Shadow AI Is The New Shadow IT

End-users are pasting sensitive data into unvetted AI tools. Here is why blanket bans fail and how MSPs can build actual data governance.

Shadow AI Is The New Shadow IT

Why blocking ChatGPT at the firewall fails, and how MSPs can stop employees from leaking sensitive data into unapproved tools.

5 min. read


A technician on our team was troubleshooting a browser slowdown for an accounting client a few weeks back. While checking the active tabs on Chrome, he saw something that made his stomach drop. Open in one of the browser tabs was a free web version of a popular public AI chatbot. Pasted directly into the prompt box was a complete, unredacted payroll spreadsheet containing employee social security numbers, home addresses, bank details, and salary figures,... The user was simply trying to write a quick formula to summarize department bonuses before an afternoon meeting. She was not trying to steal data or bypass security controls. She was just trying to get her work done forty minutes faster so she could clear out her inbox.


That single incident perfectly illustrates the massive headache every managed service provider is quietly wrestling with right now.


For the last decade, we fought the war against traditional Shadow IT. That battle was usually pretty straightforward. An employee would sign up for an unapproved file sharing app or purchase a cloud storage subscription on a corporate credit card. It was annoying from an administrative standpoint, but the core risk was mostly confined to where files were sitting. Shadow AI is a completely different beast. When an end-user pastes proprietary code or internal financial logs into a consumer chatbot, that data immediately leaves the corporate perimeter. It gets processed on servers we have zero visibility into, and depending on the terms of service, it might end up training a public model for anyone else to query later.

The instinct for a lot of IT directors and MSP owners is to immediately react like the Department of No. The knee-jerk reaction is to jump into the DNS filter and block every major AI domain we can think of. We hit the big ones first. We block the web interfaces for Gemini, ChatGPT and Claude. We post a stern reminder in the company newsletter about data privacy and feel like we solved the problem.


That approach is an absolute illusion of security.

Blanket blocking AI tools fails almost immediately for several reasons. First, end-users are incredibly resourceful when their daily productivity is threatened. The moment you block an AI website on the corporate network, employees simply open the app on their personal smartphone over a cellular connection. Or they log into a personal webmail account on their work laptop and route the work around your controls. You have not stopped the behavior. You have just pushed it completely into the dark where you cannot track it at all.

Second, AI is no longer just a standalone website you can block at the firewall. It is being baked into every single software application on the planet. PDF editors, web browsers, meeting transcription tools, and customer management platforms are all bolting generative features into their standard updates. Microsoft alone tracks over a thousand different AI applications in their cloud app catalogs. Trying to block AI with traditional web filtering is like trying to keep water out of a boat using a strainer.

Finally, acting as a strict gatekeeper completely ruins your relationship with the client. If you position your MSP as the hurdle standing between employees and modern productivity tools, executives will eventually start viewing you as a bottleneck to their business growth.


So how do we actually fix this without becoming the bad guy or exposing our clients to massive compliance fines?


It starts with changing the entire conversation around AI data governance. Instead of treating AI usage as an unauthorized breach of protocol, we need to frame it as a standard operational risk that requires clear lanes.

The first step is establishing total visibility before you attempt to write a single policy. Most business owners have absolutely no idea how heavily their staff relies on consumer AI tools. If you ask a CFO whether her team uses unapproved AI, she will confidently tell you no. But if you run an endpoint assessment or pull the telemetry from Defender for Cloud Apps across their managed devices, the data tells a radically different story. You will find that forty to fifty percent of their staff are actively using web-based writing assistants or summarizers every single day.

Showing up to a quarterly business review with actual usage data changes everything. You are no longer making hypothetical warnings about future risks. You are showing the client a clear snapshot of their current exposure.


Once the reality is on the table, you need to provide what I call the approved lane. Prohibition without an alternative always leads to evasion. If employees need AI to handle writing tasks or data processing, you have to offer a sanctioned tool that includes enterprise data protection. That might mean deploying Microsoft Copilot within their Business Premium licensing where commercial data is explicitly protected and not used for model training. It might mean setting up an enterprise workspace where prompt histories are strictly contained within the tenant. When you give users an approved tool that actually works, unsanctioned web usage drops dramatically overnight.

After setting up the approved path, you deploy smart technical guardrails at the point of use instead of relying on nuclear blocks. Modern endpoint security and browser extensions allow us to perform local content inspection. Instead of completely blocking a web page, the browser tool can look at what the user is typing in real time. If an employee attempts to paste a credit card number or source code into a web form, the system pops up a gentle warning. It prompts the user to confirm whether the data is safe to submit, or it redacts the sensitive fields automatically before the payload leaves the machine.

This approach turns security into an interactive teaching moment. It educates the user right when they are making a mistake, rather than silently logging a violation or throwing up a frustrating block page.


This shift in strategy is also an unbelievable business opportunity for independent MSPs. Cyber insurance underwriters and compliance auditors are starting to ask brutal questions about how small businesses govern artificial intelligence. Most SMBs are completely unprepared to answer those questions. They do not have the internal bandwidth or technical knowledge to draft an AI policy, let alone enforce it on their endpoints.

By building a structured AI governance offering, you turn a terrifying compliance risk into a high-value managed service. You can implement browser-level data loss prevention policies and provide ongoing usage reports as a standard line item on your agreement. It elevates your company from a basic help desk that fixes broken printers into a strategic advisor protecting the core assets of the business.


Shadow AI is not going away. Employees have tasted the speed and convenience of these tools, and they will continue finding ways to use them regardless of company rules. Trying to stop them with outdated web blocks is a battle you will lose every single time. By offering sanctioned tools and implementing smart DLP guardrails, we can keep their networks safe without getting labeled as the department that kills innovation.


How are you handling unapproved AI tools across your client base right now? Are you attempting to block them at the DNS level, or have you started rolling out dedicated governance policies for your tenants?

If you want to see more guides, scripts, and technical deep dives just like this, make sure to follow us on Twitter, check out our Facebook page, and sign up for the weekly 404 & More newsletter! ✌️