The employee who discovers that a generative AI tool dramatically reduces the time required to produce a first draft, prepare a meeting summary, or debug code will use it. They will use it with the document they are working on, which may contain customer data, employee data, strategic information, or legally privileged content. The data enters the AI vendor's infrastructure. The governance program does not know it happened.
Why This Is Different From Previous Shadow IT Problems
Previous shadow IT problems involved employees using unauthorized software tools to perform work in ways that bypassed IT governance. The risk was primarily in the tool's security posture and data handling practices. AI shadow IT introduces an additional dimension: the tool does not simply store or process data — it learns from it, in ways that may retain information in the model's parameters even after the session ends, and it may use interaction data to train models that are subsequently used by other organizations.
The generative AI tool that an employee uses to summarize a confidential business document has received that document as input. Depending on the vendor's terms of service and data handling practices, that document may be used to improve the model, may be accessible to the vendor's staff for safety review, or may be retained in the vendor's infrastructure beyond the session. The employee does not know which of these applies because they did not read the terms of service before signing up with their work email address.
The confidential document that enters a generative AI tool has been shared with the AI vendor under whatever terms the employee accepted at signup. The organization's confidentiality obligations for that document extend to its vendors. They do not extend, automatically, to the AI vendor the employee chose without organizational authorization.
The Specific Risk Scenarios
Customer Data in Generative AI Inputs
The customer service representative who uses a generative AI tool to draft responses to customer emails is feeding customer personal data into the AI system. Customer names, account details, complaint content, and contact information are in the AI input. Under GDPR, processing customer personal data through a new processor requires a DPA with that processor. The AI tool being used without IT approval is processing personal data as a processor without a DPA.
Legally Privileged Content in AI Research Tools
Legal teams using AI research and summarization tools may input content from legal matters: correspondence with external counsel, litigation strategy documents, regulatory investigation materials. These documents carry privilege. Sharing them with an AI vendor under the vendor's standard terms — which typically do not include legal privilege protections — may constitute a waiver of privilege that affects the organization's legal position. The legal team member who uses the AI tool for convenience has potentially created a legal problem.
Source Code in AI Code Assistance Tools
Developers using AI code assistance tools input source code as context for the AI's suggestions. Proprietary source code, security-relevant implementation details, and API credentials that appear in code samples may be included in inputs to AI code assistance tools that are not under organizational governance. The IP and security implications of proprietary code entering an external AI system under standard terms are not trivial.
Strategic Information in AI Meeting Transcription
AI meeting transcription tools that record and transcribe meetings, then generate summaries and action items, capture the content of strategic discussions, M&A conversations, personnel matters, and other sensitive organizational content. The transcription service's data handling, retention, and use practices determine what happens to that content. The employee who enables a transcription tool in a board meeting has captured board-level strategic content in an external AI system under whatever terms the tool operates under.
What Governance Requires
AI shadow IT governance requires the same three-step approach as general shadow IT governance: discover what is being used, assess the risk of what is discovered, and address the highest-risk uses while providing authorized alternatives for legitimate productivity needs.
Discovery for AI tool use can be conducted through network traffic analysis for known AI service endpoints, through SaaS discovery tools that identify AI applications from browser extension telemetry, and through surveys of employees that ask directly what AI tools they are using for work purposes. The survey approach consistently reveals tools that technical discovery misses.
The authorized alternative is particularly important for AI tools. Employees who discover significant productivity benefits from AI tools will not stop using AI because the IT team prohibits it — they will use it from personal devices or personal accounts. Providing an organizationally approved AI tool that meets their productivity needs, under organizational governance, redirects the use to a governed channel. The governance question is which AI tool, under what terms, for what use cases — not whether employees will use AI at all.
Discover what AI tools your employees are using. Provide governed alternatives for the high-risk use cases. The employee who is using AI is not the problem. The absence of a governed channel is.
Find the AI tools. Provide approved alternatives. Govern the channel. The productivity benefit is real — govern it rather than prohibit it.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
