The Shadow AI Policy Your IT Team Actually Needs (With Template)

A friendly robot assistant and an office worker exchanging devices

Somewhere in your company, in the last hour, someone pasted work data into a personal ChatGPT account. A customer list to “clean up the formatting.” A contract clause to “explain this in plain English.” A pricing sheet to “help me write this proposal.”

I’ve spent 25+ years in enterprise IT, and I’ve watched this movie before: with USB drives, with Dropbox, with personal Gmail. Shadow IT always follows the same script: employees find a tool that makes their job easier, IT finds out later, and the response is a ban that drives usage underground instead of stopping it. Shadow AI is the same script with higher stakes, because the data doesn’t just move; it can be retained under terms nobody in your company has read.

Why the ban-first instinct backfires

When I assess mid-size IT teams, this is how the assessment asks about shadow AI, and the 0 to 4 ladder I score it against:

S1. Which statement best describes employee use of AI tools today?

  1. We don’t know what AI tools people are using
  2. People use public AI tools with work data; we have no controls yet
  3. We block some public tools but offer no approved alternative
  4. We provide approved AI tools and discourage or block unapproved ones
  5. Approved enterprise AI tools for everyone; unapproved use is monitored and blocked

Notice that blocking public tools without offering an approved alternative scores a 2 out of 4, barely better than doing nothing. That’s deliberate. Blocking ChatGPT on the corporate network while offering no approved option doesn’t end AI use; it moves it to personal phones, where you have zero visibility, zero logging, and zero recourse. The productivity demand is real. Policy that ignores demand doesn’t govern it. It just blinds you to it.

The policy that actually works: three tiers, one approved tool

Every effective AI acceptable-use policy I’ve seen shares the same skeleton. It fits on one page, and your team can draft it this week. Here’s the template.

1. Three data tiers, in plain English

  • Never in any AI tool: customer personal data, employee/HR records, financial results before release, credentials and keys, anything under legal hold. (Adjust for your regulations, such as SOX, HIPAA, and state privacy laws.)
  • Only in approved tools: internal documents, code, process documentation, drafts containing company information.
  • Fine anywhere: public information, general questions, learning. Nobody needs permission to ask an AI how a VLOOKUP works.

2. Name the approved tools explicitly

“Use approved tools” fails if nobody knows what’s approved. Name them: “Microsoft 365 Copilot and Claude Enterprise are approved for Tier 2 data” beats a page of legalese. If you’re a Microsoft shop, start with the enterprise-grade assistant already in your licensing, with enterprise data protection confirmed in writing, before buying anything new.

3. Say what happens with violations

Proportionate and honest: first instance is a conversation and retraining, patterns go through your existing HR process. The goal is changed behavior, not fear. Scared employees don’t stop using AI; they stop telling you about it.

4. Ten-minute training, tracked acknowledgment

Publish through the policy tool you already use, require acknowledgment, and run a ten-minute walkthrough with real examples from your company’s work: “here’s a customer email; which tier?” Ten minutes of concrete examples beats an hour of policy prose.

The one-page template

Here’s the policy itself. Copy it, replace the bracketed parts, and have HR and legal review it before you publish. It’s deliberately short: a policy people actually read beats a thorough one they skim.

[Company] AI Use Policy
Owner: [name, role]. Effective: [date]. Next review: [date plus six months].

1. Why this policy exists. AI tools can make our work faster. They can also expose customer, employee, and company information if we use the wrong tool with the wrong data. This policy tells you which tools to use and what you can put into them.

2. Approved tools. [Tool 1] and [Tool 2] are approved for company information when you’re signed in with your work account. The current list is always at [intranet link].

3. What you can put where.
Never in any AI tool: [customer personal data, employee records, unreleased financial results, passwords and keys, anything under legal hold].
Only in approved tools: internal documents, code, process documentation, and drafts containing company information.
Fine in any tool: public information, general questions, and learning.

