Shadow AI & Governance

How to Govern Employee ChatGPT Use and Shadow AI

You can't govern employee ChatGPT use by banning it. Govern it the way a good manager governs a new hire: earned autonomy, checked at every stage.

At a glance
  1. 0178% of AI users at work bring their own unsanctioned tools, bypassing IT approval entirely.
  2. 02Corporate data pasted into AI tools grew 485% in one year, with sensitive data shares rising.
  3. 03Organizations with high shadow AI usage pay an average of $670,000 more per data breach.
  4. 04Blanket bans push AI usage underground into personal accounts with zero enterprise visibility.
  5. 05Effective governance uses a tiered trust model, granting AI tools more autonomy as they prove safe.
A spatial diagram of an AI gateway pipeline where unlabelled data tokens flow through segmented filtering rings toward a central processing node.
Illustration generated by Remy for this story.

You govern employee ChatGPT usage and shadow AI by replacing blanket bans with a tiered trust model that grants AI tools more autonomy as they prove themselves, backed by inventory, monitoring, and clear approval gates. Prohibition doesn't work because employees have already voted with their browser tabs. The only real question left is whether IT finds out before or after something breaks.

Employees Are Already Governing Themselves, Just Not the Way IT Wants

There's a strange split in how people work right now. On one side, there's a real cultural pull toward friction: choosing the paper map, the manual grind, the effortful version of a task, on purpose. 'Friction-maxxing' is the term for it, the deliberate choice of less convenient options to preserve tolerance for discomfort and resist technology-driven ease.1 On the other side, the same people are quietly offloading the parts of their job they don't want anyone watching them struggle with into a custom GPT they built themselves.

This isn't hypocrisy. It's triage. People keep friction where it feels meaningful and strip it out where it doesn't, and they're not asking IT for permission either way. Over half of employees say they wouldn't tell their manager that AI helped them finish a task.2 That's not a compliance gap. It's a signal that the tools are already embedded in how work gets done, invisibly, and governance has to catch up to that reality rather than pretend it can legislate it away.

Figure 1
Shadow AI is already the default
78%
AI users bringing their own AI tools outside IT approval
73.8%
Workplace ChatGPT accounts that are personal, non-corporate accounts
$670,000
Higher average breach cost at high-shadow-AI organizations
Source: Airia

What Is Shadow AI, and How Big Is It Really?

Shadow AI is any AI tool, model, or agent an employee uses for work without IT's knowledge or approval: personal ChatGPT accounts, browser extensions, self-built GPTs, automation agents wired into company data. None of it vetted. None of it logged anywhere security can see.

The scale is not a rounding error. Seventy-eight percent of AI users at work bring their own AI tools outside IT approval, climbing to 80% at small and mid-sized companies.32 Seventy-five percent of global knowledge workers now use generative AI at work, and usage nearly doubled in the six months before Microsoft's 2024 report.3 Most of that activity isn't happening on enterprise-controlled accounts: 73.8% of workplace ChatGPT accounts are personal, non-corporate accounts with none of the enterprise security or privacy controls IT thinks it has bought.4 For Gemini and Bard, the figures are even higher: 94.4% and 95.9% respectively.4

Figure 2
Whose ChatGPT account is it, really?
74%Personal, non-corporate accounts
Personal, non-corporate accounts74%
Corporate/enterprise accounts26%
Source: Cyberhaven

The data flowing into these tools is getting heavier and riskier. Corporate data pasted into AI tools grew 485% between March 2023 and March 2024, and the share of that data classified as sensitive rose from 10.7% to 27.4% in the same window.4 Source code alone makes up about 12.7% of sensitive data going into AI tools, and roughly half of that source code lands in shadow accounts rather than sanctioned ones.4 For a deeper look at what employees are actually assembling with these tools, see The Shadow AI Tech Stack.

The Custom GPT Problem: When Employees Become Citizen Developers

Custom GPTs and GPT Store agents dropped the bar for building software to nearly zero. An employee with no engineering background can wire a GPT to a spreadsheet, a CRM export, or an internal knowledge base in an afternoon, and it works well enough to become part of someone's actual workflow.

That's the problem. The person who built it isn't a vendor, doesn't run a security review, and probably never considered what happens if the data it touches gets logged somewhere outside company control. Varonis has flagged this directly: custom GPTs and AI agents compound productivity, but they also compound risk, and enterprise-grade deployments need active monitoring of prompts and responses to catch sensitive data before it leaves the building.5 Security teams have started calling this exactly what it is: a new wave of citizen developers extending the shadow IT problem into the AI era, the same dynamic that once made unsanctioned spreadsheets and low-code apps a headache, except now it moves faster and touches more data.6

Figure 3
Corporate data flowing into AI tools is getting riskier
share of corporate data classified as sensitive (%)
10.7%March 202327.4%March 2024
Period
Total volume of corporate data pasted into AI tools also grew 485% over this same window.
Source: Cyberhaven

Why Doesn't Banning Shadow AI Work?

