Writing / technology governance
Shadow AI Is a Data Processor You Never Hired

Somewhere in your organisation today, an employee pasted a customer complaint, a loan statement or a supplier contract into an AI tool the company never approved. They did it to save twenty minutes, and they probably did a good job. They also sent personal data to a service with no contract, no retention terms and no entry in any data map.
My view is that most companies are governing this in the wrong place. They argue about which AI brands to allow. The risk sits in the data path: what information leaves, where it goes, and whether anyone can see it happen. Govern the path and the brand question becomes much smaller.
This piece is for CIOs, CISOs and data protection leads. It explains why bans fail, how DPDP changes the stakes, and what an enforceable policy looks like.
The short version
Employees use their own AI tools at work at scale, often with company data. Under DPDP, the company remains responsible for personal data it collected, wherever an employee sends it. Replace bans with approved tools under contract, clear rules on what data may go where, and visibility of the data path.
- Assume shadow AI is already happening in every team.
- Provide an approved tool that is better than the unofficial ones.
- Put approved AI services under proper data processing terms.
- Classify data so people know what may go into which tool.
- Watch the data path, not individual employees.
- Name an owner for the business outcome of each AI use.
This article sits inside the technology governance cluster, where the wider argument is set out in full.
What the numbers say
The 2024 Work Trend Index from Microsoft and LinkedIn, based on a survey of 31,000 knowledge workers across 31 markets, found that 75 per cent were using generative AI at work and that 78 per cent of those users were bringing their own AI tools. The same report found that many users were reluctant to admit using AI for their most important tasks.
That survey is more than two years old, and it is from a vendor with an interest in AI adoption. I use it for its direction rather than its precision. The direction is clear: employees adopted AI faster than their employers approved it, and a good share of that use is hidden.
Why bans fail
A ban assumes the demand will go away. It does not. The employee who saved twenty minutes yesterday still has the same workload today. Blocking one website moves the activity to a phone, a personal laptop or another tool, where the company sees even less.
From first principles, the useful question is not "how do we stop people using AI?" It is "what is the smallest set of controls that keeps sensitive data where it belongs while people keep the productivity?" That question leads to three things: a sanctioned tool worth using, rules people can follow, and visibility of what leaves.
Should your organisation do this now?
- Yes, if your current policy is a list of blocked AI websites.
- Not yet, if you have no approved alternative ready to offer.
- Instead, first: select and contract a sanctioned tool.
- Measure it by: share of AI usage flowing through sanctioned tools.
Treat the tool as a processor
Under the Digital Personal Data Protection framework, the organisation that decides why personal data is used remains responsible for it, including processing carried out on its behalf. The DPDP Rules, with core obligations applying from May 2027, require reasonable security safeguards, breach notification and erasure once a purpose is served.
Whether an unapproved AI service legally counts as your data processor is a question for counsel. In practice, I would behave as though it does, because the consequences land on you either way. If customer data leaks through a tool you never contracted, you still face the breach obligations, and you have no contract to fall back on.
For approved tools, that means the contract should answer plainly: where data is stored, how long it is kept, whether it is used to train models, who at the vendor can access it, and how fast the vendor will tell you about a breach. If a vendor cannot answer those five questions, it is not ready for customer data.
Risk: a sanctioned tool without these terms gives employees false confidence and the company no protection.
This article is general information, not legal advice.
Classify before you allow
People follow rules they can remember. Most data classification schemes fail that test.
A workable approach for AI use has three tiers:
- Open data. Public or non-sensitive content. Any approved AI tool.
- Internal data. Business information without personal or regulated data. Approved tools under contract only.
- Restricted data. Personal data, customer financial data, credentials, regulated records. Only tools specifically approved for that purpose, or not at all.
Pair the tiers with examples from each team's real work. "No personal data" means little to a collections officer until someone says "no borrower names, phone numbers or loan statements".
Should your organisation do this now?
- Yes, if employees cannot say in one sentence what data may go into AI tools.
- Not yet, if your approved tool is not yet contracted.
- Instead, first: finish the contract so the middle tier has somewhere to go.
- Measure it by: employees who pass a short scenario quiz on the tiers.
Visibility without surveillance
You cannot manage what you cannot see, but monitoring every keystroke damages trust and rarely finds the real risk.
Focus visibility on the data path. Network and endpoint controls can show which AI services are being reached and how much data is sent. Data loss prevention tools can flag restricted data types, such as account numbers or identity document numbers, leaving for unapproved destinations. Aggregate reports by team show where the sanctioned tool is not meeting demand.
