How do you govern AI tools nobody approved?
By treating it as a third-party and data-flow question rather than a technology question, because that is what it is. The control that works is not a prohibition nobody can enforce, it is a sanctioned route that is easier than the unsanctioned one, plus visibility of where organisational data actually goes.
Published
Maximilian Bazzi, Founder and CEOWhy this is not a technology question
Ungoverned use of AI tools looks, at first, like a technology problem: which tools are people using, and how do we detect and block them. Framed that way, it becomes an arms race the organisation cannot win, because new tools appear faster than any block list can be maintained, and determined use moves to personal devices and accounts entirely outside the organisation's visibility.
The more useful frame is the one the organisation already has mature practice in: this is a third-party risk and data-flow question. An unsanctioned AI tool is, functionally, an unassessed third-party processor that organisational data is being sent to, with no due diligence, no data processing agreement, and no visibility into retention or onward use. Every existing discipline for third-party risk applies. The novelty is only that the "vendor onboarding" is happening without anyone in procurement or risk being asked.
Why prohibition does not work as the control
A policy prohibiting unapproved AI tools, without more, controls nothing that a determined or simply uninformed employee cannot route around in under a minute. People adopt these tools because they solve a real problem faster than the sanctioned alternative, and a prohibition that does not offer an equally fast sanctioned route does not remove the underlying incentive, it just moves the activity out of sight.
What the control that works actually looks like
The control that works has two parts. First, a sanctioned route that is genuinely easier to use than the unsanctioned alternative: an approved tool, or a small approved set, that is fast to get access to and covers the common use cases people are already solving for themselves. Second, visibility into where organisational data actually flows, through data-loss prevention tooling, browser or endpoint telemetry, or simply asking, so that the gap between sanctioned use and actual use is known rather than assumed to be small.
The carried fact this section exists for
Count the AI tools your organisation has formally approved. Then ask three people in different functions, not risk or IT, what they actually used this week to help with their work. The gap between those two numbers is the organisation's actual exposure, and in most organisations that have not measured it, the gap is larger than anyone assumed before asking.
Where teams commonly run into difficulty
The common failure is treating this as solved once a policy exists, without checking whether the sanctioned route is actually being used in practice, or whether the policy exists mainly to be pointed to after an incident rather than to prevent one. A policy with no measured adoption gap behind it is a document, not a control.
How Bazzi Consulting helps
We treat shadow AI as the third-party and data-flow question it actually is, measuring the adoption gap and designing a sanctioned route people will actually use instead of the unsanctioned one. See making the framework run.