Guide

The Enterprise Guide to Shadow AI: Discovery, Governance, and Control

The Enterprise Guide to Shadow AI: Discovery, Governance, and Control
Shadow AI is the use of AI tools by employees outside sanctioned enterprise channels. Estimates suggest 65% of enterprise AI usage happens through personal accounts, browser-based interfaces, and unsanctioned applications. This guide covers how to discover, assess, and govern shadow AI without blocking the productivity gains that employees are seeking.

The Scale of Shadow AI in 2026

Every enterprise has a shadow AI problem. The question is whether leadership knows about it. Employees across every department are using ChatGPT, Claude, Gemini, Copilot, Perplexity, and dozens of specialized AI tools to write emails, analyze data, generate code, summarize documents, and accelerate their work.

This is not a technology problem. It is an incentive problem. Employees use shadow AI because it makes them dramatically more productive. A financial analyst who can summarize a 200-page filing in 30 seconds is not going to wait for IT to approve an enterprise AI license. The risk is not that employees are using AI. The risk is that they are sharing sensitive data with AI providers that the enterprise has no contractual relationship with.

What Data Is Leaving Your Perimeter

  • Source code: Engineers pasting proprietary code into ChatGPT and Copilot for debugging and generation
  • Customer data: Support teams pasting customer conversations and PII into AI tools for response drafting
  • Financial projections: Finance teams using AI to analyze spreadsheets containing revenue forecasts and board materials
  • Legal documents: Legal teams pasting contracts and privileged communications
  • Healthcare records: Clinicians pasting patient notes (HIPAA violation risk)
  • Strategic plans: Executives using AI for competitive analyses and board presentations

A Three-Phase Approach

Phase 1: Discover

Before you can govern shadow AI, you need to know what exists. The goal of Phase 1 is a complete inventory rather than enforcement, and specifically an observed inventory: which AI tools are actually in use and what data is reaching them, not what teams report when asked. The gap between the declared list and the observed one is usually the finding.

Smartflow Edge counts visits to known AI hosts from the browser. Hostname only — no prompt content reaches that counter, which is what makes it deployable before you have had the conversation about monitoring. It answers how much and where, not what. See AI bill of materials and shadow AI discovery.

Phase 2: Provide Alternatives

Blocking shadow AI without providing a governed alternative guarantees workarounds. The sanctioned path has to be at least as convenient as the unsanctioned one, which means governing the assistants people already use rather than replacing them.

On ChatGPT, Claude and Gemini, Smartflow Edge applies the signed policy at the point of the send: block the send, warn the person, or prepend the policy text to what they are about to submit. A prompt preview of up to 2,000 characters goes to the company proxy with the policy version and whether the send was blocked. Hosts on the block list return a block page. Calls to the model hosts are redirected through the company’s Smartflow instance using the device key, which brings them under the control plane with DLP, audit logging and admin controls attached.

Phase 3: Enforce

With discovery complete and the browser path governed, enforcement happens in Smartflow on the redirected call: block specific data categories from reaching unsanctioned tools, apply policy by directory group, and keep the record of every decision with the policy version that produced it. Shield covers the developer and agent side — local audit, and a human approval ticket that holds a high-severity action until a person approves or denies it. Desktop ChatGPT, outside the browser entirely, is the Shield path rather than the Smartflow Edge path.

One limit worth stating plainly. On an unmanaged laptop the in-page block does not hold. Developer tools, or a browser without the extension, get around it. The durable control today is the redirect through Smartflow combined with force-install on managed devices, and closing the unmanaged gap is open work. A guide that claims otherwise is selling you a control you do not have.

Craig Alberino
Craig Alberino
Craig Alberino is the Founder and CEO of APERION, which builds the runtime governance layer for AI agents in regulated enterprises. Inline policy enforcement and identity-bound audit, deployable on premises.

Put this in the path of your own agents.

Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.

Request a Demo Read the docs