Blog · AI & Security · July 12, 2026 · By Mike Parker

Shadow AI at Work: What Employees Are Pasting Into Chatbots

Your team adopted AI before anyone wrote a policy for it. Here's where the pasted data actually goes, what a workable acceptable-use policy looks like, and the monitoring your IT partner should already be doing.

Somewhere in your company this week, an employee closed a gap the modern way. A client spreadsheet needed cleaning before a 4 p.m. deadline, so it went into a free AI chatbot with the prompt "fix the formatting." A delicate email to an unhappy customer got drafted by a bot that read the whole thread first. Meeting notes, a pricing proposal, a paragraph of a contract — pasted, polished, returned. Nobody asked permission, because nobody thought of it as a security decision. It was just the fastest way to get the work done.

That is shadow AI: artificial intelligence tools in active business use without IT's knowledge, approval, or controls. It's the fastest-spreading form of shadow IT we've ever watched, because the tools are free, they live in a browser tab, and — unlike most rogue software — they are genuinely, immediately useful.

The problem isn't the chatbot. It's the paste.

Employees almost never leak data out of malice. They leak it out of helpfulness, one prompt at a time. The moment business data leaves your environment for a consumer AI service, several things happen at once — and none of them are visible to you:

  • You may have just fed someone else's product. Consumer tiers of many AI services reserve the right, in their terms, to retain prompts and use them to improve their models. What goes in does not reliably come back out.
  • The data now lives under someone else's breach. Even when a provider doesn't train on your prompts, it stores them — chat history is a feature. Your client list is now part of another company's attack surface, held under a consumer account with no contract protecting you.
  • It happened under a personal account. No single sign-on, no offboarding. When the employee leaves, the chat history — and everything ever pasted into it — walks out the door with them.
  • You may have breached a contract without being breached. If the pasted data was covered by an NDA, HIPAA, CMMC, or a client security addendum, the violation happened at the moment of the paste. No hacker required.

And chatbots are only the visible edge. Browser extensions with AI features can read every page an employee views — including webmail and the CRM. AI meeting notetakers join calls, record them, and mail transcripts to lists nobody reviews. "Connect your inbox" integrations request standing access that survives password resets — the same consent problem we flagged in our Microsoft 365 hardening guide.

What the data says

Unsanctioned AI is already a breach category

This stopped being hypothetical. Shadow AI now shows up in breach post-mortems often enough to have its own line in the research.

43%

of breached organizations said the incident involved shadow AI — unsanctioned tools in employee hands

IBM Cost of a Data Breach 2026

$5.39M

average cost of a breach that involved shadow AI — against a $4.99M global average

IBM Cost of a Data Breach 2026

68%

of breached organizations had no AI governance in place to manage AI or detect shadow AI

IBM Cost of a Data Breach 2026

A ban is not a policy

The reflex is to block everything. That instinct fails twice. First, the productivity gains are real, and leadership doesn't actually want them gone. Second, a blanket ban doesn't stop the behavior — it relocates it to personal phones and home laptops, where you have no visibility at all. Per IBM's Cost of a Data Breach 2026 report, 43% of breached organizations traced their incident to shadow AI — more than double the 20% reported a year earlier — and 68% had no AI governance in place to manage or detect it. A rule nobody can live with is how you end up in that 43%.

A workable acceptable-use policy is short enough to read and specific enough to act on. Five ingredients:

  • An approved-tools list. Pick a small set of AI services on business tiers — where contractual data protections, admin controls, and audit logs exist — and give people a sanctioned lane that's actually good.
  • Data rules by category. Name what may never enter any public AI tool: client and employee personal data, financials, credentials, health or regulated data, anything under NDA. The tiebreaker rule: treat every prompt like a public post.
  • Business accounts only. Approved tools get used under company identity — behind single sign-on and MFA where supported — so access ends when employment does.
  • A review lane, not a wall. Employees can request a new tool and get an answer in days. If the sanctioned path is slower than the shadow path, the shadow path wins every time.
  • Training with real examples. Ten minutes of "here's what a bad paste looks like" outperforms a policy PDF nobody opens.