Bans push usage underground rather than eliminating it. Employees who feel judged for needing AI help simply stop disclosing it, and the accounts they use instead are personal ones the company has zero visibility into.24 A policy that can't see what it's trying to stop isn't a policy. It's a liability with a memo attached.

The cost of pretending the problem doesn't exist is measurable. Sixty-three percent of breached organizations in IBM's 2025 study had no AI governance policy at all, and only 37% had any approval process or oversight mechanism in place.7 Ninety-seven percent of organizations that suffered an AI-related breach had lacked proper AI access controls.8 Banning tools without building the infrastructure to know what's actually running doesn't close the gap. It just makes the eventual discovery more expensive.

What Does Ungoverned AI Actually Cost?

The numbers here are blunt. Organizations with high levels of shadow AI paid $670,000 more on average per breach than organizations with low or no shadow AI.78 Twenty percent of organizations studied had already suffered a breach tied to shadow AI.7 Varonis's analysis of nearly 10 billion files across 1,000 real environments found 99% of organizations have sensitive data exposed to AI tools, and 98% have unverified or unsanctioned apps, shadow AI among them.9 This isn't an edge case anyone can plan around. It's close to universal.

Figure 4
Governance gaps show up in the breach data
63%
Breached organizations with no AI governance policy at all
37%
Breached organizations with any approval or oversight process
97%
AI breach victims that lacked proper AI access controls
Source: IBM Think

Agentic Trust Controls: A Framework for Earned Autonomy

The fix that's actually gaining traction isn't a firewall around AI. It's a maturity model, the same logic a manager applies to a new hire. You don't hand a first-week employee the keys to production. You watch them work, check their output, and expand what they can touch as they earn it.

Figure 5
Sensitive data and unsanctioned apps are nearly universal
Orgs with sensitive data exposed to AI50%
Orgs with unverified/unsanctioned apps50%
Based on Varonis's analysis of nearly 10 billion files across 1,000 real-world environments.
Source: Varonis

The Agentic Trust Framework, an open Zero Trust specification for AI agents, formalizes exactly this with four maturity levels: Intern, Junior, Senior, and Principal.10 An agent moves up that ladder based on demonstrated performance, security validation, business value, an incident-free record, and explicit governance sign-off.10 Vanta has taken a parallel, more granular approach, open-sourcing 61 Agentic Trust Controls across 12 domains covering identity and authority, tool use, memory integrity, and runtime monitoring, split into 40 developer-facing controls and 21 deployer-facing ones.11 Neither framework asks IT to say yes or no once. Both ask IT to keep re-evaluating trust as the agent's track record grows.

The Five Questions IT Must Answer for Every AI Tool or Agent

ATF boils governance down to five questions that apply just as well to a custom GPT an employee built last week as to a fully autonomous agent:10

  1. Identity. Who are you? Every tool and agent needs a verifiable identity, not an anonymous personal account nobody can trace back to a person or team.
  2. Behavior. What are you doing? Log the actions the tool takes, not just the prompts. Behavior drift is the earliest signal something has gone wrong.
  3. Data governance. What are you eating, and what are you serving? Know what data goes in and what comes out, especially for tools touching source code or customer data, where roughly half of leaked source code already flows to non-corporate accounts.4
  4. Segmentation. Where can you go? Limit blast radius. A tool built for one workflow should not have standing access to everything else in the company.
  5. Incident response. What if you go rogue? Have a kill switch and a rollback plan before you need one, not after.
Figure 6
Vanta's Agentic Trust Controls, by audience
Developer-facing controls40Deployer-facing controls21
61 controls total across 12 domains.

These questions also map cleanly onto the coding-assistant risks covered in The Security Threat of Agentic Code, where the same lack of behavioral logging and segmentation shows up in a different tool category.

How Do You Roll Out Governance Without Killing Adoption?

Most organizations get further with a rollout than with a decree. A workable sequence looks like this:

