IO Technology Group — Cloud. AI. Security. Transformation.
Menu

IO Insights / AI Governance

Unmanaged AI: The risks hiding in everyday work

AI adoption often begins before governance catches up. A practical guide to finding unapproved use, protecting business information, and establishing an approved path forward.

An employee pastes a customer document into an AI assistant to save time. A developer connects an unfamiliar coding tool. A department starts using a browser extension without involving IT. Each decision can feel small. Together, they can move company information into services your organization has never assessed.

Unmanaged AI, often called Shadow AI, is AI use outside your organization's approved ownership, review, and controls. The right response starts with understanding the work people are trying to accomplish and giving them a governed way to do it.

Where unmanaged AI creates exposure

Company information leaves a reviewed boundary

A prompt can contain customer records, pricing, source code, or confidential deal information. Review each service's terms, account type, retention settings, and connected tools before approving those uses. Training practices vary: Microsoft states that prompts, responses, and Microsoft Graph data in its commercial Copilot service are not used to train foundation models. That does not establish the terms of a different product or personal account. Microsoft's data protection guidance explains this distinction.

Existing access problems become easier to encounter

Microsoft Copilot works within a user's existing permissions. If a sensitive document is already shared too broadly, that access needs correction. Deploying Copilot does not repair the underlying permission model. Review group membership, sharing links, and repository ownership as part of readiness. Microsoft's explanation of organizational data access makes this responsibility clear.

Confident output can still be wrong

An AI-generated answer can sound authoritative while containing invented facts, citations, or explanations. NIST identifies this risk as confabulation. Assign human review before generated material informs a customer commitment, important decision, or production change. NIST's Generative AI Profile describes this and other risks organizations should assess.

Untrusted content can influence an assistant

Prompt injection can arrive through a document or website an assistant reads, attempting to redirect its behavior. The consequences depend on the information and tools it can access. Limit permissions, treat retrieved material as untrusted, and require approval before consequential actions. These measures reduce exposure; they do not eliminate every attack. OWASP's prompt injection guidance explains the threat and mitigations.

Missing records make investigation harder

If the business cannot establish which account, service, or data was involved, investigating a suspected disclosure becomes harder. Ask what evidence each approved use requires, where it will be retained, and who can access it. A policy document alone does not provide that evidence.

Start with discovery that has a defined scope

Build an inventory of AI applications, browser services, extensions, integrations, and locally installed tools. Combine available technical evidence with conversations across departments. Capture the business purpose and owner, not just an application name.

Distinguish a detected visit from evidence of a prompt or upload. Microsoft Purview can provide visibility and protections for supported AI interactions, but coverage depends on the app, browser, device onboarding, policies, permissions, and licensing or billing prerequisites. Some capabilities require an extension or specific integration. Microsoft's third-party AI support guidance details those boundaries.

Document the devices and channels included in your assessment, the content you can inspect, and known gaps. Handle captured prompts as potentially sensitive information: define collection scope, reviewer access, and retention before enabling content capture. An AI Readiness Assessment should turn these findings into prioritized decisions.

Put the data foundation in order

Start with the information most important to your business. Identify its owners, intended audience, sensitivity, and lifecycle. Then work through a focused checklist:

  • Correct excessive access and inappropriate external sharing.
  • Classify important information and apply appropriate protection policies.
  • Review connected repositories, application permissions, and agent access.
  • Test realistic allowed and blocked scenarios using non-sensitive sample data.

Record expected behavior and test results before expanding access. A Copilot and AI Foundation Implementation should connect the data preparation, deployment configuration, and operating responsibilities.

Give employees a clear approved path

Publish a concise standard: approved services and account types, permitted data, prohibited uses, required review, and a route to request exceptions. Show employees examples relevant to their roles.

Use appropriate identity, endpoint, browser, and network controls to enforce the decision within the managed environment. Test restrictions against required business workflows. Do not assume blocking known websites covers personal devices, every embedded AI feature, or every locally running model.

Assign ownership for reviewing new services, investigating alerts, and updating the inventory. Reassess when vendors, integrations, or business use changes. Shadow AI assessment and controls should support an ongoing operating process with documented coverage.

What this looked like in an enterprise engagement

A large enterprise customer engaged IO Technology Group because it lacked controls around employee AI use and was concerned about compliance exposure.

IO performed an AI Readiness Assessment and AI Foundation Implementation. Discovery examined desktop and browser AI use and the types of prompts and data employees shared within the assessed environment. IO established a governed data foundation, implemented the approved company Copilot environment with Microsoft Purview guardrails, and introduced restrictions on unapproved AI use across the managed scope, alongside ongoing Shadow AI monitoring.

The engagement connected discovery, implementation, and ongoing oversight. Product configuration supports the organization's compliance program; it does not by itself guarantee compliance. Read the enterprise AI project overview.

Choose the next decision with evidence

Begin with one question: which AI use creates the greatest uncertainty about company data today? Establish the facts, identify the owner, and prioritize the controls. IO can help you move from that assessment into implementation. Discuss your AI environment with IO.

Further reading

From insight to action

Make AI useful.
Make its use accountable.

IO helps organizations assess AI use, establish a stronger data foundation, and implement an approved AI environment with controls that fit the business.

Discuss AI readiness

Back to all Insights