Shadow AI & Acceptable Use

What Data Are Employees Allowed to Put Into AI,
and How Do You Stop Shadow AI?

The one-page, class-based rule that ends the guessing, the sanctioned tool that ends the workaround, and the limit that no written policy reaches.

Built from real buyer questions in our sales meetings

Every employee you have already wrote an AI policy. They wrote it the first time a deadline collided with an open browser tab and nobody had told them which tool to use. Silence never stopped AI use; it only decided who sets the rule. The questions your people are asking are small and unanswered: what am I allowed to put into these things, and which one am I supposed to open?

Direct Answer

Publish a short, class-based rule, and pair it with a tool worth using. The rule names three things: what may go into a sanctioned tool, what may never go into any tool, and which tool is sanctioned for each class. Employees left guessing default to whatever is open in their browser. Buyers described unsanctioned AI as already widespread, and the fastest way to end it is to make the sanctioned option local, free at the point of use and at least as good — rather than to police the endpoint. Policy without a sanctioned alternative pushes usage out of sight.

The limit is the device you do not control. One workaround is already known: a user who runs into a daily query limit moves to another device, such as a phone. A good sanctioned option removes the reason to go elsewhere; it does not remove the ability, and no endpoint policy you write reaches the phone in somebody's pocket. Make the safe path the easy path, then measure adoption rather than expecting enforcement.

Three things belong in writing before you publish. What the sanctioned tool records on the device and who may read those records; whether usage is metered, since a tool that bills per query teaches people to ration it; and how it handles your own documents, tested by the people who will live under it. Iternal states that AirgapAI runs 100% local on an AI PC, carries a one-time perpetual license per device with no token fees, and logs activity on the machine.

Written policy and technical enforcement are two separate projects. The human half is the classes, the tool per class, the escalation path and the quality bar that keeps people on it. For more information visit the access control and admin console page.

Shadow AI Is Already in the Building

Shadow AI is the buyers' own phrase, and what sits underneath it is consistent: free consumer accounts used for company work, AI subscriptions expensed so the cost never lands in an IT budget, business units buying their own tools with no standards, whole workforces adopting several assistants at once with no guardrails and no policy in place. One buyer summarized the mechanism: divisions will procure their own AI solution if none is made available to them.

The sharp end is the material that travels with it — a confidential product formula pasted into a public chatbot, design trade secrets leaving the company through an AI tool with nobody intending it. The pattern reads as unmet demand rather than disobedience, which is why substitution works where blocking does not.

Write the Rule as a Table, Not an Essay

A policy people follow fits on one page and answers the employee's question at the moment they have it. One buyer put the failure directly: the AI policy is approved, and the procedure behind it does not exist yet. Four columns turn the principle into a procedure. Adapt the class names and keep the shape:

Class of material Sanctioned tool Prohibited action Escalation path
Public
Published specs, marketing copy, anything already on your website.
Any assistant on the approved list, hosted ones included. Nothing beyond normal accuracy and brand review. None. Use it and move on.
Internal
Drafts, plans, pricing, internal documents.
The assistant that keeps material on the device or inside your network. Pasting into a personal or expensed consumer subscription. Ask the document owner first.
Regulated
Customer, patient, client and controlled material; anything carrying personal data.
The local assistant only, against a data set your governance team prepared. Any hosted tool, any personal account, anything on a purchasing card. A named compliance owner rules case by case, in writing.
Never
Trade secrets, unreleased formulas, credentials, material non-public information.
None. Reclassification comes first. Entry into any AI tool, sanctioned or otherwise. The data-loss incident path you already run.

Every piece of material should map to one row, and every row that permits AI should name a tool. Which classes a deployment may legally hold is a separate question; for more information visit the regulated data classes page.

What You Can See, and What You Cannot

Security leaders and IT administrators told us the same thing in different words: they need to see what employees are doing with AI on the endpoints, and today they cannot. One buyer gave the blunt version — there is no way yet to protect the organization from what its own people do with AI.

On unsanctioned tools you see almost nothing. IT has no visibility into AI subscriptions bought on purchasing cards or personal credit cards, and hosted chat providers cannot report which local files were touched or which local commands ran. One widely deployed assistant returns little more than a daily query count.

A sanctioned local tool changes the picture on the device. Iternal states that AirgapAI keeps full logging and traceability of activity and supports STIG compliance — auditing, tracking and logging of every action taken on the machine. Administrators can read usage audits to see whether people are using the tools and whether their prompting is improving.

Two counterweights belong in the same breath. Iternal reports adoption at the customer level rather than the individual level, to stay as free of personal data as possible — restraint that is a feature, because employees who believe every prompt is read stop asking the questions they need answered. And the product ships without an out-of-the-box access control service, so your team or your managed service partner owns enforcement. Settle both in writing:

Pin it down: questions for your evaluation
  • Which user actions does the assistant log on the device, and where do those logs land?
    Whether your endpoint and log-collection tooling can pick up AI activity like everything else.
  • What can an administrator see about one named user, and what stays aggregate?
    The line between measuring adoption and reading people’s prompts, agreed before rollout rather than after the first complaint.
  • Who configures enforcement of our written rule on the endpoints, our team or a partner?
    Ownership of the policy-enforcement layer, which the product leaves to the customer.

