What to Do About the AI Your Team Already Uses
A company's security team cross-referenced its own network logs and found that a good part of the staff was already uploading internal documents to an AI nobody had approved. The response was to block access that same afternoon. Two weeks later the traffic came back. Nobody could see it anymore.
Carlos Andrés Ramírez ·
A company's security team cross-referenced its own network logs and found that a good part of the staff was already uploading internal documents to an AI nobody had approved. The response was to block access that same afternoon. Two weeks later the traffic came back. Nobody could see it anymore.
It happens in almost every company that actually looks. Someone audits outbound traffic, or reviews the corporate card statements, or just asks in a meeting who has tried this, and the same surprise shows up: people are already using AI, on personal accounts, on the free tier, uploading whatever the work requires to hit the deadline. Nobody decided this in a committee. Every person decided it alone, on some ordinary Tuesday, because the approved tool took weeks to clear and the deadline did not wait weeks.
The first instinct is almost always to shut it down. Block the domain, add the AI to the proxy blacklist, send a reminder about acceptable use. It feels like action. And it is, except it solves the wrong problem. The risk was never that the AI existed. It was that nobody knew what data was leaving through it. Blocking access kills the one signal the company had to measure that risk, right when it could finally see it.
The symptom
What does a company do when it finds out its people are already using AI without permission (shadow AI)?
The reflex answer almost everyone gives is ban first, ask later. Legal sends the notice, IT closes the access, the committee exhales because it did something visible. But the use does not disappear. It moves. Someone who already found that AI saves hours of work does not go back to the manual method because an email arrived. They switch devices, use a personal phone, log in from a network the company does not watch. The company gets a memo and loses the visibility it had by accident.
- The first sign of unauthorized AI use comes from an expense or traffic audit, almost never from someone reporting it.
- The acceptable use policy has existed for a while, but nobody updated it since AI tools changed this fast.
- The team using unauthorized AI the most is usually the one under the most delivery pressure, not the one that understands the risk least.
- The company's response gets decided in a same-day crisis meeting, before anyone measured what data went out or where.
- Blocking the domain on the corporate network does not reduce use. It moves it to a personal phone, where the company sees nothing at all.
The problem underneath
The risk is not that your people use AI. It is banning it before you look.
When a company discovers unauthorized AI use, it has, without realizing it, information it did not have the week before: real demand exists, this is the kind of task people solve with it, and these are the people doing it. That information is worth more than what the company had a month ago, when the use was already happening and nobody had looked. Banning it immediately throws that information away before it gets used for anything.
And there is a second loss, costlier than the first. Every time an employee finds a faster way to work and the company takes it away without offering an equally fast alternative, they learn a lesson that sticks: solving the problem on your own works better than asking permission. The next tool they find, they will not report. They will hide it better.
Banning the AI your people already use does not remove the risk. It removes it from view, the same day you finally had it in front of you.
BECOME
The framework
What should happen in the first weeks after discovering unauthorized use?
The five pieces below get worked in order, not all at once, and in the first weeks after the first signal shows up, not months later as part of a fully built governance project.
- Real scope
- What is being used, with what data, and across how many teams, before deciding anything. Without this map, whatever policy gets written ends up solving a problem nobody measured.
- Amnesty window
- A short, clearly communicated period in which declaring existing use carries no disciplinary consequence. Without it, nobody comes forward and the map from the first step stays incomplete.
- Data red line
- Which categories of information are off limits with no exception, such as client data, contracts, or regulated information, while everything else waits for a calmer decision. Not all use carries the same weight, and treating it as if it did is what makes the ban feel arbitrary.
- Sanctioned fast path
- An approved alternative that takes as long to clear as it takes an employee to open a new tab, not several weeks. If the official route stays the slowest one, unauthorized use comes back within a month.
- Risk owner
- One named person with the authority to decide, case by case, what gets tolerated while the permanent policy gets built. Without that owner, every manager improvises their own rule, and the company ends up back where it started.
None of the five requires turning the company into an AI police force, or treating whoever already uses it as if they did something wrong. It requires the opposite: recognizing that this person found a real problem and a faster answer than the one the company offered, and building the version of that answer the company can actually sustain.
Before writing a single line of policy, ask three different teams what AI tool they already use today, without anyone having approved it. If the answer comes back fast and straight, there is still a window to sort this out without losing the trust of whoever is about to tell you. If the answer is silence, that window already closed, and it has to be earned back.
Frequently asked questions
What does a company do when it finds out its people are already using AI without permission (shadow AI)?
The first move, almost always, is to measure before banning: which tools are in use, with what kind of data, and across which teams, before writing any new policy. Blocking access without that map does not remove the use. It hides it better, and the company loses the one chance it had to see the risk clearly.
Why do people use unauthorized AI when the company already has an approved tool?
Almost always because the approved tool takes too long to arrive, not because the person wants to break a rule. When approving a new AI tool takes weeks and the deadline will not wait, most people choose to get the work done with whatever is at hand, approved or not.
Is it better to ban unauthorized AI use immediately or give people time to declare it?
A short window to declare existing use without disciplinary consequence usually works better than an immediate ban, because it produces real information about what is being used and with what data. Banning it without that window does not remove the use. It moves it to personal devices where the company has no visibility at all.
Who should decide what to do about unauthorized AI use that already exists inside a company?
There has to be one named person with the authority to decide case by case while the permanent policy gets built. Without a single owner, every department manager improvises their own rule, and the company ends up with as many informal policies as teams, which is exactly the problem it was trying to solve.
Let's get a handle on the AI you already have
From the idea to the operation
Scaling under control means deciding limits, oversight and traceability first. Adding them later means rebuilding.
About the author
Carlos Andrés Ramírez — Transformation Director
Specialist in business transformation and reinvention. Director of Specialised Programmes and lecturer in Artificial Intelligence at UPC's Graduate School.