By Mark Allford, Acting CTO, ARO

I went for a bike ride this morning with a few friends. All of them run their own businesses. At some point the conversation moved onto how they manage the day-to-day, and every single one of them brought up ChatGPT. Not a paid enterprise subscription with data protection agreements and admin controls. The free version, on their phones, being used to draft emails, summarise documents and work through business problems. They were feeding real business information into it without a second thought about where that data goes, who can access it, or how it might be used. 

That is Shadow AI. And if it is happening in a casual conversation between small business owners on a Wednesday morning, it is happening inside your organisation right now. 

We Have Been Here Before 

Cast your mind back to the early 2010s. Cloud storage was new, consumer tools were fast and free, and employees started using Dropbox, personal Gmail and Google Drive to do their jobs more effectively. IT teams responded with blocking rules. The business responded by finding workarounds. CIOs eventually realised that the instinct to restrict was losing to the human instinct to be productive, and the industry shifted toward governance and enablement rather than prohibition. 

Shadow AI is the same dynamic playing out again, but at a faster pace and with significantly higher consequences. 

When someone stored a file in an unauthorised Dropbox, the risk was largely around data portability and compliance. Serious, but manageable. When someone feeds a client proposal, a set of financial projections or a draft HR document into a free AI tool, that data is not just stored externally. It is being actively processed by a system with its own data retention policies, training data considerations, and security posture that the organisation has not reviewed and did not agree to.  

The free consumer tier of most AI platforms carries no enterprise-grade data protection guarantees. Under GDPR and sector-specific frameworks, the regulatory exposure can be immediate and significant, and in many cases the person doing it has no idea. 

The Scale of the Problem 

The challenge with Shadow AI is that it is largely invisible through traditional security lenses. A user accessing an unsanctioned AI tool through a browser looks identical to any other internet traffic unless you are specifically looking for it. Most organisations are not. 

Microsoft’s announcements at RSAC 2026 address this directly. Entra Internet Access Shadow AI Detection became generally available on the 31st March 2026. It identifies previously unknown AI applications at the network layer, surfaces unsanctioned usage patterns, and allows organisations to enforce Conditional Access policies to permit or block specific AI applications. Combined with Microsoft Defender for Cloud Apps, it gives security and IT teams visibility into which AI tools are being accessed, by whom, how frequently, and how much data is being transferred. That is a meaningful capability that simply did not exist at this level of maturity twelve months ago. 

For organisations invested in the Microsoft security stack, this is a natural extension of controls they already have in place. It integrates with existing Conditional Access policies, works alongside Entra ID governance, and surfaces risk data in the Security Dashboard for AI that gives CISOs a consolidated view of AI-related exposure across the estate. 

The Honest Limitation 

I want to be direct about something, because I think it matters. These tools are valuable. They are also not the complete answer. 

Entra Internet Access and Defender for Cloud Apps operate at the network layer on managed devices. They will govern what happens on a corporate laptop, connected to a managed network, using a browser that the organisation controls. What they will not see is the employee using their personal phone on mobile data during their lunch break. They will not see the free ChatGPT session happening on a home computer in the evening. They will not see the contractor using their own device who is not enrolled in your MDM. 

This is not a criticism of the tooling. It is simply the reality of the modern work environment, and it means that any organisation that believes deploying these controls has solved the Shadow AI problem is mistaken. The unmanaged surface area requires a different response: clear policy, genuine user education, and a culture where people understand the risks and are motivated to work within the boundaries rather than around them. 

What CIOs Should Actually Do 

I have a clear position on the sequencing here, and it differs from how many organisations will approach this. 

The temptation is to turn on the governance tooling first and define the policy later. That is the wrong order. Without a clear acceptable use policy, the tooling generates data but cannot generate meaningful governance. It cannot distinguish between sanctioned and unsanctioned use until someone has defined what sanctioned looks like. Deploying Entra Internet Access without that policy foundation produces dashboards and alerts, but not security. 

The right starting point is an honest assessment. What AI tools are your people already using? What are they using them for? What categories of data are they feeding in? That assessment will be uncomfortable for some organisations. It will surface use cases that should have been governed earlier. Do it anyway, because the alternative is continuing to operate blind. 

From that foundation, define your acceptable use policy. What is approved? What is conditionally approved with restrictions? What is prohibited outright? What data classifications should never enter any AI tool under any circumstances? Then deploy the tooling to enforce and monitor against that policy. 

Finally, and this is the part that gets skipped most often, invest in user education. People are not using Shadow AI with malicious intent. They are using it because it makes them more effective and nobody has explained the risk or provided a better option. Education without a sanctioned alternative is just creating friction. Give people an approved path and most of them will take it. 

My View 

Shadow AI reflects something that is fundamentally positive as much as it represents a risk. People are curious. They are experimenting. They are finding ways to do their jobs better and they are not waiting for IT to give them permission. That energy is an asset, not a threat. 

The organisations that will handle this well are not the ones that build the most comprehensive blocking rules or the most exhaustive policy documents. They are the ones that move quickly to understand what their people are already doing, engage with those use cases honestly, build governance around enabling the productive ones safely, and create a culture where responsible AI use is the norm rather than the exception. 

The Microsoft tooling that came out of RSAC 2026 gives organisations a serious foundation to work from. But tooling is not strategy. If your organisation does not have an AI use policy, an honest assessment of current AI usage across the estate, and a governance framework that acknowledges both the managed and unmanaged environments your people work in, those are the gaps that need addressing before anything else. 

Shadow AI is not a future challenge to put on the roadmap. It is a present reality that is growing every week. The question is not whether to address it. The question is whether you get ahead of it or respond to it after something goes wrong. 

What does your current AI governance posture look like, and where are the gaps you have not yet addressed? 

Mark Allford is Acting CTO at ARO, a UK technology services provider delivering enterprise solutions across networking, security, unified communications, cloud and AI.