Skip to main content
ShadowAI Defense GitHub
← All runbooks
RB-003 High

Mass adoption of unsanctioned AI tool (> 50 users)

DET-MS-SEN-003 (or platform equivalent) fires for an unsanctioned AI service exceeding the program's user-count threshold. Also triggered by DET-MS-MCAS-001 / -MANUAL-001 surfacing a new viral app.

Triggers

Immediate response (first hours)

  1. AI Governance triage: Confirm the detection. Pull user / department breakdown. Identify what business need the tool is serving (often a productivity workflow not yet covered by sanctioned tools).
  2. AI Governance lead: Convene rapid-review with Security and the affected business unit(s). Goal: decide within 5 business days whether to: (a) fast-track sanction, (b) block with comms, (c) interim pilot, or (d) parallel sanctioned alternative.

Short-term response (within days)

  1. AI Governance triage: Execute the decision: update sanction status in Defender for Cloud Apps / SWG; update inventory in Governance Toolkit; issue org-wide comms (comms/department-level-briefing). (Within 10 business days)
  2. Procurement + Legal: If sanctioning: initiate vendor due diligence using the Vendor Questionnaire (AI Governance Toolkit). Capture risk-tier decision before contract finalization. (Within 30 days)
  3. AI Governance triage: Stand up an approved-tool pilot for the underlying need (if no sanctioned alternative exists). Migrate users from unsanctioned to sanctioned path.

Long-term response (weeks+)

  1. AI Governance Committee: Post-mortem: how did this become viral without earlier detection? Adjust monitoring thresholds / sanctioning cadence accordingly.
  2. AI Governance triage (quarterly): Track migration completion. Goal: < 10% of original user base still on unsanctioned tool 90 days post-decision.

Decision tree

  • Does the tool serve a genuine business need not currently covered?
    • Yes → Fast-track sanction or stand up approved alternative.
    • No → Block with comms; redirect to existing sanctioned tools.
  • Is there an enterprise-tier offering with acceptable data terms?
    • Yes → Sanction the enterprise tier; communicate migration path.
    • No → Block consumer use; consider whether to pursue a custom contract or alternative vendor.

RACI

  • Responsible: AI Governance triage lead
  • Accountable: AI Governance lead
  • Consulted: Affected business unit head, Procurement, Legal, Security architecture
  • Informed: AI Governance Committee, CISO

Metrics to capture

  • Time from detection to decision (target: ≤ 5 business days)
  • Time from decision to action (target: ≤ 10 business days)
  • User migration rate at 30 / 60 / 90 days
  • Number of fast-tracked sanctions per quarter (trend signal — high rate may indicate program-level coverage gaps)

Comms templates

  • comms-department-level-briefing
  • comms-approved-tool-announcement
  • comms-mass-adoption-program-update

Framework mappings

  • NIST AI RMF: GOVERN-4.1, MANAGE-2.2, MANAGE-4.1
  • ISO/IEC 42001: 8.2, 8.4, 10.2
  • NIST CSF: DE.AE-2, RS.AN-1

Related AI Controls Catalog entries