Watchlight AI
Back to Blog
Shadow AIAI GovernanceCISOEnterprise Security

Shadow AI Is Already in Your Enterprise: A CISO's 90-Day Action Plan

Aldo PietropaoloJanuary 11, 20268 min read
Share

Here's a number that should concern every security leader: 73% of work-related ChatGPT queries are processed through accounts not approved for corporate use. Your employees aren't waiting for permission. They're already using AI, with or without you.

This is the reality of Shadow AI. Unlike shadow IT of the 2010s, where employees might spin up an unauthorized Dropbox account, AI tools are invisible, instantaneous, and capable of ingesting your most sensitive data in a single paste.

And here's what keeps security leaders up at night: you can't protect what you can't see.

The Scale of the Problem

Recent surveys paint a stark picture:

  • 59% of employees admit to using unapproved AI tools for work tasks, according to a Cybernews survey of over 1,000 US workers
  • 38% of employees acknowledge sharing sensitive work information with AI tools without employer permission, per research from CybSafe and the National Cybersecurity Alliance
  • 68% of security leaders admitted to actual data leaks caused by staff feeding sensitive information into AI tools, yet just 23% had rolled out serious policies to address it, according to a 2025 Metomic survey
  • 73% of work-related ChatGPT queries were processed using accounts not approved for corporate use, per Reco's 2025 State of Shadow AI Report

The gap between "official AI policy" and "actual AI behavior" isn't a crack. It's a canyon.

Why Traditional DLP Doesn't Catch It

Your existing Data Loss Prevention tools were built for a different threat model. They look for files leaving the network, sensitive patterns in email attachments, and uploads to unauthorized cloud storage.

But when an employee pastes a customer list into Claude, copies source code into ChatGPT, or asks Gemini to summarize a confidential contract, none of those actions look like traditional exfiltration. There's no file. There's no attachment. Just text in a browser, gone in milliseconds.

Worse, many AI tools are accessed through:

  • Personal devices and networks (BYOD blind spots)
  • Browser extensions that inject into existing workflows
  • API integrations buried in developer toolchains
  • Mobile apps that never touch your managed infrastructure

Your perimeter-based controls weren't designed for this. They can't be retrofitted to solve it.

The 90-Day Framework

Drawing from two decades of enterprise security work, I've seen what separates successful governance initiatives from failed ones. Meaningful progress requires a phased approach. Trying to boil the ocean, complete lockdown on day one, creates backlash, workarounds, and false confidence. Instead, focus on building durable capability across three phases.

Phase 1: Discovery (Days 1-30)

Objective: Understand what's actually happening.

Before you can govern AI, you need to know what AI is being used, by whom, for what purposes, and with what data. This isn't about blame, it's about baseline.

Key Actions:

  1. Deploy AI-aware traffic analysis. Work with your network and proxy teams to identify AI service endpoints. Most enterprise AI tools have identifiable domains and API patterns. Start logging, not blocking.

  2. Survey without judgment. Send a confidential survey asking employees about their AI usage. Frame it as "help us enable AI safely" not "tell us what rules you've broken." You'll be surprised by the candor when there's no threat of punishment.

  3. Audit browser extensions. ChatGPT, Claude, and other AI tools have browser extensions that many employees install. Get visibility into extension inventories across managed endpoints.

  4. Interview power users. Every department has someone who's gone deep on AI. Find them. Buy them coffee. Learn what tools they use, what problems they're solving, and what data they're feeding these systems.

  5. Map the data flows. For each AI tool discovered, document: What data could it access? Where does that data go? What's the vendor's data retention and training policy?

Deliverable: An AI usage inventory with risk classifications, not perfect, but directionally accurate.

Phase 2: Policy (Days 31-60)

Objective: Establish clear, enforceable rules.

Most AI policies I review fall into two failure modes: either so restrictive they're ignored ("no AI, ever") or so vague they're meaningless ("use AI responsibly"). Effective policy lives in the middle.

