An estimator at a small fabrication shop in Channelview is up against a deadline. He has a forty-page bid package, a customer's pricing history and about an hour. So he drops the whole thing into a free chatbot on his phone and asks for a summary and a draft response. It works beautifully. He does it again the next week, and tells two coworkers.

Nobody in that story is doing anything malicious. They are trying to get good work done faster. But in about ten seconds, a customer's confidential specifications and your own pricing strategy left the building and landed in a service your company never reviewed, under terms nobody read.

That is what people mean by "shadow AI": AI tools used for work without the business knowing about them or setting any ground rules. In most small offices we visit around Houston, it's already happening.

Why it spreads so quickly

Most business software arrives through a decision. Someone gets a quote, the owner signs off, and IT sets it up. AI tools skip all of that. They are free or cheap, they run in a browser or on a phone, and one person can start using one in the middle of a busy afternoon.

That means the usual checkpoints never happen. Nobody asks where the data goes, whether the provider can use it to improve their models, or what happens to the account when the employee leaves. And because the tools really are helpful, people are reluctant to mention them in case they're told to stop.

What's actually at risk

The concern isn't AI itself. It's the information people feed it. The things we'd least want to see pasted into an unapproved tool:

  • Customer personal information, like names paired with account numbers, birthdates or driver's license details.
  • Health information in medical, dental or benefits settings, where privacy rules apply.
  • Contract, bid and pricing documents that a competitor would love to see.
  • Financial records, payroll exports and bank details.
  • Controlled or export-sensitive technical data for businesses that serve defense, energy or government customers.
  • Passwords, network details or screenshots of internal systems.

There's also an ownership problem. If an employee builds a useful workflow in an AI account tied to a personal email address, that history, including anything pasted into it, walks out the door with them.

Put a one-page AI policy in place

You don't need a thick handbook. A single page that people actually read beats a long document that nobody opens. Cover these points:

  • Approved tools. List the AI tools the company supports, and state that work happens in work accounts, never personal ones.
  • Red-line data. Spell out the categories above in plain language: "never paste these into any AI tool that isn't on the approved list."
  • How to ask for a new tool. Give people a simple way to request something, and answer quickly. A slow "no" pushes usage back underground.
  • Check the output. Anything AI produces for a customer or a regulator gets reviewed by a person first.
  • Who to ask. Name one person to go to with questions.

Then talk about it at a staff meeting. Ask, without judgment, which tools people are already using and what they find helpful. You'll learn a lot, and people are far more likely to follow a policy they helped shape.

Back the policy with the right settings

A policy tells people what to do. Your systems can make the safe choice the easy choice. If your business runs on Microsoft 365, there are settings worth reviewing:

  • Offer an approved alternative. Microsoft's Copilot, signed in with a work account, is built with business data protections in mind. Confirm how it's licensed and configured for your tenant, then point staff to it.
  • Limit third-party app access. Restrict who can grant outside apps permission to read company email, files and calendars.
  • Label sensitive files. Sensitivity labels and data loss prevention rules can flag or block sensitive content from being shared where it shouldn't go.
  • Manage devices and browsers. Company-managed devices make it possible to see and control which browser extensions are installed.

These controls are powerful, but they need to be set up carefully so they don't break everyday work. That's where our network security team comes in. If your business has regulatory obligations, our compliance services can help you tie an AI policy into the rest of your documented safeguards.

Start this week by simply asking your team what they're using. The answers will tell you exactly where to begin.