Shadow AI: someone in your firm is already pasting client data into a chatbot
Consumer AI tools have different terms from business ones. If you haven't given people a sanctioned option, they've found their own. What to do this month.
Shadow IT was the personal Dropbox and the spreadsheet on a home laptop. Shadow AI is the same instinct with a chat window: a capable person, a tedious task, a free tool that does it in seconds. The difference is what goes into the box.
Why it matters more than the old kind
Consumer AI products are governed by consumer terms. Those differ from the commercial and enterprise terms the same vendors offer to businesses, on retention, on whether inputs may be used to improve models, on where processing happens and on who is contractually responsible for what. We are not going to make a blanket claim about any vendor here, because the honest answer is that it depends on the product and the plan. That uncertainty is exactly the problem: nobody in your firm can say where the client's pension statement went after it was pasted in.
For a regulated firm, that is a data-protection question, a confidentiality question and, increasingly, a question your compliance consultant will ask.
What people are actually doing
- Drafting client letters from notes that include names, balances and health details.
- Summarising meeting recordings that contain identifiable information.
- "Tidying up" spreadsheets exported from the back-office system.
- Asking for help with a suitability report, with the fact-find pasted in for context.
None of it is malicious. All of it is unmanaged.
What to do this month
- Say what is allowed. A one-page policy: which tools, on which accounts, with which data. Absence of a policy is a policy.
- Give people a sanctioned option. A business-grade assistant, on business accounts, with the terms reviewed and the data classification decided. Prohibition without an alternative fails within a week.
- Block the obvious routes. DNS and endpoint controls can stop consumer AI domains on managed devices. It is not airtight; it makes the sanctioned route the easy one.
- Train, briefly. Ten minutes on what not to paste, and why. People comply with rules they understand.
- Log. Whatever you sanction should record who used it for what. That log is what you will show a regulator or an insurer.
The longer answer
Sanctioned AI in a data-sensitive firm means choosing where the model runs by how sensitive the data is: an enterprise API under commercial terms for minimised content, a model inside your own cloud subscription and region for client files, or AI inside the tenant you already govern. That is an architecture decision, and it is the difference between "we use AI" and "we can show how we use AI".
Want help with this in your business?
Talk to Foundry — we’ll talk through your situation, no obligation.