Shadow AI: why banning fails, and what replaces it
Blocking public generative AI tools looks like the safest answer. In practice, usage carries on, on other devices and without any trace, and the organisation loses the one thing it had: visibility. This guide explains why, what to keep from the ban, and what replaces it.
Published September 22, 2026
How shadow AI differs from shadow IT
Shadow AI is the use of generative AI tools that the organisation has neither chosen nor framed: a public assistant opened in a browser, an extension that summarises web pages, an AI feature switched on in an online application already in use, an app on a personal phone.
Classic shadow IT meant software installed without permission or an unapproved storage service. It could be spotted, uninstalled, its domain blocked. Shadow AI differs on three points:
- The data leaves inside the request. There is no file to exfiltrate: the user pastes a contract, a customer spreadsheet or a piece of code into a text box, and the data has left your information system.
- Nothing is installed. A browser tab or a phone is enough. The software inventory sees nothing.
- AI arrives through approved tools. Generative AI features appear in software you have already approved, sometimes switched on by default in an update.
The main risk is therefore not the tool itself, but the data that goes into it, and the fact that nobody knows which data.
Why banning fails
An outright ban is the most common response, and the least effective. It fails for four reasons, which add up.
The need is real
People use these tools to save time on concrete tasks: rewording a letter, summarising a document, translating, writing a spreadsheet formula. Banning the tool does not remove the need. As long as there is no alternative, the individual calculation stays the same: the gain is immediate, the risk seems remote.
Blocking leaks
Network filtering stops known domains, on managed devices, on the premises. It does not see the personal phone, the home computer, the new tool that appeared last month, or the AI feature built into an approved application. Every blocked domain pushes usage towards a less visible channel.
A ban produces silence
When usage is forbidden, nobody declares it. Nobody asks whether a document may be submitted, nobody reports that sensitive data went out by mistake. The organisation loses the information it would need to correct course: which needs, which volumes, which data.
It treats all data the same way
Rewording an email with no confidential content and submitting a customer list fall under the same ban. The rule loses credibility on the harmless case, and that loss spreads to the serious one.
What to keep from the ban
Dropping the blanket ban does not mean allowing everything. Part of the rule must stay firm. ANSSI, the French national cybersecurity agency, in its security recommendations for a generative AI system, advises against using generative AI tools on the internet for professional purposes involving sensitive data (recommendation R34). It names in particular personal data, contractual, legal or financial data, and secrets such as passwords or API keys.
The right rule is therefore not about the tool, but about the combination of data and tool:
| Data category | Public, non-contracted tool | Governed internal tool |
|---|---|---|
| Public information | Tolerated | Allowed |
| Internal documents with no sensitive data | Discouraged | Allowed |
| Personal data: customers, employees | Forbidden | Allowed according to rights |
| Contractual, legal, financial data | Forbidden | Allowed according to rights |
| Secrets (passwords, keys, sensitive code) | Forbidden | Forbidden in requests |
A ban targeted at sensitive data is understandable, and therefore defensible. It only holds if the right-hand column really exists.
What replaces it: a governed internal alternative
The only measure that durably reduces shadow AI is an approved alternative that users prefer. This point is decisive: if the internal tool is slower, less capable or harder to reach than the public one, it replaces nothing.
Models comparable to the public tools, for the same everyday tasks: drafting, summarising, translating, analysing a document.
What the public tool cannot do: reach internal documents according to each person's rights, accept the data the policy forbids elsewhere.
Sign-in with the company account, access open to everyone within days, no justification needed for everyday uses.
Model catalogue, group rights, consumption caps, logs: what lets you open it widely without losing control.
The second card matters most. An internal tool that merely copies the public one, with more constraints, loses the comparison. One that answers questions about internal procedures, finds a document in the company's knowledge base or handles a customer file safely wins it.
This alternative sits within a wider framework (roles, usage policy, catalogue, traceability, costs), described in the guide on generative AI governance in the enterprise. For uses that go through an external provider, pseudonymisation before sending widens what can be submitted.
Measure, before and after
Without measurement, shadow AI remains an impression, and so does the effect of the alternative. Measurement happens in two stages, and always in aggregate: the aim is to understand usage, not to monitor individuals. Prepare it with your DPO, in line with the rules on informing employees.
- BaselineVolume of access to known public AI services from managed devices, by broad tool category, over a few weeks. Complemented by an anonymous survey on uses and needs.
- Opening the alternativeGradual rollout, population by population, starting with those who used public tools the most.
- Tracking adoptionActive users on the internal tool, types of use, requests for new use cases or new document sources.
- Tracking the shiftChange in the volume of access to public tools for the same populations. This is the indicator that tells you whether the alternative replaces usage or adds to it.
A good sign: requests start coming in. When users ask for a new source, model or connector, usage has come out of the shadows. A bad sign: many accounts opened, few active users, and a stable volume of access to public tools.
Mistakes to avoid
Announcing the ban before the alternative
Banning first and promising a tool “in a few months” locks in workaround habits. The reverse order works: open the alternative, then tighten the rule on sensitive data.
Restricting the internal tool until it is useless
A less capable model, quotas set too low, access only on justified request: every restriction added without reason sends people back to the public tool. Caps are there to spot excess, not to discourage normal use.
Measuring people instead of usage
Named monitoring of access destroys the trust needed for usage to surface, and raises legal questions of its own. Aggregate measurement is enough to steer.
Forgetting AI built into approved tools
AI features switched on in software you have already approved fall under the same policy. Check their configuration and the data they can reach at every major update.
Frequently asked questions
Should we block ChatGPT and other public tools?
Block uses involving sensitive data, yes; block the tool for every use, rarely. A blanket block with no alternative moves usage to devices and channels the organisation cannot see.
How can we tell whether employees use unapproved AI tools?
Through aggregate measurement of access to known AI services from managed devices, complemented by an anonymous survey. It does not capture personal devices, which is why you should also track adoption of the internal alternative.
Is an acceptable use policy enough to deal with shadow AI?
No. A policy sets the rule, but only changes behaviour if an approved tool meets the same need. Without an alternative, it becomes a document everyone knows how to get around.
Where SmartAGT fits
SmartAGT serves as a governed internal alternative: an agent platform deployed on-premise, with fully local models or cloud providers contracted directly by the company. In hybrid mode, a privacy vault, once enabled, pseudonymises direct identifiers before any outbound call.
Agents reach company documents and tools with each user's own rights, under quotas and caps per user or per group, with cost tracked in real money. See the platform overview.