Contents
Governance and rollout

Shadow AI: why banning fails, and what replaces it

Blocking public generative AI tools looks like the safest answer. In practice, usage carries on, on other devices and without any trace, and the organisation loses the one thing it had: visibility. This guide explains why, what to keep from the ban, and what replaces it.

Published September 22, 2026

How shadow AI differs from shadow IT

Shadow AI is the use of generative AI tools that the organisation has neither chosen nor framed: a public assistant opened in a browser, an extension that summarises web pages, an AI feature switched on in an online application already in use, an app on a personal phone.

Classic shadow IT meant software installed without permission or an unapproved storage service. It could be spotted, uninstalled, its domain blocked. Shadow AI differs on three points:

  • The data leaves inside the request. There is no file to exfiltrate: the user pastes a contract, a customer spreadsheet or a piece of code into a text box, and the data has left your information system.
  • Nothing is installed. A browser tab or a phone is enough. The software inventory sees nothing.
  • AI arrives through approved tools. Generative AI features appear in software you have already approved, sometimes switched on by default in an update.

The main risk is therefore not the tool itself, but the data that goes into it, and the fact that nobody knows which data.

Why banning fails

An outright ban is the most common response, and the least effective. It fails for four reasons, which add up.

The need is real

People use these tools to save time on concrete tasks: rewording a letter, summarising a document, translating, writing a spreadsheet formula. Banning the tool does not remove the need. As long as there is no alternative, the individual calculation stays the same: the gain is immediate, the risk seems remote.

Blocking leaks

Network filtering stops known domains, on managed devices, on the premises. It does not see the personal phone, the home computer, the new tool that appeared last month, or the AI feature built into an approved application. Every blocked domain pushes usage towards a less visible channel.

A ban produces silence

When usage is forbidden, nobody declares it. Nobody asks whether a document may be submitted, nobody reports that sensitive data went out by mistake. The organisation loses the information it would need to correct course: which needs, which volumes, which data.

It treats all data the same way

Rewording an email with no confidential content and submitting a customer list fall under the same ban. The rule loses credibility on the harmless case, and that loss spreads to the serious one.

What to keep from the ban

Dropping the blanket ban does not mean allowing everything. Part of the rule must stay firm. ANSSI, the French national cybersecurity agency, in its security recommendations for a generative AI system, advises against using generative AI tools on the internet for professional purposes involving sensitive data (recommendation R34). It names in particular personal data, contractual, legal or financial data, and secrets such as passwords or API keys.

The right rule is therefore not about the tool, but about the combination of data and tool:

Data categoryPublic, non-contracted toolGoverned internal tool
Public informationToleratedAllowed
Internal documents with no sensitive dataDiscouragedAllowed
Personal data: customers, employeesForbiddenAllowed according to rights
Contractual, legal, financial dataForbiddenAllowed according to rights
Secrets (passwords, keys, sensitive code)ForbiddenForbidden in requests

A ban targeted at sensitive data is understandable, and therefore defensible. It only holds if the right-hand column really exists.

What replaces it: a governed internal alternative

The only measure that durably reduces shadow AI is an approved alternative that users prefer. This point is decisive: if the internal tool is slower, less capable or harder to reach than the public one, it replaces nothing.

As useful

Models comparable to the public tools, for the same everyday tasks: drafting, summarising, translating, analysing a document.

More useful

What the public tool cannot do: reach internal documents according to each person's rights, accept the data the policy forbids elsewhere.

Frictionless

Sign-in with the company account, access open to everyone within days, no justification needed for everyday uses.

Governed

Model catalogue, group rights, consumption caps, logs: what lets you open it widely without losing control.

The four conditions for an internal alternative to genuinely replace public tools.

The second card matters most. An internal tool that merely copies the public one, with more constraints, loses the comparison. One that answers questions about internal procedures, finds a document in the company's knowledge base or handles a customer file safely wins it.

This alternative sits within a wider framework (roles, usage policy, catalogue, traceability, costs), described in the guide on generative AI governance in the enterprise. For uses that go through an external provider, pseudonymisation before sending widens what can be submitted.

Measure, before and after

Without measurement, shadow AI remains an impression, and so does the effect of the alternative. Measurement happens in two stages, and always in aggregate: the aim is to understand usage, not to monitor individuals. Prepare it with your DPO, in line with the rules on informing employees.

  1. BaselineVolume of access to known public AI services from managed devices, by broad tool category, over a few weeks. Complemented by an anonymous survey on uses and needs.
  2. Opening the alternativeGradual rollout, population by population, starting with those who used public tools the most.
  3. Tracking adoptionActive users on the internal tool, types of use, requests for new use cases or new document sources.
  4. Tracking the shiftChange in the volume of access to public tools for the same populations. This is the indicator that tells you whether the alternative replaces usage or adds to it.
The measure that counts is the shift in usage, not the number of accounts opened.

A good sign: requests start coming in. When users ask for a new source, model or connector, usage has come out of the shadows. A bad sign: many accounts opened, few active users, and a stable volume of access to public tools.

Mistakes to avoid

Announcing the ban before the alternative

Banning first and promising a tool “in a few months” locks in workaround habits. The reverse order works: open the alternative, then tighten the rule on sensitive data.

Restricting the internal tool until it is useless

A less capable model, quotas set too low, access only on justified request: every restriction added without reason sends people back to the public tool. Caps are there to spot excess, not to discourage normal use.

Measuring people instead of usage

Named monitoring of access destroys the trust needed for usage to surface, and raises legal questions of its own. Aggregate measurement is enough to steer.

Forgetting AI built into approved tools

AI features switched on in software you have already approved fall under the same policy. Check their configuration and the data they can reach at every major update.

Frequently asked questions

Should we block ChatGPT and other public tools?

Block uses involving sensitive data, yes; block the tool for every use, rarely. A blanket block with no alternative moves usage to devices and channels the organisation cannot see.

How can we tell whether employees use unapproved AI tools?

Through aggregate measurement of access to known AI services from managed devices, complemented by an anonymous survey. It does not capture personal devices, which is why you should also track adoption of the internal alternative.

Is an acceptable use policy enough to deal with shadow AI?

No. A policy sets the rule, but only changes behaviour if an approved tool meets the same need. Without an alternative, it becomes a document everyone knows how to get around.

Where SmartAGT fits

SmartAGT serves as a governed internal alternative: an agent platform deployed on-premise, with fully local models or cloud providers contracted directly by the company. In hybrid mode, a privacy vault, once enabled, pseudonymises direct identifiers before any outbound call.

Agents reach company documents and tools with each user's own rights, under quotas and caps per user or per group, with cost tracked in real money. See the platform overview.

SOVEREIGN BY ARCHITECTURE

A question these guides
do not settle?