Cyber Security

5 Steps to Defend Against Shadow AI

Author:
Sam Kenneth
Aug 21
3 min read

Your employees are already using AI through public tools, personal accounts, browser extensions and features built into everyday applications. Whether you have approved it or not, AI is already part of how people work.

When that activity sits outside your security and governance controls, it becomes shadow AI. As I often tell customers, you can’t secure or govern what you can’t see.

But blanket bans are not the answer. They create shadow AI, not controlled usage. People may simply turn to unapproved tools, making their activity harder to see and increasing the risk to your business.

In this article, I’ll share five practical steps to manage shadow AI and enable your people to use AI safely.

Step 1: Discover how AI is really being used

Before setting up rules, you need a clear picture of what is actually happening across your organisation.

That means looking beyond approved platforms such as Copilot. Employees may also be using personal ChatGPT accounts, browser extensions or AI features built into everyday tools like Canva and Grammarly. With new services appearing constantly, a static list will never tell the full story.

At Intouch, we partner with CultureAI to provide that visibility. For example, you may have given every employee a Copilot licence, only to discover that half are not using it—or are using ChatGPT instead. CultureAI can reveal which applications and account types are being used, by whom, and whether sensitive information is being shared through prompts or uploads.

These insights can help you address risks, improve employee education and identify opportunities to optimise licence costs. The important thing is to understand the behaviour before deciding what to allow, redirect, warn against or block.

Step 2: Govern AI use with an enforceable policy

Once you understand how AI is being used, you need a policy that reflects how your people actually work.

It should define your approved tools and licence types, who can use them, and what data employees can share. It must also cover safe use cases, prompts, file uploads, exceptions and ownership.

Avoid applying the same rules to everyone. Marketing may need Claude, while sales may use ChatGPT. Your policy should support legitimate business needs with the right licences and controls rather than forcing people to find workarounds.

CultureAI can translate those requirements into practical rules based on the application, user, department, data type or action involved. Without enforcement, an AI policy is little more than a wish list.

Step 3: Protect sensitive data at the moment of risk

One of the greatest risks comes from sensitive information being shared through prompts or file uploads.

Imagine someone in marketing using a free AI account to prepare a presentation for the CEO. To save time, they upload a document containing confidential financial information. Their intention is not malicious, but the data may still be exposed.

The answer is not necessarily to block the entire application. CultureAI can allow access while detecting sensitive data and stopping a risky prompt or upload before it is submitted. It can also warn the employee or redirect them to an approved tool.

People make mistakes. The right controls protect both your people and your data at the moment it matters.

Step 4: Enable safe and productive AI adoption

I’d like to reiterate that the goal is not to prevent people from using AI. It is to give them a safe and practical way to use it.

Different teams will naturally have different needs. Marketing may use AI to develop content, sales may use it for research, and development teams may rely on coding assistants. Providing the right tools, licences and controls reduces the temptation to turn to shadow alternatives.

Safe enablement will always beat restriction. In the CultureAI dashboard, we saw adoption continue to increase after policies were applied, while higher-risk activity reduced. The guardrails did not slow innovation; they made it safer.

This requires leadership and IT to work together. With clear business direction and the right technical controls, AI governance can become a competitive advantage rather than simply a compliance exercise.

Step 5: Monitor behaviour and continuously improve

Shadow AI is not a one-time discovery exercise. New tools and embedded features appear constantly, while the way your people use AI will continue to change.

Monitor new applications, use of personal accounts, sensitive prompts, file uploads and recurring risky behaviour. You should also track whether employees are adopting approved tools and responding to your policies and guidance.

CultureAI provides live activity, risk insights, reporting and policy recommendations based on the behaviour it detects. You do not have to manage that process alone. Our cybersecurity team at Intouch can help you review the findings, apply appropriate controls and update your policies as your organisation evolves.

The principle is simple: know your data, know your prompts and know your platforms.

See it, steer it, secure it

Across these five steps, I’d like to leave you with a few final thoughts.

Start by understanding how AI is being used across your organisation. Turn those insights into a practical policy, support it with proportionate guardrails and keep reviewing the results as the technology evolves.

You should not have to choose between security and innovation. With the right governance, controls and support, you can reduce risk while giving your people the freedom to use AI productively.

If you are unsure where to begin, Intouch’s free AI risk assessment is a practical first step. Using CultureAI, our cybersecurity team can uncover your current AI usage and risks, then help you decide what to do next.

Book your free AI risk assessment and start building a safer approach to AI adoption.

ABOUT THE AUTHOR

Sam Kennett is Head of Sales at Intouch Tech, helping businesses understand their technology and cyber security needs. He focuses on clear, practical recommendations that reduce risk and support long-term business goals.

Frequently Asked Questions

No items found.
Trusted UK IT Team

Lets Start A Conversation

Tell us what you need, from AI governance and cyber security to managed IT, Microsoft 365, phones and connectivity. You'll deal with one accountable UK team that's looked after growing businesses since 2012, and leave with clear next steps.

0333 370 7000

Mon-Fri 8am-5pm · 24/7 for managed clients

[email protected]

Response within 1 business day, guaranteed

United Kingdom

UK-based team, since 2012

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.