Home / Resources / Risk

Risk · 7 min read · Updated 2026-07-06

Shadow AI: your biggest leak is a paste-⁠box

Why employees pasting contracts into public chatbots is a legal exposure, not an IT nuisance — and why bans fail where better tools succeed.

The largest uncontrolled data channel in most enterprises today is not email or USB drives. It is the input field of a public chatbot, used daily by employees who are trying to do good work faster.

The pattern

The mechanics are mundane, which is exactly why they are dangerous. A lawyer pastes a draft settlement agreement into a public assistant to tighten the language. An analyst pastes a customer list to "summarise the top accounts". An engineer pastes proprietary source code to debug it. Each act takes seconds, leaves no trace in your DLP tooling, and transmits regulated or privileged material to third-party infrastructure under terms of service nobody in the room has read. Surveys consistently find a large share of knowledge workers using unsanctioned AI tools for work tasks; your organisation is not the exception, because the incentive — the tools genuinely help — applies to your people too.

The legal exposure is real

Three exposures deserve board-level attention. First, privilege: disclosing legally privileged material to a third party can risk waiving that privilege — and a chatbot operator is a third party. A contract pasted into a public model may surface in litigation discovery arguments you would rather not have. Second, GDPR: pasting personal data into an external service is a processing operation and a transfer, typically with no lawful basis assessed, no processor agreement, and no entry in your Article 30 records. If the recipient uses inputs for model training, honouring an Article 17 erasure request may be practically impossible. Third, contractual confidentiality: most commercial NDAs do not contemplate "we sent your pricing schedule to a consumer AI service", and counterparties are beginning to ask.

Why bans fail

The instinctive response — block the domains, publish a policy — has a decade of failed precedent in shadow IT. Employees route around blocks with personal devices precisely because the productivity gain is real. Prohibition without alternative converts a visible risk into an invisible one: usage continues, but now outside your network telemetry entirely. A policy you cannot observe being broken is not a control.

The countermeasure pattern

The organisations that have actually reduced shadow AI share one move: they made the sanctioned tool the better tool. The pattern has four parts:

  • Capability parity or better, inside the perimeter. An on-prem assistant with private RAG over internal documents answers questions the public chatbot cannot — the incentive now points inward.
  • Guardrails at the point of use. PII and secret detection on prompts and outputs, applied automatically, so the safe path requires no vigilance from the user.
  • Audit by default. Every interaction logged to an append-only ledger — converting AI use from an invisible risk into reviewable evidence, which is what your regulator and your litigators both want.
  • Human approval on consequential actions. When the assistant graduates from answering to acting, a person signs off — and the sign-off is recorded.

Measure success by migration, not enforcement: sanctioned-tool adoption rising while egress to public AI endpoints falls. The paste-box does not get less convenient — so the answer must be more convenient, and inside your walls.

See the sanctioned-tool pattern running →

Related guides

Procurement

The sovereign AI buyer's checklist

Twelve concrete questions that separate verifiable sovereignty from a configuration checkbox — ask them of every vendor, including us.

8 min read

Read the guide

Economics

Token economics: why your AI bill scales with sloppy context

How RAG and agent context quietly inflate token spend, what compression can and cannot safely remove, and what a 48–79% measured reduction means for a real workload.

8 min read

Read the guide

Compliance

The EU AI Act Article 12 readiness guide

What record-keeping and human-oversight obligations actually require operationally from August 2026 — and the evidence an auditor will ask you to produce.

9 min read

Read the guide
COMING SOONAANCER launches shortly.Register for prelaunch events & demos →