongs to another team or customer.

5. Use a policy people will actually follow

A 20-page AI policy written by lawyers is unlikely to change behaviour. Most employees need a one-page guide supported by short, role-specific training.

Your policy should clearly cover:

  • Approved AI tools and account types.
  • Information that must never be entered into public AI services.
  • When human review is required before using AI-generated work.
  • How staff can request a new tool.
  • Who owns AI risk and approves exceptions.
  • How suspected data exposure should be reported.

Make the approval process quick. If a department can get a clear decision within days rather than months, it is far more likely to involve IT before adopting a new service.

A common shadow AI scenario

Consider a 200-person professional services firm. The leadership team believes staff are experimenting with one public chatbot, but a discovery review identifies multiple writing assistants, meeting tools, browser extensions and document analysers.

Several employees are using personal accounts, while one application has permission to access company email and files. Different departments are also paying for overlapping subscriptions.

The firm does not need to ban AI. It can consolidate approved tools, remove unnecessary connections, block sensitive uploads and provide clear guidance for common tasks. The result is lower software spending, better visibility and a much smaller chance of confidential client information leaving the business.

A practical 30-day control plan

  1. Week one: Identify AI websites, applications, browser extensions and Microsoft 365 connections currently in use.
  2. Week two: Classify each service as approved, restricted or blocked based on its business value and data risk.
  3. Week three: Configure device, browser, identity and data protection policies, starting in audit or warning mode to avoid disrupting legitimate work.
  4. Week four: Publish the approved tool list, train employees and create a simple process for requesting new AI services.

After rollout, continue measuring adoption, incidents, subscription costs and business value. Our guide to monitoring AI applications after deployment provides a practical framework for keeping approved AI useful and financially controlled.

Shadow AI and Australian compliance

Australian privacy obligations continue to apply when information is processed by AI. Businesses should understand what personal information is being shared, why it is needed, where it is processed and whether the chosen service is appropriate for the intended use.

The Essential Eight, the Australian Government’s cybersecurity framework that many organisations are expected or required to follow, does not directly govern AI. However, its controls around application management, access, patching and multi-factor authentication provide an important security foundation.

Shadow AI control should sit alongside those measures, not replace them.

Control the risk without losing the productivity

Shadow AI is usually a sign that employees see genuine value in the technology but have not been given a safe path to use it. The answer is visibility, sensible choices and technical safeguards rather than fear-driven bans.

CloudProInc combines more than 20 years of enterprise IT experience with practical expertise across Microsoft 365, Azure, Intune, Defender, OpenAI and Claude. As a Melbourne-based Microsoft Partner and Wiz Security Integrator, we help organisations put workable controls around AI without turning every new idea into a six-month project.

If you are not sure which AI tools are already accessing your business data, we are happy to help you take a practical look at the situation โ€” no strings attached.


Discover more from CPI Consulting

Subscribe to get the latest posts sent to your email.