At a Glance

Should you ban AI at work? Understanding the Shadow AI problem

It’s an understandable instinct. Somewhere in the back of every leadership team’s mind sits the story of Samsung. Back in 2023, an employee pasted sensitive company info into ChatGPT, including internal source code and confidential meeting notes. Samsung’s response was swift and, on paper, sensible – ban AI chatbots across the business, problem solved. 

Except it isn’t solved. It’s just moved somewhere you can’t see it.

A ban doesn’t make Shadow AI disappear 

We get why many think of banning AI first because Shadow AI is actually a costly problem. IBM found that organisations that faced a security incident involving Shadow AI incurred, on average, an additional $670,000 in breach-related costs. It also found that 97% of organisations reporting an AI-related breach had no proper AI access controls in place. That’s a business case for taking this seriously. 

The instinct goes wrong when it assumes a ban addresses the problem. It doesn’t, because a ban is a policy for the tools you can see. Shadow AI, by definition, is everything you can’t see.

"You'll find employees use AI tools even if you ban them, not maliciously, but because it's so accessible these days, via personal accounts or devices. They'll just bypass that process. Trying to ban AI at work today is like banning Google in 2005. You can try. Policing it is a different matter entirely.”

Rob Smith,COO, CloudClevr

The employees using AI are not the problem

Nobody’s doing this to be reckless. It’s someone with a deadline, a blank page, and a tool that can help solve it quicker. If there’s no approved tool that’s just as easy to use, people will find their own solution. Research from Microsoft found that 71% of UK employees have used unapproved consumer AI tools at work, and the single most common reason was simply that no approved alternative existed.  

Ban ChatGPT, for instance, and, in most businesses, that same person is one search away from Gemini, Claude, or a dozen tools you’ve never heard of. If things are completely locked down, users will always find a way around it. Ban the tool, and you haven’t changed the behaviour. You’ve just made it invisible to you. 

We recently ran a Shadow AI assessment for a business that was confident it had this under control. The report found 37% of staff were already using AI tools nobody in the business had approved, across fifteen different apps. None of that showed up anywhere until you deliberately looked into it.

Can you prove your cyber security?

Find out the important questions organisations often overlook about cyber security, why they matter, and how you can develop evidence to answer your board and customers.

Read the ebook

AI doesn’t create new problems. It amplifies the ones you already have 

AI is an amplifier for whatever practice you already have in place. If your security fundamentals are solid, AI makes your team faster without adding real risk. If they’re shaky – permissions too loose, data ownership unclear, nobody quite sure who’s responsible for what – AI can make those weaknesses much easier to exploit, much faster. 

That reframes the whole question. “Should we ban AI tools?” was never really the issue. The issue is do you understand how AI is being used, what information is going into it, and what controls do we need to govern the usage? 

That applies to the tools you’ve approved as much as the ones you haven’t. 

The same AI tool can create very different risks without guardrails 

Take Claude as an example. Sign up with a personal account, and by default, your data is processed in the US and can be used to train the underlying model. But if you set up a proper corporate account instead, a business can choose exactly which region its data sits in. Same tool. Completely different risk profile and how data is handled, stored and governed. 

The same principle applies to Microsoft Copilot. For businesses already heavily using Microsoft 365, using an AI service in that environment can make it easier to apply existing security, identity, and data controls. 

The point isn’t that one AI tool is inherently “safe”, and another isn’t – it’s just a reminder that the tool matters less than the controls wrapped around it. 

That’s why we say Shadow AI isn’t only a security issue. It’s a corporate governance one, touching compliance, risk management and operational oversight all at once, which is exactly why a single blanket rule was never going to solve it. 

What we actually recommend instead to govern Shadow AI

Not a longer list of restrictions. A shorter, clearer one: 

  1. Find out what’s actually being used. You can’t govern what you can’t see. Look beyond the AI tools you’ve approved and find out what people are actually using, including personal accounts, browser-based tools and AI features built into existing software. Our free shadow AI assessment is a useful starting point for understanding what’s being used, by whom and for what purpose if you don’t know this yet.

     

  2. Write the policy before you write the controls. What’s approved, what data can and can’t be shared, and why? Make it clear in plain language.

     

  3. Protect what actually matters first. Not every file needs the same level of control. Identify genuinely sensitive data, such as client information, IP, and financial details, and put the strongest protection there.

     

  4. Name an owner. Give someone clear responsibility for AI governance. 

     

  5. Keep the evidence. A log of what’s approved, what’s been checked, and when. It’s the difference between describing your security and proving it to a board, an insurer, or a customer asking harder questions. 

None of that requires banning AI. And most of it is likely to be more sustainable than maintaining a ban that people can route around within a week.

Make the secure way the easy way 

If there’s one idea worth taking from all of this, it’s this – the goal was never to stop people using AI. It’s to make sure the safe option is also the easy one, so nobody has to choose between doing their job quickly and doing it safely. 

That’s a harder thing to build than a ban, but it’s also the only version of this that actually works. 

We go deeper into this topic and the other quiet assumptions businesses make about their own security in our Prove & Protect ebook. If this blog changed how you’d answer the AI question, the rest of the guide is worth fifteen minutes of your time.

Free Cyber Security assessment

Let's get things started

Fill out the form below and we will be in touch for your free assessment.

To qualify for a free trial of Clevr360, please submit your enquiry using a valid work email address and ensure you are based in the UK. We reserve the right to review, delay, or decline any request at our discretion.

Request an AI Readiness Review -
Powered by Clevr360

Discover how AI-Ready your IT estate is and get clarity across Microsoft 365 and key IT systems so you can adopt AI safely, optimise spend, and boost productivity.

GET A QUOTE

Get a tailored quote for ClevrOffice

ClevrOffice gives you everything your team needs to work — securely, seamlessly, and without the usual IT drama.

DISCOVERY SESSION

Speak to our team

Fill out the form below and account manager will be in touch

BOOK A DEMO

Discover Clevr360

Fill out the form below and we will be in touch with the next steps.