Thought Leadership

The Shadow AI Trap: Why Blocking Chatbots Increases Enterprise Security Risk

Banning public generative AI tools doesn't stop usage. It creates a corporate blind spot on employee mobile devices.

In the spring of 2023 a series of famous employers discovered that generative tools had entered the building without a project plan. Samsung told staff, after sensitive code was uploaded to ChatGPT, that generative AI was temporarily restricted on company machines. CNBC and The Verge, citing internal reporting, described a ban that also asked people not to upload sensitive business information from personal devices. The company said it was buying time to create a secure environment. JPMorgan and other large banks had already limited ChatGPT on similar grounds. The instinct was understandable. The control was incomplete the moment the phone stayed in the employee’s pocket.

A year later the numbers had not gone back in the bottle. Microsoft and LinkedIn’s Work Trend Index reported that 75 percent of knowledge workers use generative AI at work and that 78 percent of AI users bring their own tools. Leaders agree they need AI — 79 percent in that survey — and 60 percent worry their organisation lacks a plan. Prohibition did not produce a plan. It produced a second network.

What the restriction changedWhat it left in place
The tool in the managed browserThe deadline, the blank page, and the colleague whose draft took ten minutes
A visible corporate destinationThe personal account, the personal laptop, and the phone on a guest network
The company’s ability to say it had actedThe log. The data still leaves. The company cannot see it
The instinct, which was soundThe sequence. Restrict now, and postpone the secure environment until a steering committee agrees a vendor

What a ban actually removes

A network block removes the tool from the managed browser. It does not remove the deadline, the blank page, or the colleague who says the draft took ten minutes instead of two hours. People under that pressure do what they did in every previous generation of shadow IT. They use a personal account, a personal laptop, or a phone on a guest network. The data still leaves. The company has lost the log.

IBM’s Cost of a Data Breach research put a cost on that pattern: one in five organisations studied reported a breach involving shadow AI. High levels of shadow AI were associated with roughly $670,000 in additional average breach cost. Incidents involving shadow AI compromised personally identifiable information and intellectual property at higher rates than the global averages in the study. Only 37 percent of organisations had policies to manage AI or detect unsanctioned use. A policy that says “do not” and a network rule that cannot see the phone are not, together, a programme. The Cost of a Data Breach report is the longer version of the same finding.

The same research found that 13 percent of organisations reported a breach of an AI model or application, and that 97 percent of those compromised lacked proper AI access controls. The lesson is not that AI is uniquely cursed. It is that companies turned it on, or allowed it to be turned on, without the boring machinery — identity, scope, retention — they would have demanded of a new file store.

FigureWhat a quiet proxy log will not tell you
75 percent of knowledge workers use generative AI at workThe block did not end the work
78 percent of AI users bring their own toolsThe second network is the normal path
60 percent of leaders worry the organisation lacks a planProhibition was asked to stand in for the plan
1 in 5 organisations reported a breach involving shadow AIThe unofficial path is already in the incident set
About $670,000 higher average breach cost where shadow AI use was highThe premium sits on the path you cannot see
37 percent have policies to manage AI or detect unsanctioned useMost companies cannot tell whether the ban worked
97 percent of those with an AI-related compromise lacked proper access controlsThe missing machinery is identity, scope, and retention

Why employees are not villains in this story

Call the behaviour misconduct and you will design the wrong remedy. The Work Trend Index’s harder finding is that employees adopted the tools because the work demanded it and the employer had not caught up. Sixty percent of leaders doubting their own plan is an admission. People do not wait for an admission to become a platform.

There is also a quality reason they leave the official path. Early “enterprise” assistants were often a boxed model with a login wall and no access to the files the job required. The personal chatbot at least let them paste the paragraph they needed rewritten. Paste is the leak. Paste is also a rational response to a tool that cannot see the document it is supposed to help with. If the sanctioned system cannot do the job, the ban trains people to become their own integration layer, copying sensitive text from the system of record into a consumer window and copying the answer back. You have built an exfiltration workflow and called it compliance.

What a substitution programme must include

Samsung’s memo was explicit about the sequence: restrict now, build a secure environment, then allow the productivity. Many companies did the first step and postponed the second until the steering committee could agree a vendor. The postponement is the failure.

A substitution that works has four properties.

It can see the right documents. Not every document. The documents for this job, under the same permissions the person already has. If the assistant is blind, paste returns.

It does not train a public model on the company’s text. Employees cannot be expected to read a consumer privacy policy in the middle of a closing. The enterprise agreement has to say, in language a manager can repeat, what is retained and what is not.

It keeps a record. When something goes wrong, “we banned ChatGPT” will not explain the customer email that was sent anyway. The sanctioned path should show the draft, the sources, and whether a person approved the outbound version.

It is not a punishment. If the official tool is slower, uglier, and less capable, people will keep a personal account for the work they care about and use the official one for the work they are willing to have seen. That split is the worst of both worlds: the risky work is the invisible work.

