Security

Shadow AI: the tools your staff already use

Shadow AI is any generative tool in use without a company account or a written rule. You will not invent it on a whiteboard. You will discover it in browsers, extensions, and meeting recorders. The fix is an approved list, device and browser control where we manage the endpoint, and a way to request the next tool without a lecture.

Updated 2026-09-01

How it shows up

A Chrome extension that “summarizes any page.” A meeting bot that joins Zoom and drops a transcript into a personal drive. A free chatbot with last quarter's deck pasted in because the deadline was real.

None of that requires malice. It requires a gap between the work people are asked to finish and the tools the company named.

Find, then choose

Start with an inventory, not a threat memo. Browser extensions, OAuth apps on Google or Microsoft, and “what AI did you use this month?” in a staff survey will surface more than a firewall category named AI.

Then split the list. Keep and formalize. Replace with an approved equivalent. Retire. The middle path (ignore it) is how the next incident report starts.

Controls that actually exist

On devices Tailored Tech manages we can deploy the approved apps, remove the ones you reject from the standard image, and apply browser controls that fit the policy. We cannot see a personal iPhone in the break room. Say that out loud so executives do not expect omniscience.

Identity reviews catch OAuth grants that meeting bots and “AI notetakers” like to collect. That review is as useful as a web filter and gets skipped more often.

Tie it to the AUP

Shadow AI is the discovery problem. The acceptable use article is the written rule. Do them together. A list of banned URLs with no approved substitute will recreate the same extensions in a month.

Questions & answers

Questions on this topic

Short answers for buyers comparing options.

Is shadow AI always a fire?

No. Sometimes it is a good tool used on a personal account. Formalize the good ones. Remove the ones that eat client data.

Can you block every AI site?

You can block many of them on managed browsers. People have phones. Pair blocks with an approved option.

Where do we start if we have done nothing?

Write the one-page AUP, inventory extensions and OAuth apps, pick two approved tools, and put those on the company tenant.

Want this applied to your environment?

Tell us how the business runs. We will map the model without a long pitch.

Start a conversation
Start a conversation