Policy
Shadow AI / Acceptable Use of External AI Services
A drafted policy you can adapt. CC-BY 4.0 — retain attribution to this repo.
1. Scope and definitions
This policy applies to all employees, contractors, and other authorized users accessing the Company's information assets. "External AI Service" means any third-party generative AI, AI-augmented productivity, or AI-augmented code-assistance service accessed from a managed device, managed identity, or with the Company's data.
2. Sanctioned tools
The Company maintains a list of sanctioned AI tools (see the AI Inventory). Use of any non-sanctioned External AI Service for Company business is prohibited unless covered by Section 6 (Exception process).
3. Prohibited data categories
- Customer Personal Information of any category;
- Regulated data (PCI, PHI, banking secrecy data, national-security-relevant material);
- Source code containing secrets, proprietary algorithms with material trade-secret value, or customer-implementing logic;
- Internal documents marked Confidential or Restricted;
- Information subject to attorney-client privilege or litigation hold;
- Information whose disclosure would breach a third-party confidentiality obligation.
4. Approved-use process
Where a sanctioned tool exists, it is the default. Where one does not exist, route the need via the AI Use-Case Intake (AI Governance Toolkit /inventory). The AI Governance lead, in consultation with Security, Privacy, and the business sponsor, determines suitability and sanctioning path.
5. Monitoring disclosure
The Company monitors network and endpoint activity for compliance with this policy. Monitoring includes detection of External AI Service usage and the categories of data conveyed to such services. Monitoring is conducted in accordance with applicable privacy law and the Company's Employee Privacy Notice.
6. Exception / risk-acceptance process
Where a legitimate business need cannot be served by a sanctioned tool, an exception may be requested using the Exception Request form. Exceptions are time-bound, conditioned on compensating controls, and approved at the level appropriate to data sensitivity and tool risk tier.
7. Browser extensions and OAuth grants
Installation of AI browser extensions and granting of OAuth access to AI applications require advance approval per the Browser Extension and OAuth Governance Standard. The Company maintains technical controls to enforce extension and OAuth approval.
8. Disciplinary framework
Violations of this policy may result in disciplinary action up to and including termination, consistent with Company policy and applicable law. The Company's first-occurrence response emphasizes education and approved-tool migration; repeated or wilful violation will be escalated.
9. Review cadence
This policy is reviewed at least annually by the AI Governance lead and approved by the AI Governance Committee. Substantive changes are communicated to all employees.
Drafted by Emmanuel Guilherme Jr. for Shadow-AI-Defense. Licensed CC-BY 4.0. Adapt to your organization; retain attribution.