AI on the Clock mehmeterkek.com

Nº 004 · SECURITY · 6 August 2026

What Is Shadow AI? Why Banning AI Tools Makes the Risk Worse

Employees are already using AI at work through personal accounts and browser extensions nobody approved. Banning it does not remove the risk — it removes your visibility of it.

Shadow AI defined: AI tools employees use for work without formal review or approval — free chatbots, browser extensions, meeting note-takers, coding assistants. Your employees are already using it; the question is what they are pasting into it.
The reality: this is not coming, it is already in your building. Employees sign up with work emails, install browser extensions that quietly retain every page they visit, and paste customer data into free tools. None of it appears in a procurement system.
The numbers from the Verizon DBIR 2026: 858,440 AI-upload policy violations analysed, source code the most-uploaded data type by a wide margin, and more than 15% of users running unauthorised AI browser extensions.
Why bans fail: a ban does not remove the risk, it hides it. Where AI is banned, usage continues on personal phones and accounts, far harder to monitor. You did not remove the risk. You removed the logs.
What it costs. Data: source code, contracts and customer records leaving your perimeter. Legal: GDPR fines up to 4% of global annual turnover. Persistence: once data is retained beyond your control, removing its influence may be impossible.
What works instead, in four steps: see it by auditing actual use before writing policy; replace it with a sanctioned tool that is genuinely better, not merely approved; draw lines naming what may never be pasted; and make the safe path faster than the shadow one.
Start Monday with three questions. Ask IT which AI domains show up in the network logs. Ask a team lead which tool they actually use and why that one. Ask Legal whether anyone has reviewed where the data ends up.
Shadow AI is not a discipline problem, it is a product gap. People reach for these tools because they work. Make the safe path the fastest one.

Download the deck (PDF, 8 pages) Read the original on LinkedIn

Every company has shadow AI. Very few can see it. Employees sign up with work emails, install browser extensions that quietly retain the context of every page they visit, and paste customer complaints, contracts and code into free tools — none of which ever went through a procurement process.

The instinct is to ban it. That instinct is the mistake this post is about.

The numbers are not small

The 2026 Verizon Data Breach Investigations Report analysed 858,440 policy violations involving uploads to generative AI tools. The most-uploaded data type was source code, by a wide margin. The same report found more than 15% of users had unauthorised AI browser extensions installed.

Separately, industry surveys put roughly one in four employees at having entered confidential company information into a public AI tool.

A ban does not remove the risk. It hides it.

This is the part most leaders get wrong. Where bans exist, usage tends to continue — on personal phones, on personal accounts, outside anything you can monitor or govern. The behaviour moves. The exposure does not.

What you actually lose is visibility. You did not remove the risk. You removed the logs.

What it costs when it goes wrong

  • Data. Source code, contracts and customer records leaving your perimeter, with no record that they left.
  • Legal. Under GDPR, fines can reach up to 4% of global annual turnover, and the EU AI Act adds obligations of its own.
  • Persistence. Once sensitive data is retained beyond your control, or incorporated into model training, removing its influence may be difficult or impossible.

What works instead

  • See it. Audit what is genuinely in use before writing a single line of policy. You cannot govern what you have not measured.
  • Replace it. Provide a sanctioned tool that is actually better — not merely approved. Approved and worse loses every time.
  • Draw lines. Name what may never be pasted anywhere: personal data, source code, contracts, unreleased financials.
  • Make it easy. If the safe path is slower than the shadow one, people will route around it. Every time.

Three questions to ask on Monday

  • IT: which AI domains appear in our network logs?
  • A team lead: which tool do you actually use, and why that one?
  • Legal: has anyone reviewed where this data ends up?

Shadow AI is not a discipline problem. It is a product gap. People reach for these tools because they work. The fix is not a stricter policy — it is making the safe path the fastest one.