4. Your responsibilities. Check AI output before you rely on it or send it to anyone. You’re accountable for the work you submit, however it was produced. Don’t connect AI apps or browser extensions to your work email, files, or calendar unless they’re on the approved list.

5. Asking for a new tool. Request it at [link]. We aim to answer within [two weeks].

6. If something goes wrong. If you think you’ve put restricted data into an unapproved tool, tell [contact] the same day. Reporting quickly is what matters, and honest mistakes reported promptly are handled as a conversation, not a disciplinary matter.

7. Monitoring. We monitor the use of AI services on company devices and networks to understand demand and protect data. [Adjust this notice to your local requirements.]

Seven short sections. If yours runs past one page, cut until it doesn’t; the detail belongs in training and in the approved-tools list, not in the policy.

Handle new tool requests fast, or they’ll go around you

The quickest way to recreate shadow AI is a request process that takes three months. Keep it light: a short form asking what the tool is, what problem it solves, what data would go into it, who else would use it, and whether the vendor trains on customer data. Answer within two weeks, even if the answer is “not yet.” Most requests turn out to be for something your approved tool already does, which makes the answer a five-minute training conversation rather than a procurement project. For the rest, the difference between the consumer and business versions of the same product usually decides it; consumer AI vs. enterprise AI covers what to check.

The order of operations matters more than the wording

Here’s the sequence that works, drawn from the 90-day plans I build for assessment clients:

  1. Week 1–2: Stand up the approved tool first. The demand needs somewhere safe to go before you restrict anything.
  2. Week 2–3: Publish the policy and run the training, announcing the approved tool in the same breath. The message is “here’s how to use AI here,” not “stop using AI.”
  3. Week 4+: Now move your web filter from monitoring to warn-or-block on unapproved AI sites, and review the logs monthly. Watch the numbers: unapproved usage should fall steadily once the approved path exists. If it doesn’t, your approved tool isn’t good enough. That’s product feedback, not a compliance problem.

Two supporting moves make the policy durable: add AI questions to your vendor security reviews (ask “does any AI feature retain our data or train on it?” at every renewal, because AI features are switching on inside SaaS tools you already pay for), and keep a simple AI inventory (which tools, which data, which owner) so you can answer an auditor or a customer questionnaire without a scramble.

Shadow AI is one question of 24

In the AI Readiness assessment, shadow AI is a red-flag question: score low here and it surfaces at the top of your risk list no matter what your overall score is, because uncontrolled data flow into public AI is the fastest-compounding risk a mid-size org carries. The free 10-question version takes three minutes and will tell you where you stand on this and five other dimensions.

Get your free AI Readiness Score →

Related: before you switch on an AI assistant in Microsoft 365, read Fix SharePoint Oversharing Before You Turn On Copilot, the other red flag I see most often. And if your team needs an AI skills baseline to run all this, start with the best AI certifications, ranked.

Related guides

Frequently asked questions

Should we block ChatGPT and other public AI tools?

Not as a first step. Blocking without an approved alternative moves AI use onto personal phones, where you have no visibility at all. Provide an approved tool first, publish a policy, and then warn about or block unapproved sites.

What are the three data tiers in a shadow AI policy?

Never in any AI tool: customer personal data, HR records, unreleased financials, credentials, and anything under legal hold. Only in approved tools: internal documents, code, and drafts containing company information. Fine anywhere: public information, general questions, and learning.

How should we handle employees who break the AI policy?

Proportionately. Treat a first instance as a conversation and retraining, and route repeated issues through your existing HR process. If people are punished for honest mistakes, they don't stop using AI; they stop telling you about it.

How do we know whether a shadow AI policy is working?

Review your web filter or proxy logs monthly. Once an approved tool exists, unapproved AI use should fall steadily. If it doesn't, treat that as feedback that the approved tool isn't meeting people's needs, not as a compliance failure.

Scroll to Top