
5 Steps to Defend Against Shadow AI
.png)
Your employees are already using AI through public tools, personal accounts, browser extensions and features built into everyday applications. Whether you have approved it or not, AI is already part of how people work.
When that activity sits outside your security and governance controls, it becomes shadow AI. As I often tell customers, you can’t secure or govern what you can’t see.
But blanket bans are not the answer. They create shadow AI, not controlled usage. People may simply turn to unapproved tools, making their activity harder to see and increasing the risk to your business.
In this article, I’ll share five practical steps to manage shadow AI and enable your people to use AI safely.
Step 1: Discover how AI is really being used
Before setting up rules, you need a clear picture of what is actually happening across your organisation.
That means looking beyond approved platforms such as Copilot. Employees may also be using personal ChatGPT accounts, browser extensions or AI features built into everyday tools like Canva and Grammarly. With new services appearing constantly, a static list will never tell the full story.
At Intouch, we partner with CultureAI to provide that visibility. For example, you may have given every employee a Copilot licence, only to discover that half are not using it—or are using ChatGPT instead. CultureAI can reveal which applications and account types are being used, by whom, and whether sensitive information is being shared through prompts or uploads.
These insights can help you address risks, improve employee education and identify opportunities to optimise licence costs. The important thing is to understand the behaviour before deciding what to allow, redirect, warn against or block.
Step 2: Govern AI use with an enforceable policy
Once you understand how AI is being used, you need a policy that reflects how your people actually work.
It should define your approved tools and licence types, who can use them, and what data employees can share. It must also cover safe use cases, prompts, file uploads, exceptions and ownership.
Avoid applying the same rules to everyone. Marketing may need Claude, while sales may use ChatGPT. Your policy should support legitimate business needs with the right licences and controls rather than forcing people to find workarounds.
CultureAI can translate those requirements into practical rules based on the application, user, department, data type or action involved. Without enforcement, an AI policy is little more than a wish list.
Step 3: Protect sensitive data at the moment of risk
One of the greatest risks comes from sensitive information being shared through prompts or file uploads.
Imagine someone in marketing using a free AI account to prepare a presentation for the CEO. To save time, they upload a document containing confidential financial information. Their intention is not malicious, but the data may still be exposed.
The answer is not necessarily to block the entire application. CultureAI can allow access while detecting sensitive data and stopping a risky prompt or upload before it is submitted. It can also warn the employee or redirect them to an approved tool.
People make mistakes. The right controls protect both your people and your data at the moment it matters.
Step 4: Enable safe and productive AI adoption
I’d like to reiterate that the goal is not to prevent people from using AI. It is to give them a safe and practical way to use it.
Different teams will naturally have different needs. Marketing may use AI to develop content, sales may use it for research, and development teams may rely on coding assistants. Providing the right tools, licences and controls reduces the temptation to turn to shadow alternatives.
Safe enablement will always beat restriction. In the CultureAI dashboard, we saw adoption continue to increase after policies were applied, while higher-risk activity reduced. The guardrails did not slow innovation; they made it safer.
This requires leadership and IT to work together. With clear business direction and the right technical controls, AI governance can become a competitive advantage rather than simply a compliance exercise.
Step 5: Monitor behaviour and continuously improve
Shadow AI is not a one-time discovery exercise. New tools and embedded features appear constantly, while the way your people use AI will continue to change.
Monitor new applications, use of personal accounts, sensitive prompts, file uploads and recurring risky behaviour. You should also track whether employees are adopting approved tools and responding to your policies and guidance.
CultureAI provides live activity, risk insights, reporting and policy recommendations based on the behaviour it detects. You do not have to manage that process alone. Our cybersecurity team at Intouch can help you review the findings, apply appropriate controls and update your policies as your organisation evolves.
The principle is simple: know your data, know your prompts and know your platforms.
See it, steer it, secure it
Across these five steps, I’d like to leave you with a few final thoughts.
Start by understanding how AI is being used across your organisation. Turn those insights into a practical policy, support it with proportionate guardrails and keep reviewing the results as the technology evolves.
You should not have to choose between security and innovation. With the right governance, controls and support, you can reduce risk while giving your people the freedom to use AI productively.
If you are unsure where to begin, Intouch’s free AI risk assessment is a practical first step. Using CultureAI, our cybersecurity team can uncover your current AI usage and risks, then help you decide what to do next.
Book your free AI risk assessment and start building a safer approach to AI adoption.
ABOUT THE AUTHOR
Frequently Asked Questions
Lets Start A Conversation
0333 370 7000
Mon-Fri 8am-5pm · 24/7 for managed clients
[email protected]
Response within 1 business day, guaranteed
United Kingdom
UK-based team, since 2012


