Two halves of the same problem
Most organisations treat AI governance as a policy exercise: write a set of rules about which AI tools may be used, get executive sign-off, publish it, and consider the work done. The result is usually a document that describes an imagined environment while the real one operates differently.
The reason is Shadow AI. Employees adopt AI tools independently — browser extensions, free tiers of consumer services, API-based integrations with productivity tools — because they are useful, free, and one click away. Each instance looks small. Cumulatively, they form an exfiltration surface no one owns.
What sanctioned AI governance covers
- Which AI tools are approved, and for what kinds of work
- What categories of data may be sent to those tools
- How prompts and outputs are logged and reviewed
- How AI-generated content is verified before use
- Who is accountable when an AI-produced output causes harm
These are ordinary information governance questions applied to a new class of tool. The mistake is assuming that publishing the answers is sufficient.
Finding Shadow AI
Discovery of unsanctioned AI use is a mixture of technical and cultural work:
- Network telemetry that identifies traffic to consumer AI endpoints
- Browser extension audits, since many risks arrive through third-party extensions
- Reviewing what employees actually use, through anonymous survey rather than only interview
- Making the sanctioned option genuinely better than the unsanctioned one, so people prefer it
The last point matters most. Shadow AI thrives where sanctioned tools are worse than the free consumer alternatives. Policy alone will not close the gap.
POPIA implications
Personal information sent to an unsanctioned AI service is still a processing operation, still requires a lawful basis, and still creates a POPIA obligation if it leaks. The regulator does not distinguish between authorised and unauthorised tools. From an accountability perspective, the organisation is on the hook either way.
Related in the Knowledge Base
- Data Privacy Compliance: POPIA, GDPR, and the Practical Overlap
- Custom AI Agents and Voice Automation: Beyond Chatbots
- What Is POPIA and Who Does It Apply To?
Know what an attacker sees before they do.
A practical exposure checklist covering the gaps that cause most breaches, plus what POPIA actually requires you to have in place.
Free PDF · No spam · Unsubscribe anytime