While organisations formally evaluate one AI vendor, employees have already adopted seventeen unapproved tools using corporate credentials and company data. Marketing uses ChatGPT for drafts, developers pipe code into Copilot, HR screens CVs with AI, finance analyses quarterly data.
Why Traditional Approaches Fail
AI tools are everywhere
Unlike Shadow IT, AI is embedded in pre-approved tools—CRM, email clients, IDEs. Blocking "AI" means blocking productivity.
Data flows are invisible
Pasting contracts into chatbots leaves no file transfer trails. DLP tools cannot detect text in browser windows.
The value is genuine
Employees using AI are measurably more productive. Blocking AI wholesale creates workarounds and erodes trust.
Four-Phase Governance Framework
Phase 1: Discovery (Weeks 1–2)
- Network analysis: DNS/proxy logs for AI service domains
- Browser extension audits: identify broad permissions
- SaaS audits: review OAuth connections in identity providers
- Procurement review: silently-enabled AI features in existing tools
- Employee surveys: amnesty to identify actual usage
Phase 2: Risk Assessment (Weeks 2–3)
Phase 3: Governance (Weeks 3–4)
- AI Register: Living inventory of all AI tools (required under EU AI Act)
- Tiered Approval: Tier 1 pre-approved, Tier 2 48-hour review, Tier 3 full assessment
- Data Classification for AI: What can be shared at each classification level
- One-Page AUP: Clear examples of permitted/prohibited activities
Phase 4: Continuous Monitoring (Ongoing)
Automated discovery scanning, quarterly AI register reviews, AI-specific incident response runbooks, board-level metrics on sanctioned vs. unsanctioned tools.
Need help implementing this?
First strategy session is complimentary. We typically respond within 4 hours.