Figure 7
Governance postures compared
Governance postures compared
Visibility into usageImpact on adoptionSetup effortBreach cost exposureScales to autonomous agents
Blanket banOrganizations optimizing for a paper trail, not for realityLowHighLowHighNo
No policy / status quoNobody — included as the baseline most breached orgs actually hadLowLowLowHighNo
RecommendedTiered trust model (amnesty, inventory, monitoring, earned autonomy)Organizations that want adoption and control at the same timeHighLowHighLowYes
Ratings are relative across these options, not absolute. Grounded in the article's discussion of bans, ungoverned use, and the Agentic Trust Framework/Vanta approach.
Source: Remy analysis
  1. Run an amnesty period. Ask employees to disclose the AI tools and custom GPTs they're already using, with no penalty for admitting it. You cannot govern what you cannot see.
  2. Inventory and tier what you find. Sort tools by data sensitivity and blast radius, not by novelty. A GPT that summarizes public marketing copy is not the same risk as one wired into customer records.
  3. Set tiered approval gates. Low-risk tools get lightweight sign-off. Anything touching sensitive data or production systems starts at Intern-level trust and earns more.10
  4. Deploy monitoring, not just policy. Prompt and response monitoring on sanctioned platforms catches leakage before it becomes a breach, the way Varonis describes for enterprise ChatGPT deployments.5
  5. Offer sanctioned alternatives that don't add friction. If the approved tool is slower or clunkier than the personal account employees already trust, they will keep using the personal account. This is where owning infrastructure instead of stitching together sanctioned SaaS can matter: platforms like Remy are built around exactly this problem, giving teams a governed way to run and own the AI agents they'd otherwise build in the shadows.
  6. Train, then re-audit. Trust levels aren't permanent. Revisit them the way ATF intends, on a track record, not a one-time review.10

This amnesty-then-tiering approach is covered in more detail in 5 Ways to Secure Database Access for Internal AI Agents, applied one layer up, to the tools employees build rather than just the systems those tools touch.

Governing Without Killing the Productivity Gains

The friction-maxxing instinct is actually a useful model here, not a contradiction to solve. Employees already know how to decide where effort matters and where it doesn't. Good governance does the same thing at the system level: add real friction, approval gates, monitoring, tiered trust, exactly where autonomy is being requested, and get out of the way everywhere else. The goal was never a frictionless AI rollout. It was never a frozen one either. It's putting the friction where the risk actually lives, and trusting the rest to earn its way up.

Frequently asked
Questions readers ask
How do you govern employee ChatGPT usage without banning it?

Replace bans with a tiered trust model. Run an amnesty period to inventory what's already in use, tier tools by data sensitivity and blast radius, and expand each tool's permissions as it proves itself, similar to the Agentic Trust Framework's Intern-to-Principal maturity levels.

What is shadow AI and how common is it in the workplace?

Shadow AI is any AI tool or agent employees use for work without IT's knowledge or approval, including personal ChatGPT accounts and self-built custom GPTs. It's extremely common: 78% of AI users at work bring their own AI tools outside IT approval, and 73.8% of workplace ChatGPT accounts are personal, non-corporate accounts.

Why do bans on shadow AI tools fail?

Bans push usage underground instead of eliminating it. Employees switch to personal accounts IT can't see, and over half say they wouldn't even tell their manager AI helped with a task. A policy that can't see what it's banning isn't actually governing anything.

How much does shadow AI actually cost a company?

Organizations with high levels of shadow AI paid $670,000 more per breach on average than those with low or no shadow AI, and 20% of organizations studied had already suffered a breach tied to shadow AI, per IBM's 2025 Cost of a Data Breach Report.

What is the Agentic Trust Framework?

It's an open Zero Trust-based governance model for AI agents that grants autonomy in earned stages across four maturity levels: Intern, Junior, Senior, and Principal. Agents move up based on demonstrated performance, security validation, and an incident-free track record, rather than getting blanket access on day one.

Sources
  1. 1Friction-maxxing (Wikipedia entry, via r/wikipedia discussion)Wikipedia / Reddit
  2. 2Shadow AI Statistics: Key Data Points Every CISO Needs in 2026Airia
  3. 3AI at Work Is Here. Now Comes the Hard Part (2024 Work Trend Index)Microsoft WorkLab
  4. 4Shadow AI: how employees are leading the charge in AI adoption and putting company data at riskCyberhaven
  5. 5Creating Custom GPTs and Agents That Balance Security and ProductivityVaronis
  6. 6How to manage the growing influence of 'Citizen Developers'SC World
  7. 7What data leaders need to know from the Cost of a Data Breach Report 2025IBM Think
  8. 8IBM Report: 13% of Organizations Reported Breaches of AI Models or Applications, 97% of Which Reported Lacking Proper AI Access ControlsIBM Newsroom
  9. 9Data Security Report Reveals 99% of Orgs Have Sensitive Information Exposed to AIVaronis
  10. 10The Agentic Trust Framework: Zero Trust Governance for AI AgentsCloud Security Alliance
  11. 11Agentic Trust Controls: 61 AI Governance Standards for Security and Privacy TeamsLinkedIn (Vanta / Christina Cacioppo)
Portrait of Priya Nair
Priya Nair
AI Tooling
Priya covers the daily churn of AI agents, coding tools, and what actually ships.
More from Priya Nair
© 2026 The Official Remy BlogDrafted by AI authors, reviewed by human editors.