The technical backstop: DLP that matches the policy

Policy without enforcement is a poster. The enforcement layer is data loss prevention — DLP — tuned to the same rules the policy states:

  • DLP rules in email and on endpoints that recognize sensitive patterns — account numbers, Social Security numbers, client identifiers — and can warn, require a justification, or block when that data heads for an uploader or a browser paste.
  • Web filtering that blocks unapproved AI domains on company devices, or nudges users toward the approved alternative.
  • App-consent controls in your cloud tenant, so an AI integration can't grab standing access to mail and files without an admin's sign-off.
  • Monitoring of new OAuth grants and integrations, because the riskiest AI adoption isn't a paste — it's a connection.
  • A monitor-first rollout. Start in audit mode, learn what normal looks like, then tighten. DLP that blocks payroll on day one gets turned off by day three.

What your IT partner should be doing about this

If you pay an MSP or MSSP, shadow AI is now squarely their problem too. The service you should expect:

  1. Discovery. An inventory, from network logs and tenant sign-in and consent data, of which AI services your business already talks to — before anyone writes a rule.
  2. Policy, co-written. An acceptable-use policy drafted with leadership, in plain language, mapped to how your teams actually work.
  3. Tenant hardening. Consent restrictions, conditional access, and sign-in controls so the policy is enforced by settings, not memos.
  4. DLP deployment and tuning. Rules matched to your data types, rolled out monitor-first, tightened with evidence.
  5. Ongoing watch. New AI tools, new integrations, and unusual data movement surfaced in your business review — and sooner when it matters, because this landscape changes monthly.

That's the standard we hold ourselves to in our managed cybersecurity service, and it rides on the same day-to-day discipline as managed IT. If you have an internal IT team, a co-managed arrangement can bolt the monitoring and DLP layer onto what they already run.

The chatbots are already in the building. The only question is whether the policy — and the monitoring — arrive before the first paste you'll regret.

Quick answers

Shadow AI, answered plainly

What is shadow AI?

Shadow AI is any artificial intelligence tool employees use for work without IT approval or oversight — free chatbots, AI browser extensions, meeting notetakers, and AI features quietly switched on inside otherwise-approved apps. The name echoes "shadow IT," but adoption spreads faster because the tools are free, browser-based, and genuinely useful, which is why bans alone rarely stop them.

Should we just block all AI chatbots?

Usually no. Blanket bans push the behavior onto personal phones and home computers where you have zero visibility, and they surrender real productivity gains. The pattern that works: approve a small set of tools on business tiers, define the data that may never leave, block unapproved services on company devices where it matters, and give employees a fast lane to request new tools.

What should employees never paste into a public AI tool?

Client and employee personal information, financial records, passwords and API keys, health or other regulated data, contract text under NDA, and anything you would not post publicly. If the data is covered by HIPAA, CMMC, or a client security addendum, a paste into a consumer chatbot can be a reportable violation all by itself — no hacker required.

How do we find out which AI tools are already in use?

Combine three sources: network and DNS logs show which AI services company devices talk to; your cloud tenant's sign-in and app-consent logs show which integrations employees have connected; and an amnesty-style survey — tell us what you use, nobody gets in trouble — surfaces the rest. A managed security provider can run this discovery and keep the inventory current.

Do free AI tools really keep what employees type?

Assume yes. Consumer tiers of many AI services retain chat history by default, and some reserve the right to use prompts to improve their models — details that live in terms of service most users never read. Business tiers generally offer stronger commitments: no training on your data, admin controls, and audit logs. That difference is exactly why an acceptable-use policy steers work to business accounts.

Find out what AI tools your business already talks to

A free 30-minute assessment with the owner — including a plain-English read on your unsanctioned-app exposure. No pitch deck, no obligation.

Book a Free 30-Minute IT Assessment