Use those signals first to improve the sanctioned offering, and only second to enforce. A team that keeps using an unofficial tool is usually telling you the approved one is missing something.
Before you approve it
Checklist:
- Sanctioned AI tool available, with a contract covering the five questions.
- Three-tier data rule with team-specific examples.
- Short training and scenario check for all staff.
- Visibility of traffic to AI services and restricted data leaving.
- Process to request new AI tools with a fast answer.
- Owner named for the business outcome of each approved AI use.
Questions to ask:
- Your team: which AI services are being reached from our network today, and how often?
- Your team: what would an employee in collections or customer service need that the approved tool lacks?
- Your vendor: is our data used to train your models, and can we switch that off?
- Your vendor: where is our data stored and for how long?
- Your counsel: how should we treat unapproved AI services under DPDP?
- Your board: who owns the outcome of our AI use, and who reports it?
How to measure it
- Sanctioned share of AI traffic. Proportion of AI usage going through approved tools. Baseline: first network scan. Owner: CISO. Review: monthly. Leading.
- Restricted data alerts. Flags for sensitive data sent to unapproved AI services. Baseline: first month of monitoring. Owner: security operations. Review: weekly. Leading.
- Tool request turnaround. Days to answer a request for a new AI tool. Baseline: current process. Owner: IT governance. Review: monthly. Leading.
- Training pass rate. Staff passing the data tier scenario check. Baseline: first run. Owner: HR with data protection lead. Review: quarterly. Leading.
- AI-related data incidents. Confirmed incidents involving AI services. Baseline: last 12 months. Owner: data protection lead. Review: quarterly. Lagging.
Mistakes that cost the most
Banning without an alternative
Use goes underground.
- Why it happens: blocking is quick and visible.
- Prevention: offer a better sanctioned tool first.
- Early warning: AI traffic from personal devices on guest networks.
Approving tools without data terms
The brand is trusted; the contract is not checked.
- Why it happens: procurement treats AI like any software subscription.
- Prevention: require answers to the five data questions.
- Early warning: nobody can say where prompts are stored.
Classification nobody remembers
Long policies are not applied under time pressure.
- Why it happens: schemes are written for auditors.
- Prevention: three tiers and real examples per team.
- Early warning: staff asking "is this allowed?" for routine tasks.
Monitoring people instead of data
Trust falls and risk is missed.
- Why it happens: tools make individual tracking easy.
- Prevention: focus on data types and destinations.
- Early warning: employee complaints about surveillance.
Slow approval of new tools
Staff give up and use unofficial options.
- Why it happens: reviews queue behind other work.
- Prevention: a fast track with a published turnaround.
- Early warning: request backlog measured in months.
Frequently asked questions
What is shadow AI?
The use of AI tools at work that the organisation has not approved or does not know about, often involving company or customer data.
How common is it?
Microsoft and LinkedIn's 2024 Work Trend Index found that 78 per cent of AI users at work were bringing their own AI tools. The figure is from 2024 and a vendor survey, so treat it as a direction rather than a precise current rate.
Is using a public AI tool with customer data a DPDP breach?
It depends on the facts, including what data was shared and on what terms. The company generally remains responsible for personal data it collected. Get legal advice on specific cases.
Should companies ban public AI tools?
Bans alone tend to push use out of sight. A better approach is an approved tool under contract, clear data rules and visibility of restricted data leaving the organisation.
What should an AI vendor contract cover?
Where data is stored, how long it is kept, whether it is used for training, who can access it, and how quickly the vendor reports a breach.
How should data be classified for AI use?
A simple three-tier model works well: open data for any approved tool, internal data for contracted tools only, and restricted data only where specifically approved or not at all.
Can we monitor employees' AI use?
Monitoring should focus on data types and destinations rather than individuals, and should follow your employment and privacy obligations. Check with HR and counsel.
When do DPDP obligations fully apply?
The DPDP Rules were notified in November 2025 with an 18-month phased timeline, so core obligations apply from around May 2027.
What to do next
Run a scan of AI services reached from your network this month and share the results with the business, not only the security team. Then read the technology governance topic page, and the related piece on DPDP compliance for malls and retail.
Sources
- Microsoft and LinkedIn, 2024 Work Trend Index: AI at work is here, now comes the hard part, May 2024. microsoft.com
- Press Information Bureau, DPDP Rules, 2025 notified, November 2025. pib.gov.in
- Ikigai Law, A closer look at the DPDP Rules 2025, November 2025. ikigailaw.com
Last reviewed: 15 September 2026.
Views are my own and do not represent my employer.
This article is general information, not legal advice.