HACKED24, Autonomous Enterprise IT

A ban on AI tools does not stop shadow AI. It hides it.

Banning AI tools does not keep company data out of them. A sanctioned tool, enforced data rules and measured usage give management control over shadow AI.

David Lorenz
Oct 8, 20267 min read
Frosted glass hexagon resting on a white ceramic hexagonal base, with indigo to cyan light glowing through the glass from below, on a light grey background.

Key points

  • Most organisations already block some AI apps, yet sensitive data still reaches AI tools every month.
  • A ban without a sanctioned alternative pushes shadow AI onto personal accounts and devices, where IT has no logs at all.
  • In the Microsoft stack, discovery, blocking and data loss prevention for generative AI apps are available today and can be enforced on managed devices.
  • Management should track actual use of sanctioned and unsanctioned AI, not the number of signed policy acknowledgements.

In 2024, Microsoft and LinkedIn asked 31,000 people in 31 countries how they use AI at work. 75% of knowledge workers said they use it, and 78% of those users bring their own tools (Microsoft Work Trend Index 2024). That is shadow AI: company data in tools the company never approved, never configured and cannot audit.

Many management teams answered with a ban. According to Netskope, 90% of organisations now block at least some generative AI apps, and the average organisation still records 223 generative AI data policy violations per month, roughly twice as many as a year earlier (Netskope Cloud and Threat Report 2026). Our position is simple. A ban without a sanctioned tool and technical enforcement does not stop the data flow. It only removes your view of it.

A ban moves shadow AI out of sight, not out of the company

The work behind the prompt does not disappear with the policy. The sales manager still has to summarise 40 pages of tender documents by Friday. If the corporate browser blocks the AI site, the private phone does not. The text goes in anyway, only now through a personal account on an unmanaged device.

For the CISO this is the worst outcome. The proxy logs show fewer AI hits and management reads silence as compliance. In reality the organisation has traded a risk it could measure for one it cannot.

The Netskope data points in the same direction from the other side. Between 2024 and 2025 the share of generative AI users working with personal accounts fell from 78% to 47%, while use of organisation-managed accounts rose from 25% to 62% (Netskope 2026). The report does not prove cause and effect. It does show that where companies provide a managed account, employees use it.

Shadow AI already has a price in breach statistics

IBM’s Cost of a Data Breach Report 2025 is the first edition that puts a number on unsanctioned AI. Based on 600 breached organisations, 20% reported a breach involving shadow AI. Organisations with high levels of shadow AI paid on average $670,000 more per breach than those with low or no shadow AI, against a global average breach cost of $4.44 million (IBM, July 2025).

The type of data is the bigger concern. In shadow AI incidents, 65% involved personally identifiable information and 40% involved intellectual property, compared with 53% and 33% across all breaches. Customer data and product know-how are exactly what people paste into a chat window.

Governance is mostly missing. 63% of the breached organisations had no AI governance policy or were still writing it. Of those with a policy, only 34% audit regularly for unsanctioned AI. For a CFO this means the risk is now quantified and belongs in the risk register with a figure attached, not in a footnote of the IT strategy.

A sanctioned AI tool is the precondition for every control

Enforcement only holds if the rule is reasonable. When the company offers nothing, every block is a productivity tax and people find the workaround quickly. When the company offers a capable tool under enterprise terms, blocking the rest becomes defensible, to employees and to the works council.

In practice that means a decision for 1 or 2 tools, not a catalogue of 10. The tool needs contractual data terms, sign-in through Microsoft Entra ID and logging in your tenant. Next to it sits a short rule set that says which data classes may go in and which may not.

Conditional access then makes the sanctioned path the controlled path. Require multifactor authentication and a compliant device for the AI app. For unmanaged devices, Conditional Access app control in Defender for Cloud Apps can route browser sessions through session policies that block download or upload of sensitive content (Microsoft Learn). The employee keeps access, the company keeps visibility.

Data rules for shadow AI only count when the platform enforces them

The tooling in the Microsoft stack is further than many organisations realise. Defender for Cloud Apps lists more than a thousand generative AI apps in its catalogue, each assessed against more than 90 risk factors (Microsoft Learn). Filter Cloud Discovery on the category Generative AI and you see which apps your users reach, how often and from which devices.

Discovery becomes enforcement through Defender for Endpoint. Apps tagged as unsanctioned are pushed to devices as network indicators and blocked by network protection, which has to run in block mode. Apps tagged as monitored show a warning with a bypass option instead. Plan for up to 3 hours until a new tag is effective on the endpoint (Microsoft Learn).

Microsoft Purview covers the data itself. Endpoint data loss prevention (DLP) on onboarded Windows devices can warn or block when a user pastes or uploads sensitive information into a third-party AI site in the browser. Data Security Posture Management for AI shows which sensitive information types reach which AI apps, and Insider Risk Management offers a template for risky AI usage (Microsoft Learn). Microsoft also recommends applying these DLP policies in Edge and blocking other browsers, so users cannot reach AI apps through an unprotected browser (Microsoft Learn).

The limit is clear and should be said openly to the board. All of this works on managed devices and managed identities. A private smartphone stays outside. That is why the sanctioned tool carries more weight than the block list.

Measure actual AI use, not policy acknowledgements

A signed AI policy tells you who clicked a button, not where data goes. Management needs numbers from the systems that already see the traffic.

We recommend 3 figures per quarter. First, the share of generative AI activity that goes to sanctioned versus unsanctioned apps, from Cloud Discovery. Second, DLP matches on AI destinations per month and their trend. Third, active users of the sanctioned tool against licences bought. If the third figure is low, find out why before adding more blocks. A tool nobody uses is a budget item, not a control.

This also puts AI agents on the same agenda. Agents that act on company data need the same discipline as users, with identities, permissions and logs. We described the identity side in our article on Entra Agent ID governance.

What to do now

  1. CIO: Run Cloud Discovery filtered on Generative AI for 30 days before you write any new rule. You need a baseline of which apps, which users and which data volumes.
  2. Board: Decide on 1 sanctioned AI tool with enterprise data terms, a budget and a short list of data classes that may and may not be used with it.
  3. CISO: Deploy Endpoint DLP policies for your sensitive information types against generative AI sites, start in audit and warn mode, then move to block. Tag high-risk AI apps as unsanctioned in Defender for Cloud Apps.
  4. IT Operations: Protect the sanctioned tool with conditional access, compliant devices and MFA, and close the browser gap where DLP does not apply.
  5. CFO: Add shadow AI to the risk register, using the IBM cost difference as a reference point, and ask for the 3 usage figures every quarter.

At HACKED24 we start with read access: discovery data, DLP events and sign-in logs show what really happens before anything is blocked. From there we build the sanctioned path and the enforcement in the Microsoft tenant and report usage on your numbers. A good entry point is the Executive IT & AI Review; ongoing governance is part of our AI Agent Operations & Governance service.

Note

As of October 8, 2026. Product names and capabilities follow current Microsoft Learn documentation; some features are in preview and licensing differs by feature. Check the current Microsoft service descriptions before planning a rollout.

David Lorenz

Founder and Managing Partner of HACKED24. More than 20 years in enterprise IT architecture, security and operations.

Want to see what this means for your IT?

Every enquiry is answered personally, usually on the same business day.