Skip to main content
foundry

Shadow AI: someone in your firm is already pasting client data into a chatbot

Consumer AI tools have different terms from business ones. If you haven't given people a sanctioned option, they've found their own. What to do this month.

Foundry Team

Shadow IT was the personal Dropbox and the spreadsheet on a home laptop. Shadow AI is the same instinct with a chat window: a capable person, a tedious task, a free tool that does it in seconds. The difference is what goes into the box.

Why it matters more than the old kind

Consumer AI products are governed by consumer terms. Those differ from the commercial and enterprise terms the same vendors offer to businesses, on retention, on whether inputs may be used to improve models, on where processing happens and on who is contractually responsible for what. We are not going to make a blanket claim about any vendor here, because the honest answer is that it depends on the product and the plan. That uncertainty is exactly the problem: nobody in your firm can say where the client's pension statement went after it was pasted in.

For a regulated firm, that is a data-protection question, a confidentiality question and, increasingly, a question your compliance consultant will ask.

What people are actually doing

  • Drafting client letters from notes that include names, balances and health details.
  • Summarising meeting recordings that contain identifiable information.
  • "Tidying up" spreadsheets exported from the back-office system.
  • Asking for help with a suitability report, with the fact-find pasted in for context.

None of it is malicious. All of it is unmanaged.

What to do this month

  1. Say what is allowed. A one-page policy: which tools, on which accounts, with which data. Absence of a policy is a policy.
  2. Give people a sanctioned option. A business-grade assistant, on business accounts, with the terms reviewed and the data classification decided. Prohibition without an alternative fails within a week.
  3. Block the obvious routes. DNS and endpoint controls can stop consumer AI domains on managed devices. It is not airtight; it makes the sanctioned route the easy one.
  4. Train, briefly. Ten minutes on what not to paste, and why. People comply with rules they understand.
  5. Log. Whatever you sanction should record who used it for what. That log is what you will show a regulator or an insurer.

The longer answer

Sanctioned AI in a data-sensitive firm means choosing where the model runs by how sensitive the data is: an enterprise API under commercial terms for minimised content, a model inside your own cloud subscription and region for client files, or AI inside the tenant you already govern. That is an architecture decision, and it is the difference between "we use AI" and "we can show how we use AI".

Want help with this in your business?

Talk to Foundry — we’ll talk through your situation, no obligation.

Keep reading

Before you switch on Copilot: the oversharing problem

Copilot respects the permissions you already have, which is good news and bad news. How to find what is overshared in your tenant before an assistant does.
Foundry Team

Where does your data go when you use AI? It depends on the product

One vendor can sell a consumer app, an enterprise API and a model in your own cloud, each on different terms. Four deployment models, compared honestly.
Foundry Team

Prompt injection: the security problem every AI workflow inherits

If an AI system reads untrusted text and can act, someone will put instructions in the text. What prompt injection is and how to design around it.
Foundry Team

Remote-first / UK-wide / one team

Ready for a technology team that can build?

Thirty minutes with an engineer, not a salesperson: what you run today, what’s at risk, what should be automated, and what we’d build or wouldn’t.

30 min call / no pitch / no obligation