Your Staff Already Use AI. The Only Question Is Where the Data Goes.
Unapproved chatbot use is already routine in most companies. What leaves the building, why bans fail, and how to give people a safe alternative.

Ask a department head how many AI tools their team uses and you get a number. Ask the team anonymously and you get a bigger one. That gap is shadow AI, and it is not fringe behaviour. For a large share of office workers it is simply how the work gets done now, because nobody gave them a sanctioned way to do it.
What actually gets pasted
Not the trivial things. People do not open a chatbot to spell-check a memo. They open it when the work is hard and the deadline is close.
So what goes into the box is the draft supplier contract that needs summarising before a call at four. The candidate's CV and the interviewer's blunt notes, turned into a rejection letter that will not cause trouble. The angry customer email with the account number still in it. A spreadsheet of last quarter's margins by client, pasted whole so the model can find the pattern. Production logs that happen to contain an API key three lines down. The board pack, because someone wanted a plain-English version by morning.
Every one of those is a reasonable decision by an employee trying to do a good job. Together they move your commercially sensitive material, your customers' personal data and occasionally your live credentials onto infrastructure you have no contract with, no retention terms for, and no record of.
Why the ban fails
The usual response is to block the domains and send a firm email. It does not work, and it makes things worse in a specific way.
Blocking the corporate network moves the activity to personal phones, where you have no visibility at all. The work still gets done with AI, just outside anything you can see or govern. Meanwhile the people who obey the policy do the same tasks more slowly than the people who ignore it, which teaches everyone which behaviour the company actually rewards. A ban converts a manageable problem into an invisible one and pays for the privilege in productivity.
The exposure is contractual before it is technical
The real risk is rarely a dramatic breach. It is the paperwork.
Consumer tiers of most chatbots may use what you type to improve the product; business tiers generally do not. That distinction is the difference between a normal vendor relationship and an unlogged transfer of personal data to a processor you never appointed, with no data processing agreement, no defined retention period and no idea which jurisdiction it landed in. Your own client contracts increasingly forbid exactly this, and many now require you to name every sub-processor touching their data.
The worst part is the record. When a major client asks whether their information has been through a third-party AI system, "we don't know" is a far more damaging answer than "yes, under these terms."
Give people somewhere better to go
Shadow AI is a demand signal. Your staff have told you, through their behaviour, that this tool makes them faster. The job is to meet that demand on your terms.
A sanctioned option only works if it is as good as what they use now and no harder to reach. That means a proper business or enterprise tier with training on your inputs disabled, single sign-on so leavers actually lose access, retention configured on purpose rather than by default, and a signed agreement you can show a client. For the narrow band of genuinely restricted material — patient records, unreleased results, code under NDA, legal privilege — the answer is a model running on hardware you control, where the data never leaves the building.
The first month
- Ask rather than audit. An anonymous survey asking which tools people use and for what will tell you more in a week than log analysis will in a quarter, and it does not put anyone on the defensive.
- Buy one tool properly. Pick the leader for your main use case, take the business tier, turn off training, put it behind SSO, and roll it out to everyone who needs it.
- Write one page of rules in plain language. Three categories — fine, ask first, never — with real examples drawn from your own business, not abstract data classes.
- Name a person for the middle category. If "ask first" has no address, it becomes "do it anyway."
- Train the heaviest users for an hour. They set the norms for everyone else.
- Review in ninety days against what people actually do.
The target is not zero AI use outside the approved list. The target is that nothing sensitive leaves your organisation without a contract standing behind it, and that you can say so with evidence.
This is the part of AI adoption that no one volunteers for: the survey, the vendor terms, the awkward inventory of what has already gone out. At Hercules A we carry that weight for our clients, including the private, on-premise models for the work that should never touch a public service. The heavy lifting is the point.