PropertyPresentMissing
Sees the documents for this job, under the person’s existing permissionsPaste is unnecessaryPaste returns. The employee becomes the integration
Does not train a public model on company text. A manager can say what is retainedPeople do not have to parse a consumer privacy policy at close of businessThe agreement is a PDF nobody can repeat
Keeps the draft, the sources, and whether a person approved the outbound version“We banned ChatGPT” is not the only sentence you haveThe customer email went out anyway, and you cannot show the path
Faster than the personal account for the work people care aboutThe risky work is the visible workThe official tool gets the harmless work. The phone gets the rest

What to put in people’s hands the same week you tighten the block

So design the week as a substitution, not as a speech. Name the three tasks that are driving the personal accounts — drafting from a document the person already has, summarising a thread, searching an internal policy — and make those three tasks fast on a tenant you operate. Fast means the account exists before the block tightens, the document can be reached under the person’s existing permissions, and the output stays in a log you can show later. If you cannot do those three tasks well yet, delay the spectacle of the ban and keep a narrower block on the truly uncontrolled paste of code, credentials, and unpublished numbers. A narrow block you can explain will be respected more often than a total block you cannot police.

Measure the thing you are afraid of, not the thing that flatters the policy. Proxy denials will fall after a ban and look like success. They are success only for traffic that respects the proxy. Ask, in a short pulse, whether people used a personal tool for company work in the last week, and whether that work included customer data, code, or financials. You will under-count. Even a partial count should be read against the external benchmark that most AI users bring their own tools, and against breach research in which shadow AI was common and usually ungoverned. A rising pulse after a ban means the policy moved the work. It did not remove it.

Give managers a sentence they can say without becoming hypocrites: “Use the company tool for anything that touches a customer, a number we have not published, or code. If it cannot do the job, tell me, and we will not pretend you should have pasted it elsewhere.” Then mean the second clause. A manager who is punished for a missed deadline and punished for a workaround will choose the workaround you cannot see. The framework language for this is straightforward: map the real use, give it a governed route, measure what still leaks. The route is a product problem. Security cannot finish it alone, and a policy team cannot finish it on paper.

This weekDo thisTreat this as a false victory
Before the blockProvision the account. It can see the files the person may already see, and it keeps a logA speech, then a block, then a vendor selection that takes a quarter
The block itselfNarrow: code, credentials, unpublished numbers, customer dataA total ban you cannot police. The careful wait. The fast use a phone
The three tasks driving personal accountsDrafting from a document they have, summarising a thread, searching an internal policy — fast, on your tenantAn enterprise login that cannot see the document
The measureA pulse: personal tool in the last week, and whether it touched customer data, code, or financialsProxy denials falling. Quiet logs are what phones look like
The manager’s sentenceUse the company tool. If it cannot do the job, say so. You will not be told you should have pastedPunishment for the deadline and punishment for the workaround. They will choose the workaround you cannot see

The path, then the block

Provision the sanctioned account before you tighten anything. It has to see the files the person is already allowed to see, and it has to keep a log. Then block the destinations you truly cannot defend, and say so narrowly: code, credentials, unpublished numbers, customer data. A total ban you cannot police trains the careful to wait and the fast to use a phone. That is the failure mode already on the record. Pulse people on whether company work still happens in personal tools. A quiet proxy log is not the answer. The pulse is. Run it before you declare the policy a success.

A call to chief information security officers and chief operating officers

Keep the block on truly uncontrolled destinations if you must. Do not confuse it with a strategy. Publish the sanctioned path, fund it until it is actually usable, and measure shadow use instead of declaring victory when the corporate proxy log goes quiet. Quiet logs are what phones look like.

Samsung was right that source code does not belong in a consumer chatbot. The companies that copy only the restriction will meet the same code again, later, in a breach report, with a line that says the employee was not on the network when they pasted it.


References

About Nimbus

Nimbus is a Collaborative AI Operating System built around four core pillars that bring human teams and autonomous AI together into a single, unified workspace.

Communication: Keep context tied to the job. Unify emails, meeting recordings, transcripts, and operational files directly within active projects—ending knowledge silos buried in private inboxes, scattered Slack threads, or unrecorded calls.

Collaboration: Work alongside AI in real time. Bring people and AI agents onto the exact same brief, visual canvas, or initiative. Query company-wide data, invite agents into live calls, and co-create in one shared space—eliminating the split between human group chats and isolated AI sidebars.

Automation: Put routine workflows on autopilot. Connect more than 2,000 enterprise tools and standardize repetitive operations. Background loops run on schedules or data triggers with full execution logs, ensuring operational knowledge is shared across the team rather than trapped in one person’s head.

Governance: Deploy AI with absolute control. Enforce strict role-based access controls across workspaces. AI agents can analyze, summarize, and draft—but no live system changes or external communications occur without explicit, verified human sign-off.

Short answers

A ban is a change of device

What happened when companies banned public chatbots?

After leaks and compliance scares, the ban felt like control. For many employees it was a change of device, not a change of behaviour.

Why do people keep using the personal tool?

The official path is slower or missing, and the phone still works.

What works instead of a ban?

A tool people can finish the job in, with a record and a stop, so the personal account is no longer the path of least resistance.

See what governed AI looks like on your stack.

Connect your tools, run a workstream, and keep every decision on your ledger. Start on Free.