7 min read

Shadow AI: how to regain control without slowing your teams down

Your teams already use ChatGPT or Claude with personal accounts. How to take back control without imposing a single tool: a 5-step method.

GouvernanceShadow IAAdoption

Shadow AI is shadow IT applied to AI: the use of tools not approved by the company, often with personal accounts. To get it under control, centralize governance (data access, agent catalog, costs, usage rules), then let each team choose the tool suited to its job: Claude Code or Codex for IT, Dust or Copilot for the back office.

In our conversations with CIOs of mid-sized companies since the start of the autumn, the problem keeps coming up. Employees work with ChatGPT or Claude on their personal subscription because the company doesn't provide governed tools. Nobody decided this situation. It set in because tools move faster than company projects.

Why does shadow AI take hold in your teams?

Because the need exists before the framework: when the company doesn't roll out governed licenses, employees use their own. According to a survey by Sapio Research for cybersecurity vendor BlackFog (November 2025, 2,000 employees in the UK and US at companies with more than 500 people), 49% use AI tools not sanctioned by their employer and 51% have connected AI tools to other work apps without IT approval. Executives are not on the sidelines: 69% of presidents and C-level leaders believe speed matters more than privacy or security risks.

The CIO isn't to blame. They are often running an ERP migration that absorbs their team, or they depend on a group whose IT blocks any official initiative. The business teams have a report due tomorrow morning. They take the tool that works.

The result is the same everywhere: usage with no rules on the data uploaded, no identified budget and no measurable return on investment.

Is banning shadow AI enough to solve the problem?

No, unless you offer an equally easy-to-use alternative at the same time. An employee who saves an hour a day with their personal subscription won't give it up because a policy asks them to.

During a pilot at a food-industry manufacturer, an advanced user was testing their prompts with their personal Claude account. That bypassed the company's security. We didn't ask them to stop: we showed them that the same models were available in the approved platform. The need was legitimate, and the official channel met it.

What should be centralized, and what should be left to the teams?

Centralize what binds the company. Leave to the teams what depends on their job.

To centralizeTo leave to the teams
Identity and access (SSO, permissions)The choice of the tool suited to the job
Authorized data sourcesPriority use cases, with a business owner
Agent catalog, owners, lifecycleAgent creation within the approved framework
Validation process before productionThe pace of iteration
Monitoring of consumption and costs
Short usage policy

On tool choice, here is Idoption's position:

  • Developers need tools built for code, such as Claude Code or Codex.
  • Back-office teams (finance, HR, procurement, supply chain, legal) rely more on an agent platform: Dust, Copilot or Claude depending on what's already in place.

Idoption is certified on every platform mentioned here (Dust, Claude, Microsoft Copilot, OpenAI, Google Gemini) and stays vendor-agnostic: our recommendation follows your use cases.

How do you structure governance in practice?

In five steps, in this order.

1. Define an AI policy. A few pages that teams read in a few minutes: authorized uses, prohibited data, approved tools. It starts from real usage, without looking for someone to blame.

2. Inform and consult the works council (CSE) on AI usage and on the introduction of tools, before the deployment decision. In France, introducing a new technology likely to affect working conditions requires consulting the CSE (article L. 2312-8 of the Labour Code).

3. Build a project team with key users, business champions who carry usage in their department and report needs back.

4. Give access to tools within a governed framework (Copilot, Claude, Dust, ChatGPT depending on needs), with a short validation process for creating agents.

5. Then strengthen security: data access rights, traceability, rules for sensitive data.

This order matters: without a policy, the CSE and the teams have nothing to build on, and without approved tools made available, employees keep using their personal accounts.

Two field situations show why these steps matter. During a pilot, an agent sent an unsolicited email to a customer. Since then the rule is simple: no write access to the ERP or CRM without prior approval. In another deployment, employees created several hundred agents within a few weeks. Rules for sharing, editing and validation had to be put in place. Governance becomes urgent when adoption works: better to anticipate it.

Why isn't governance alone enough?

Because a framework nobody uses protects nothing. Teams also need support.

We rely on business champions, trained to carry usage in their department, and on office hours where users come to get their questions unblocked. Training happens in stages: during one pilot, an advanced training turned out to be too dense because it covered APIs before users had mastered the basics. It was replaced by a hands-on workshop after a few weeks of usage.

At one of our consulting clients, this work delivered 90% adoption in 29 days and 4 agents in production in 4 weeks.

How do you measure that governance is working?

Five indicators are enough to start:

  • adoption rate, month over month;
  • time to validate a new agent;
  • share of agents that comply with the framework;
  • cost of use per user;
  • incidents and deployment blockers avoided.

When is this approach not a good fit?

It doesn't always fit.

  • A small organization of a few dozen people with a single tool doesn't need a validation process: a one-page policy and a team subscription are enough.
  • Data subject to strong sovereignty requirements (regulated sectors, public-sector clients) means choosing hosting and models before ergonomics, sometimes with dedicated infrastructure.
  • Poorly structured data can't be fixed by governance. When business definitions are ambiguous or files are incomplete, an agent won't work, even well supervised. That data work comes first.

What does European regulation say?

Article 4 of the EU AI Act requires providers and professional deployers of AI systems to take measures to develop AI literacy among their staff and the people using these systems on their behalf. It has applied since 2 February 2025. Regulation (EU) 2026/1744, known as the "Digital Omnibus", published in the Official Journal on 24 July 2026 and in force since 27 July 2026, reworded it: the obligation now concerns the means put in place, without requiring a specific level of competence to be guaranteed.

The AI Act does not, in itself, require consulting the CSE. For high-risk AI systems used at work, it requires informing workers' representatives before the system is put into service (Article 26, paragraph 7). Consulting the CSE on a tool deployed within a company falls under the French Labour Code.

A clear policy, trained teams and traced usage serve governance and compliance at the same time.

Frequently asked questions

What is shadow AI? It is the use of generative AI tools (ChatGPT, Claude, etc.) by employees without company approval, often with personal accounts, which exposes company data. A tool provided by the company, such as Copilot, is not shadow AI.

Should the whole company standardize on a single AI tool? No. You need a common governance foundation and tools suited to each job: a developer and a finance team don't have the same needs.

Where to start? With an AI policy, then informing and consulting the CSE, a project team with key users and access to tools within a governed framework. Stronger security comes next.

Which indicators should you track? Adoption rate, agent validation time, share of compliant agents, cost per user and incidents avoided.

Your teams already use AI without a common framework? Start a diagnostic to set up your policy, put governed tools in place and prioritize the use cases with the strongest return on investment.

Read also: our deployment method · customer cases and measured results

Pick the one that fits.

Your first agent in production.

We start from your real situation, not a generic template. Free diagnostic, 45 min, concrete results on your context.

Book my diagnostic45 min, on your context. No generic pitch.

Free, 45 min, no commitment, on your real data