Key Actions:

  1. Tier your AI tools. Create three categories:

    • Approved: Vetted tools with acceptable security posture, enterprise agreements, appropriate data handling
    • Conditional: Tools permitted for specific use cases or data types (e.g., "public data only")
    • Prohibited: Tools that fail security review or have unacceptable data practices
  2. Define data boundaries. Be explicit about what can and cannot be shared with AI tools:

    • Customer PII: Never
    • Proprietary source code: Approved tools only
    • Internal strategy documents: Case-by-case with manager approval
    • Public information: Any approved tool
  3. Integrate with existing governance. Your AI policy shouldn't be an island. Connect it to your data classification framework, acceptable use policy, and third-party risk management process. Employees shouldn't need to learn a new system, AI governance should feel like an extension of existing controls.

  4. Create an exception process. Some teams will have legitimate needs for tools outside your approved list. Build a fast-track review process. If it takes 6 weeks to get a tool approved, people will just use it anyway.

  5. Get executive sponsorship. AI policy without C-suite backing is a suggestion. Ensure your CEO, CFO, or General Counsel can articulate why this matters.

Deliverable: A published AI Acceptable Use Policy, tool classification matrix, and exception request workflow.

Phase 3: Enforcement (Days 61-90)

Objective: Operationalize the policy with technical controls.

Policy without enforcement is theater. But enforcement doesn't mean surveillance, it means making the right thing easy and the wrong thing hard.

Key Actions:

  1. Implement AI-aware web filtering. Move from logging to blocking for prohibited tools. Use warning pages for conditional tools ("This tool is approved for public data only. Continue?").

  2. Deploy endpoint DLP with AI context. Modern DLP tools can recognize when sensitive data is being pasted into AI interfaces. Implement clipboard monitoring for high-risk data patterns, but do it transparently with employee notice.

  3. Integrate with identity. Connect AI tool access to your SSO and role-based access controls. Marketing should access different AI capabilities than Engineering. Finance different from HR. Your IAM system should be the source of truth.

  4. Establish monitoring and alerting. Build dashboards showing AI usage trends, policy violations, and exception requests. Report monthly to security leadership. Quarterly to the board.

  5. Enable approved alternatives. If you're blocking ChatGPT, you'd better be providing an approved alternative. The fastest way to reduce shadow AI is to make sanctioned AI genuinely useful.

Deliverable: Technical controls deployed, monitoring operational, approved alternatives available.

Quick Wins in Each Phase

Not everything requires 30 days. Here are actions you can take this week:

Discovery Quick Wins:

  • Check your proxy logs for api.openai.com, claude.ai, gemini.google.com traffic
  • Search your CASB for "ChatGPT" or "AI assistant" in app inventory
  • Ask your help desk how many AI-related questions they're fielding

Policy Quick Wins:

  • Draft a one-page AI usage guidance memo (even imperfect guidance beats silence)
  • Add AI tools to your next vendor risk assessment cycle
  • Include AI usage questions in your next security awareness training

Enforcement Quick Wins:

  • Enable browser extension visibility in your endpoint management console
  • Add AI domains to your web filter's logging (not blocking) category
  • Create a Slack channel or email alias for AI tool requests and questions

The Bigger Picture

Shadow AI is a symptom, not the disease. The underlying issue is that AI adoption is outpacing governance, and that gap represents risk.

But it also represents opportunity. Organizations that get AI governance right won't just avoid incidents. They'll accelerate adoption, build employee trust, and create competitive advantage.

The goal isn't to stop AI adoption, it's to enable it safely. The organizations that get this right will shift from asking "how do we stop this?" to "how do we scale this safely?" That's the transformation we should all be working toward.


Watchlight AI helps enterprises discover, govern, and secure their AI usage. If you're starting your AI governance journey, or stuck somewhere along the way,we'd welcome a conversation.


Sources

Found this useful? Share it with your network.
Watchlight AI Beacon

Put runtime governance in front of every agent action

Watchlight AI Beacon is in early access, fully on-premises and air-gapped, through the Founding Design Partner program.

Request Early Access
Recommended Workshop

Agent Governance Readiness Assessment

Evaluate your governance posture against the 12 principles. Get a maturity score and roadmap.

2-3 days · Download one-pager (PDF)

We value your privacy

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. You can choose to accept all cookies or customize your preferences. Learn more