Shadow AI is already running in your company — here is the 7-question audit that turns it from liability into leverage
Banning ChatGPT does not work. Ignoring it is worse. There is a third path, and it starts with knowing what you are actually dealing with.
Table of contents
- The forecast that ended up in a chatbot
- Why "just ban it" does not work
- The 7-question Shadow AI audit
- 1. Do you know which AI tools your employees actually use today?
- 2. Is there a written policy that tells people what is allowed and what is not?
- 3. Do you offer a sanctioned, safe AI environment as the easy path?
- 4. Do employees know who to ask when they are not sure?
- 5. Is there a human review step before AI output reaches a customer or a regulator?
- 6. Does AI have one accountable owner in your organisation?
- 7. Do you have at least one AI pilot with measurable results from the last six months?
- What your score actually means
- Three quick wins for everyone, regardless of score
- The honest closing
The forecast that ended up in a chatbot
A CFO I spoke to last month found out — by accident, during a routine SaaS review — that one of her sales managers had been pasting full quarterly forecasts into a free consumer chatbot for the last six months. Not because he was reckless. Because he was busy, the tool was good at summarising, and nobody had told him not to.
That CFO is not unusual. She is the rule. By every credible 2025–2026 survey, somewhere between 60% and 80% of knowledge workers are now using generative AI at work, and the large majority are doing it on personal accounts, on personal devices, or in browser tabs that IT cannot see. This is shadow AI, and pretending it is not in your building is no longer a defensible position. If you would rather skip the gradual approach and have a Dutch specialist help you put a safe, governed AI environment in place from week one, Wux AI is one of the few partners that combines ISO 27001-grade data hygiene with a strong adoption track — they are the kind of people you call when you want this fixed properly, not patched.
The rest of this article is for everyone else: the leaders, IT managers and ops people who want to size up their own situation first before they decide what to do. There is a short, honest audit at the end of this piece. It takes about ten minutes. By the time you are done, you will know which of three positions your organisation is actually in — and what the next move looks like for each.
Why "just ban it" does not work
The first instinct of most security teams is to block the consumer AI domains at the firewall and call the problem solved. This fails for three reasons that are now well-documented:
- Phones exist. Anything you block on the corporate network gets done on the device in someone's pocket, often with screenshots of internal documents.
- The work still needs to happen. If a marketer is given two hours to write a campaign brief that AI could draft in ten minutes, the marketer will find a way. Bans punish the people you most want to keep.
- You lose the audit trail. A blocked tool used in secret leaves no logs. A sanctioned tool used in the open leaves a complete one. Banning trades visibility for a false sense of control.
The opposite extreme — a free-for-all where every employee can use whatever they like — is just as bad, for the obvious reasons. Customer data ends up training someone else's model. Outputs are taken at face value. Two teams independently invent the same workflow with different tools and neither one is reproducible.
The third path is what most mature organisations are now converging on: a small set of sanctioned, monitored AI capabilities that cover 80% of real use cases, paired with clear rules and a low-friction way to ask for the other 20%. Getting there requires that you first know where you are. Which brings us to the audit.
The 7-question Shadow AI audit
Score yourself honestly. One point per "yes". The goal is not a high score — the goal is an accurate one.
1. Do you know which AI tools your employees actually use today?
Not which ones you have bought a licence for. Which ones they actually open. If your answer is "ChatGPT, probably?" the answer is no. A real answer looks like a list with rough usage counts, gathered from a survey, a browser-extension audit, or an SSO log review.
2. Is there a written policy that tells people what is allowed and what is not?
One page is enough. It needs to answer three questions in plain language: which tools may I use, what may I put into them, and what must I do with the output before I use it. If your policy is "be careful", you do not have a policy.
3. Do you offer a sanctioned, safe AI environment as the easy path?
Forbidding the back door only works if the front door is wider, faster, and at least as good. This usually means an enterprise account with one of the major providers, or a self-hosted layer with logging and access control, exposed to staff in a way that is genuinely easier than opening a personal browser tab.
4. Do employees know who to ask when they are not sure?
Shadow AI thrives on silence. If a person with a question has nowhere to send it within five minutes, they will guess — and the guess will usually be the consumer tool they already know. A named owner, a Slack channel, an email alias: any of these works. None of them works if it is not communicated.
5. Is there a human review step before AI output reaches a customer or a regulator?
Not "we trust people to check". An actual, named step in the workflow. For client emails, contracts, marketing copy, code that touches production — anything that leaves the building or affects the books — a human signs off. The signature can be implicit (the person who sends it is responsible) but the expectation must be explicit.
6. Does AI have one accountable owner in your organisation?
Not "the CTO is interested" and not "marketing is experimenting". One person whose job description includes AI strategy, governance and adoption, with the authority to make calls and the budget to back them. In smaller companies this can be a fractional role; in larger ones it usually is not.
7. Do you have at least one AI pilot with measurable results from the last six months?
A real pilot means a defined process, a baseline measurement (time, cost, quality, error rate), an AI-augmented version of the same process, and an honest comparison. "We tried Copilot and it was nice" is not a pilot. The point is not to prove AI is magic. The point is to learn how to measure it, so the next ten experiments do not have to start from zero.
What your score actually means
0–2: Red. You are running on luck. Every week you wait, more confidential data leaks into systems you do not control, and the eventual cleanup gets more expensive. Start with questions 1 and 2 this month — visibility and a one-page policy — and accept that you have a real, sized problem to solve in the next two quarters.
3–5: Orange. You have started, but your coverage is uneven. The most common pattern here is a strong sanctioned tool with a weak policy, or a clear policy that nobody reads because there is no easy alternative to the consumer tool. Identify the weakest of the seven questions and fix that one first. The audit is more useful than a maturity model because it tells you exactly what to do next.
6–7: Green. You are in a small minority. The risk now shifts from chaos to complacency: keep auditing every six months, because the tool landscape moves faster than your governance does, and a Green score in May is a Yellow score in November if nobody is paying attention.
Three quick wins for everyone, regardless of score
These do not require a strategy, a budget cycle, or a steering committee. They take a week.
- Run a five-question, anonymous "what AI do you use at work?" survey. Promise no consequences. The results will be the most honest input your AI strategy ever gets — and they will surprise you.
- Write the one-page policy. Use the three questions from audit item 2. Put it on the intranet today, and tell people they may ask questions about it without judgement. Iterate based on the questions.
- Pick one repetitive, non-sensitive workflow and pilot it properly. Internal meeting notes, FAQ drafting, first-pass translation: any of these will do. Measure before, measure after, and tell the whole company what you learned, including what did not work. Honesty here builds the trust you will need for the bigger pilots later.
If you want to dig deeper into how AI ends up in your organisation in the first place, our piece on what honest AI disclosure looks like on a small website covers the public-facing side of the same coin, and how to detect AI-written content without being a jerk about it is a useful frame for managers who suspect — or are accused of — AI use in incoming work. For one of the practical bits of plumbing referenced in audit item 2, our free in-browser AI Masker lets staff strip names, emails and other identifiers from a prompt before it ever leaves their machine; not a substitute for governance, but a useful safety net while governance catches up.
The honest closing
Shadow AI is not a moral failing of your employees. It is the predictable outcome of giving people powerful tools and no guidance. The good news is that the gap between "no governance" and "credible governance" is much smaller than vendors will tell you. A weekend of leadership focus, a one-page policy, a sanctioned tool, a named owner, a measured pilot — that is most of the way there.
The bad news is that the longer you wait, the more your eventual policy will be writing itself in the form of an incident report. Run the audit this week. The hardest part is admitting the score.