Ask a room of business owners whether their team uses AI at work and about half say no. Ask the team and the number is closer to everyone. The gap between those two answers is your exposure.
Shadow AI looks exactly like shadow IT did
Someone pastes a contract into a free chatbot to get a plain-English summary. Someone else drops a client spreadsheet in to build a formula. None of it is malicious. All of it is data leaving your control through a door you didn't know was open.
Why a ban fails
A ban doesn't remove the tool, it removes your visibility into it. The work still gets done faster with AI, so people keep using it, just on personal accounts, on personal devices, where you have no logs and no recourse.
The version that works
- Sanction one tool, inside your Microsoft 365 tenant, where the data stays under your agreement rather than in a consumer account.
- Write a one-page AI use policy in plain language: what may be pasted in, what may never be, and who to ask when it's unclear.
- Set data classification first. A guardrail is only as good as the labels it's enforcing on.
- Pick two or three real tasks (proposal drafts, meeting notes, first-pass estimating), and measure whether they actually got faster.
Map the opportunity, build the guardrails, implement the efficiency. In that order. The order matters more than the tooling.
The firms getting real value from AI are not the ones with the most licences. They're the ones who decided what was allowed before they scaled it.