Digital Transformation & Artificial Intelligence

Managing Shadow AI and Unsanctioned Use of Generative AI Tools

Learn to discover unsanctioned AI tool use across the organisation, assess the exposure it creates, and replace prohibition with governed, usable alternatives.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

Staff started using generative AI tools long before most organisations had a policy for them, and blocking every consumer chatbot at the firewall only pushes the activity onto personal devices where nothing is visible at all. This course treats shadow AI as a discovery and design problem rather than a purely disciplinary one: participants learn how to find out what tools are actually in use, why staff reach for them, and what data has already left the organisation's control as a result. From there the course builds a practical governance response, covering acceptable use policy drafting, data classification rules that staff can apply without training in data protection law, and technical controls such as network monitoring, browser extension visibility and data loss prevention rules tuned for AI traffic. A central theme is that prohibition without a usable alternative simply drives shadow use further underground, so the course dedicates significant time to selecting and rolling out sanctioned tools that meet the same needs staff were solving with unsanctioned ones. Participants finish with a discovery plan, a draft acceptable use policy and a rollout plan for a sanctioned alternative.

Expected Learning Outcomes

01

Run a discovery exercise to identify which generative AI tools are already in use across departments.

02

Interview staff to understand which tasks are driving them toward unsanctioned AI tools.

03

Assess the data protection and confidentiality exposure created by identified shadow AI use.

04

Draft an acceptable use policy with data classification rules staff can apply without specialist training.

05

Configure technical controls such as browser visibility and data loss prevention tuned for AI traffic.

06

Select and pilot a sanctioned AI tool that replaces the primary unsanctioned use case identified.

07

Design an amnesty and communication plan that shifts staff from unsanctioned to sanctioned tools without punishment.

Who Should Attend

01

Information security teams responsible for data loss prevention

02

IT leaders deciding which AI tools to sanction and roll out

03

Compliance officers drafting acceptable use and data policies

04

Risk managers assessing exposure created by unmanaged AI use

05

HR and legal teams handling policy and disciplinary implications

06

Digital transformation leads selecting enterprise AI tooling

Course Modules

Select any module to see its sessions and points.

01

Discovering Shadow AI Use

2 sessions · 8 points

Session 1Finding Out What Is Already in Use

  • Review network and proxy logs for traffic to known consumer generative AI domains and applications.
  • Audit browser extensions installed on managed devices for embedded AI assistants and writing tools.
  • Run an anonymous staff survey asking directly which AI tools they use and for which tasks.
  • Cross-check expense claims and departmental software requests for AI subscriptions bought outside IT.

Session 2Understanding Why Staff Use Unsanctioned Tools

  • Interview frequent users to identify the specific task the unsanctioned tool solves faster than approved options.
  • Distinguish genuine capability gaps in sanctioned tools from simple unfamiliarity with what already exists.
  • Map unsanctioned use against team and function to identify where exposure is concentrated.
  • Document use cases in enough detail to inform which sanctioned tool could realistically replace them.
02

Assessing the Exposure

2 sessions · 8 points

Session 1Data and Confidentiality Risk Assessment

  • Classify the type of data likely pasted into unsanctioned tools based on the tasks identified in discovery.
  • Assess whether any identified use has already breached confidentiality, client or regulatory obligations.
  • Evaluate the data retention and training-use terms of the specific unsanctioned tools found in use.
  • Prioritise remediation by the severity of data exposure rather than by the volume of tool usage alone.

Session 2Compliance and Contractual Implications

  • Check client and supplier contracts for clauses restricting the use of third-party AI processing on their data.
  • Assess intellectual property risk where staff have used AI tools to draft client-facing or patentable material.
  • Determine what must be disclosed to regulators or clients if a genuine data exposure incident is confirmed.
  • Brief legal and compliance teams before publishing findings so the response is coordinated, not reactive.
03

Building the Policy and Control Response

2 sessions · 8 points

Session 1Drafting an Acceptable Use Policy

  • Write a data classification guide that tells staff, in plain terms, what may never be pasted into an AI tool.
  • Set out approval routes for teams that need an AI tool the current sanctioned list does not cover.
  • Define consequences for policy breaches proportionate to intent and the sensitivity of data involved.
  • Circulate the draft policy to representative staff for feedback before it is finalised and published.

Session 2Technical Controls for AI Traffic

  • Configure data loss prevention rules tuned to detect sensitive data patterns in AI-bound web traffic.
  • Deploy browser management tools that can allow, warn or block specific AI domains by user group.
  • Set up alerting for large or unusual volumes of data submitted to external AI endpoints.
  • Review and adjust control thresholds regularly to avoid blocking legitimate sanctioned tool use.
04

Moving Staff to Sanctioned Alternatives

2 sessions · 8 points

Session 1Selecting and Piloting a Sanctioned Tool

  • Shortlist enterprise AI tools against the specific tasks identified during the discovery interviews.
  • Confirm contractual guarantees on data handling, retention and training-use before shortlisting a vendor.
  • Pilot the chosen tool with the heaviest unsanctioned users first so adoption feedback is realistic.
  • Adjust the rollout scope based on pilot feedback before committing to an organisation-wide licence.

Session 2Communication, Amnesty and Adoption

  • Announce a limited amnesty period so staff can disclose unsanctioned use without automatic disciplinary action.
  • Communicate the new sanctioned tool as a replacement for a named pain point, not as a restriction.
  • Train champions in each department to support colleagues switching from unsanctioned to sanctioned tools.
  • Track adoption and repeat the discovery exercise periodically to confirm shadow use has genuinely reduced.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course