Shadow AI Is a Growing Security Risk: 7 Policies Your Business Needs Before Staff Use ChatGPT

Fresh Mango AI
Shadow AI Is a Growing Security Risk: 7 Policies Your Business Needs Before Staff Use ChatGPT

Most organisations are already using artificial intelligence in some form. The question is whether that use is controlled.

Employees may be using ChatGPT, Gemini, Claude, transcription services, image generators or browser extensions to draft emails, summarise documents, analyse spreadsheets and prepare reports. They may be doing useful work. They may also be placing confidential information outside the organisation's control.

This is shadow AI: the use of AI tools for work without formal approval, security review, clear guidance or management oversight.

The risk is not that employees are interested in AI. The risk is that they are using it without knowing what information should not be shared, which accounts are appropriate or who is responsible for checking the output.

Recent UK research from Microsoft found that 71% of UK employees had used unapproved consumer AI tools at work, with 51% doing so every week. Only 32% said they were concerned about the privacy of company or customer data entered into those tools.

The precise AI adoption figure varies by survey and definition. The British Chambers of Commerce and Atos reported that 54% of SMEs were actively using AI in early 2026. The direction is clear: AI use is becoming normal faster than governance is being put in place.

Blocking every AI tool is not a sustainable strategy. A practical AI governance framework for business should reduce unmanaged use while giving employees a secure, approved route to useful AI.

Why shadow AI creates a business risk

Shadow AI creates several connected problems.

Data can leave your control

Employees may paste client details, pricing, contracts, employee information, technical designs or commercially sensitive plans into a consumer tool. Once shared, the organisation may not know where the information is stored, how long it is retained or who can access it.

There may be no audit trail

If staff use personal accounts, the business may be unable to establish what was entered, when it was entered or what output was produced. That makes incident investigation, client assurance and regulatory reporting more difficult.

AI output can be wrong

Generative AI produces plausible answers, not guaranteed facts. An unreviewed response can introduce errors into a contract, customer communication, financial analysis or operational decision.

Existing permissions may be exposed

AI assistants can make poorly managed access more visible. If a user already has access to an overshared folder, an AI tool may help them find information they would not otherwise have located.

The practical response is not to treat staff as the problem. It is to provide clear rules, approved tools, suitable training and proportionate controls.

Business leaders reviewing data and technology decisions together in a modern workplace

The seven policies your business needs

1. An approved tools and accounts policy

Purpose: define which AI tools staff may use and how they must access them.

Your policy should distinguish between:

  • Approved enterprise tools.
  • Tools requiring additional security review.
  • Tools that are prohibited for business use.
  • Personal accounts that must not be used for company work.

The policy should also explain why an enterprise account is different from a free consumer account. Enterprise arrangements may provide stronger administrative controls, contractual protections, access management, audit capability and data-handling commitments.

Do not simply publish a list of approved tools and leave employees to interpret the rest. State who approves new tools, what information is required for review and how staff request an alternative.

2. A data classification and handling policy

Purpose: explain what information can and cannot be entered into an AI system.

A useful policy should use categories employees already understand, such as:

  • Public information.
  • Internal business information.
  • Confidential information.
  • Personal or special category data.
  • Client-restricted or legally privileged information.

For each category, state whether it can be used with an approved AI tool and under what conditions.

For example, public information may be suitable for most tools. Internal information may require an approved business account. Client-restricted data may require explicit authorisation, anonymisation or a specific controlled workflow.

The ICO's guidance on AI and data protection makes clear that UK GDPR obligations continue to apply when personal data is processed through AI. Using an AI platform does not transfer responsibility away from your organisation.

3. A human review and accountability policy

Purpose: make clear that AI can assist with work, but responsibility remains with a named person.

The policy should identify the activities that always require human review. These may include:

  • Client advice.
  • Legal or contractual documents.
  • Financial calculations.
  • Recruitment and employment decisions.
  • Health and safety information.
  • Regulatory submissions.
  • Customer complaints.
  • Operational instructions.

Define what "review" means. It should involve checking facts, sources, calculations, tone, confidentiality and suitability for the intended audience.

Avoid vague instructions such as "use AI responsibly". Tell people who reviews the output, what they check and when they escalate an issue.

4. An identity, access and permissions policy

Purpose: prevent AI tools from exposing information that users should not be able to reach.

AI governance depends partly on existing security controls. Review:

  • User accounts and leavers' access.
  • Multi-factor authentication.
  • Guest accounts.
  • External sharing links.
  • Administrative privileges.
  • Shared mailboxes and folders.
  • Inherited permissions.
  • Access to sensitive data.

An AI assistant cannot correct poor information governance. If a team has access to confidential files unnecessarily, the risk exists before AI is introduced.

The Fresh Mango AI Governance & Security Project reviews these areas alongside data classification, acceptable-use guidance, audit and logging recommendations.