Carve-Out Rules Are Why People Are Guessing

The most common policy failure is the half-job rule. Employees are told some information is too sensitive for the assistant, so half their work may go in and the sensitive half must be done by hand. Education, healthcare and government hesitate over what may be uploaded at all. One buyer named the muddle: organizations say they need everything private, then name the one thing at the end that is not.

A carve-out asks every employee to perform a classification judgment, in the moment, with a career consequence attached. Buyers described staff who worry about getting in trouble for what they put into an AI tool, and staff who avoid an approved assistant because they do not want their employer reading what they ask. They stop using the tool, or they open a personal account where the judgment never has to be made.

Sanction by class, not by task. A class-based rule moves the judgment from thousands of individuals to the organization, once. The employee's job shrinks to recognizing which row their material sits in and opening the tool it names. Where an entire class is sensitive, the answer is a tool that keeps the material on the device, converting “you may not use AI for this” into “use this one for this”. For a four-column table to start from, visit the AI Acceptable Use Policy template page.

If the Sanctioned Tool Is Worse, People Go Back

Buyers raise the objection before you finish the sentence. If the internal solution is too slow, people abandon it and return to the consumer one. Sharper still: a user who is not paying the bill picks the best available model regardless of guidance. Your sanctioned tool competes on merit with a free tab, and loses the moment it is slower, poorer or rationed. Three properties clear that bar:

  • Free at the point of use. Metering teaches rationing. Iternal licenses AirgapAI once per device, perpetually, with no token fees and unlimited use, so the person working never counts queries.
  • Strong on the work that matters. Iternal is straight about where the local experience sits today: the AirgapAI chat experience is very close to, and not yet equal to, a top consumer assistant, and local models sit nearer 2024-era quality than a frontier data-center model. On grounded work over your own documents, where answers come from a prepared data set and cite your sources, that distance narrows sharply.
  • Room for the frontier when the class allows it. AirgapAI can point at a hosted model over an OpenAI-compatible endpoint, so public-class work routes to the strongest available model from one interface while regulated-class work stays on the machine. The rule stops being a downgrade and starts being a router.

Prove it before you publish. Run the sanctioned tool for two weeks with the ten people most likely to defect, on their own work and hardware, and let their verdict set the rollout date.

Answered elsewhere
FAQ

FAQ: Shadow AI and Acceptable Use

Shadow AI is unsanctioned AI use at work — free consumer accounts used for company tasks, subscriptions expensed on personal cards, business units buying their own tools with no standards. Buyers describe it as close to universal, and the cause is ordinary: people have deadlines and an AI tab is open. The durable fix is a sanctioned option good enough to be preferred, published with a rule saying what goes into it. For more information on the exposure it creates, visit the shadow AI risks page.

Three things, on one page: which classes of material may go into a sanctioned tool, which may never go into any tool, and which tool is sanctioned for each class. Add a fourth column naming who rules when a case is unclear. A policy that stops at principles leaves the classification judgment with the employee at the worst possible moment, which produces hesitation, workarounds and churn.

Barely, on unsanctioned consumer tools: IT has no visibility into subscriptions bought on personal cards, and hosted chat providers cannot report which local files were touched. A sanctioned local tool changes that on the device — Iternal states that AirgapAI keeps full logging and traceability of activity and supports STIG compliance. Iternal reports adoption at the customer level rather than the individual level, and your team or managed service partner configures enforcement.

They bypass it whenever it is slower, poorer or rationed. Buyers say plainly that if the internal solution is too slow people go back to the consumer one, and that a user who is not paying the bill picks the best available model regardless of guidance. The counter is a tool that costs nothing per query and holds up on real work. The limit: someone who hits a daily query limit can move to another device, such as a phone.

Because the rule they were given asks them to classify their own work with a career consequence attached. Buyers described employees told that only half their job may go into AI, and employees who worry about getting in trouble for a mistake. Sanction by class rather than by task, so the organization makes the judgment once and the employee only recognizes which class the material sits in.

Start with the policy and the culture statement before any AI project — Iternal tells clients who have neither to do exactly that. A structured risk assessment supplies the inventory to write against: AI inventory, shadow AI discovery, data flow review, risk register, heat map and NIST AI RMF alignment. The one-page class rule then takes an afternoon.

Ship the Rule and the Tool on the Same Day

A rule published on its own tells people what to stop doing. A rule published with a sanctioned tool tells them what to do instead, and only the second one changes behavior. Draft the four-column table this week, then put a local assistant in front of the people who have been improvising without one.

John Byron Hanby IV
About the Author

John Byron Hanby IV

CEO & Founder, Iternal Technologies

John Byron Hanby IV is the founder and CEO of Iternal Technologies, a leading AI platform and consulting firm. He is the author of The AI Strategy Blueprint and The AI Partner Blueprint, the definitive playbooks for enterprise AI transformation and channel go-to-market. He advises Fortune 500 executives, federal agencies, and the world's largest systems integrators on AI strategy, governance, and deployment.