AI governance
Shadow AI is already inside your organisation
Personal AI tool use among employees is already widespread, policy or no policy. Prohibition does not remove that risk. It removes your visibility into it.

Executive summary
4
moves in the governed alternative, in order
Core conclusions
- A prohibition doesn't reduce usage among people already getting real productivity from AI — it only makes them discreet about it.
- Widespread employee use is evidence of demand and readiness, not a compliance failure — the workforce has already decided this is useful.
- The governed alternative: a sanctioned tool good enough to compete, behind your own boundary, with a classification rule that's published and enforced.
Employees already use personal AI tools for work at scale — regularly, not occasionally, and largely irrespective of whether a policy exists.
The governance risk is not the AI. It is confidential material leaving your systems with no contract behind it, no audit trail, and no control over what happens to it next.
Why a ban makes it worse
A prohibition does not reduce usage among people getting real productivity from it. It makes them discreet. You lose the one thing still working in your favour, which is knowing roughly what is happening.
That level of use reads better as evidence of demand and readiness than as a compliance failure. The workforce has already decided this is useful. The open question is only whether it happens inside a boundary you control.
The governed alternative
Four moves, in this order:
- Provide a sanctioned tool good enough that the unsanctioned one is not worth the friction.
- Put it behind your own boundary, with logging and retention you specify.
- Classify what may and may not go into it, in language an operator can apply without a lawyer.
- Publish the rule, then enforce it. A policy nobody has read is indistinguishable from no policy.


