Writing a Shadow AI Policy That People Will Actually Follow

Most shadow AI policy documents fail the same way. They are written to satisfy an auditor, they prohibit more than they permit, and the people they govern never read past the first paragraph. Six months later usage is unchanged and nobody mentions it, which the policy owner reads as compliance.

A policy that works looks different, and it is shorter than you expect.

Why the strict version backfires

Blanket bans do not reduce AI usage. They relocate it.

The employee who was using a summariser on their work laptop now uses it on their phone. You have lost the logs, lost the ability to steer them toward something safer, and added a reason for them to stay quiet when something goes wrong. You have made the actual risk worse while making the reported risk zero, which is the worst possible combination because it looks like success.

Salesforce found 27% of employees have entered confidential data into public AI tools. Those people are not saboteurs. They are trying to finish something, and a rule that makes finishing it harder loses to the deadline every time.

What to write instead

Four things, and they fit on one page.

1. A green list, published and easy to find

Name the tools people can use without asking, and say what each is cleared for. Most policies lead with prohibitions and bury the permitted list in an appendix, or never write one at all, which leaves “ask IT” as the only sanctioned path. Nobody asks IT. They just use the thing.

The green list is the single highest-leverage part of the document, because it is the only part that gives people somewhere to go.

2. A data rule people can apply without a lawyer

The classification scheme in your security policy is not usable at the moment someone is about to paste. Write the rule so it can be applied in the two seconds actually available.

Something closer to: never paste customer data, credentials, source code, or anything from an unreleased financial or legal document into any AI tool that is not on the green list. Concrete nouns beat “confidential information”, because everyone believes their own work is fine.

3. A fast path for anything new

If approval takes three weeks, your policy is decorative. Someone will have used the tool, finished the project, and forgotten about it before your review meeting happens.

Commit to a turnaround measured in days, publish it, and hold yourself to it. A five-day answer that is sometimes no beats a three-week answer that is usually yes, because only one of them is fast enough to be worth using.

4. Amnesty, stated plainly

You need to know what is already running, and people will only tell you if telling you is safe. Say in the policy that reporting existing use carries no consequence, then honour it the first time somebody tests you, which is when the policy is really written.

One exception worth being explicit about: if data has already gone somewhere it should not, you need to hear that early, and the incentive has to point toward telling you fast rather than hoping nobody notices.

The clause almost everyone leaves out

Every policy above governs tools people go and adopt. Almost none govern the AI your existing vendors switch on inside products you already pay for, and that is now where most new AI processing appears.

Nobody signed up. No approval was sought, because no human made a decision. Your green list is silent, since the product was already on it, cleared for something that was true last quarter.

Two lines fix it. State that vendor-shipped AI features count as new tooling and are reviewed on the same footing. And name somebody responsible for watching release notes and changelogs for material changes to what your licensed software does with your data.

That second line is the one nobody staffs, which is why it keeps happening. Tracking it is what CopperFeed is for.

Keep it to a page

Length is inversely correlated with compliance. A one-page document people can hold in their head beats a twelve-page one that is technically comprehensive and functionally invisible.

Test it before you publish. Give the draft to three people who are not in security or legal, ask them what they are allowed to paste into ChatGPT this afternoon, and see whether they can answer without rereading it. If they cannot, the problem is the document.

Then revisit it on a schedule, because the tools change faster than the policy will. Something on your green list this quarter may ship a feature next quarter that changes what it does with your data, and the review date is what catches that.

Finding out what is already running comes first, and costs nothing: How to Find Shadow AI in Your Company Without Buying a Tool. The wider picture is in Shadow AI: The Tools Nobody Approved and Nobody Tracks.

General guidance, not legal advice. Employment and privacy obligations vary by jurisdiction, and anything touching monitoring or discipline should go past your own counsel before it ships.