Fix permissions first. Then decide which AI capabilities are appropriate.

5. A prompt, output and records policy

Purpose: establish how staff handle information before, during and after an AI interaction.

Staff should understand that prompts and outputs can contain business information even when they appear to be informal notes. The policy should cover:

  • Removing unnecessary personal or confidential information.
  • Anonymising examples where possible.
  • Checking whether uploaded files are permitted.
  • Storing useful outputs in approved business systems.
  • Recording material AI assistance where appropriate.
  • Avoiding the presentation of AI-generated content as independently verified work.

This is particularly important in professional services, manufacturing, logistics and hospitality, where AI output may feed into client work, production records, schedules, supplier communications or customer decisions.

6. An incident reporting and escalation policy

Purpose: give employees a clear response when something goes wrong.

People need to know what to do if they:

  • Paste sensitive information into an unapproved tool.
  • Receive an unexpected or unsafe output.
  • Discover a fake or malicious AI service.
  • Find that an AI-generated document contains confidential information.
  • Suspect that an account or browser extension is compromised.

Make reporting straightforward. Tell staff who to contact, what information to provide and what not to do next. Do not create a process so complicated that employees delay reporting while trying to resolve the issue themselves.

Early reporting usually gives the organisation more options. It allows IT, security, legal and management teams to assess the situation before the information spreads further.

7. A training, monitoring and review policy

Purpose: ensure that the rules are understood, applied and updated.

Training is a prerequisite. A policy that employees cannot apply in daily work will not control shadow AI.

Training should use realistic examples from your organisation. Show staff how to:

  • Select an approved tool.
  • Identify sensitive information.
  • Improve a prompt without exposing data.
  • Check an AI-generated response.
  • Recognise unreliable or manipulated output.
  • Report a mistake.

Monitoring should be proportionate and transparent. Review approved-tool usage, new applications, unusual data movement, access changes and policy breaches where your systems support it.

Review the policy at least quarterly during the early adoption period. New tools, features, suppliers and working practices will create new questions.

AI readiness assessment with business professionals reviewing a structured adoption plan

How to put the policies into practice

A policy document alone will not solve shadow AI. Use a controlled implementation sequence.

1. Assess

Identify where AI is already being used, formally and informally. Speak to department leads and review available application, identity and data-access information.

Start with the highest-cost processes. This helps you understand both the risk and the potential value.

2. Govern

Approve suitable tools, define prohibited data, assign ownership and create the seven policies above. Record unresolved risks in a practical register with named owners.

3. Enable

Give employees a secure alternative to consumer tools. Provide role-based training, prompt libraries and examples that match their work.

4. Build

Where a use case is repeatable and valuable, consider a controlled workflow, assistant or agent grounded in approved business knowledge.

5. Sustain

Review usage, incidents, adoption and value regularly. A Quarterly AI Success Review can provide an independent checkpoint as tools and behaviours change.

6. Transform

Only after the controls and evidence are in place should you consider wider process redesign, automation, AI agents or robotics.

This six-stage method: assess, govern, enable, build, sustain and transform, supports a secure AI implementation for your business without treating every department or use case in the same way.

What good governance should achieve

A well-designed AI adoption strategy for SMBs and larger organisations should produce measurable outcomes:

  • Fewer unapproved AI tools and personal accounts.
  • Clearer handling of confidential and personal data.
  • Faster reporting of mistakes and potential incidents.
  • Better visibility of AI usage and ownership.
  • More consistent human review.
  • Safer adoption of useful tools.
  • Evidence of hours released from repetitive work.

Measure the outcome, not only the number of licences purchased. Establish a baseline for the task before introducing AI, then review time spent, cycle time, rework, quality indicators and staff adoption.

AI should support judgement, not remove accountability.

What should happen next?

If staff are already using ChatGPT or other consumer AI tools, assume that shadow AI exists. That is not a reason for alarm. It is a reason to establish visibility and control.

Fresh Mango AI starts with the business process, the data involved and the level of risk that is proportionate to your organisation. We are platform-independent and governance- and security-focused from day one.

If you want to discuss your current position, book a free 30-minute discovery session. There is no obligation, and you will speak directly with an AI consultant about your objectives, current tools, data risks and practical next steps.

If a meeting is not appropriate yet, you can request information instead.

Fresh Mango AI specialists reviewing an AI adoption plan with a business client

Book a free 30-minute discovery session

Discuss your EU AI Act exposure, current AI governance and the most practical next steps for your organisation. No obligation.

Your next step

Not Sure Where to Start?

Whether you're exploring AI for the first time or looking to scale existing AI initiatives, our specialists can help you identify practical opportunities and avoid common pitfalls.

Fresh Mango AI specialists reviewing an AI adoption plan with a business client
Book Free Discovery Session