412-444-7768Careers
Pittsburgh · Since 198924/7 Monitoring
Back to Blog
October 6, 2026

How to Find Shadow AI and Write an AI Acceptable Use Policy (Free Template)

AILatest blog
William Palmer
William Palmer7 min read
Stay Ahead of Downtime

IT and security insights for manufacturers — straight to your inbox.

A smartphone with an AI chat prompt on screen, propped beside a closed laptop on a desk.

Find the AI tools your staff already use, write the rules on two pages, and know what to do in the first hour after client data lands in a chatbot.

Stay Ahead of Downtime

IT and security insights for manufacturers — straight to your inbox.

What Is Shadow AI, and How Common Is It?

Shadow AI is any AI tool your staff use for work without your approval, and it is almost certainly in your office today. That matters because anything typed into those tools sits in accounts you cannot see or control.

Verizon's 2026 Data Breach Investigations Report found 45% of employees using AI regularly on work devices. Two in three of the staff using unapproved AI signed in with personal accounts.

This guide shows how to find it and write an AI acceptable use policy, building on our four-step plan for becoming an AI-powered business.

How Do You Find the AI Tools Your Staff Already Use?

You can find most of it in about a week, with what you already pay for. Ask your people first, then check where these tools leave a trace.

  1. Send every team a short survey about the AI tools they use, and promise in writing that nobody gets in trouble.
  2. Have your IT person list the apps connected to company email.
  3. Check which browser add-ons are installed on company computers.
  4. Read six months of card statements and expenses for AI subscriptions.
  5. Read your web filter reports for visits to AI sites, if you have a filter.

Right now, any employee can usually let an outside app, such as an AI note-taker, read their company email. Ask your IT person to tighten that setting, as Microsoft recommends, so most new apps need IT's OK before they can read company email.

If nobody in-house has time, Wolf's AI advisory services start with a readiness assessment that reviews permissions like these. On Monday, send the survey and ask for the connected-apps list.

What Goes in an AI Acceptable Use Policy?

A good AI policy is two pages that tell staff which tools they may use, what they must never paste, and who to call when something goes wrong. The rules fit on the first page, and the second covers reporting, monitoring and review.

Section

What it says

Approved tools

The AI tools staff may use, signed in with a work account only.

Ask first

How to request a new tool, and who answers within two business days.

Never paste

Customer drawings and financial records, payroll, passwords, and anything under an NDA.

Check the output

A person reads every AI draft before a client sees it.

Not for AI

Hiring, firing and pay decisions, and legal or medical advice to clients.

Add-ons and note-takers

Browser extensions and meeting bots need approval too.

If something goes wrong

Report it within one hour, with no penalty for reporting.

What we monitor

The company reviews app sign-ins and web traffic on company devices.

Review

The policy owner updates the list every six months.

The one-hour reporting rule works because people speak up early when nobody is blamed. By Friday, decide which AI tools you will approve and who will own the policy.

What Can Employees Share With AI Tools?

Staff can use public material in approved tools, must ask before using bids, quotes or internal documents, and must never paste customer, payroll or ID data. Nothing from the company goes into a personal AI account.

OK to use

Ask first

Never paste

Text already on our public website

Bids, quotes and proposals

Customer drawings, designs and CAD files

General questions, such as how to write a spreadsheet formula

Internal procedures and price sheets

Customer financial records and tax returns

Your own rough drafts with no customer or staff names

Customer emails with names and account details removed

Payroll, HR and health information

Passwords, codes and access keys; Social Security, bank account and driver's license numbers; anything under an NDA or customer contract

In personal accounts the answer is no for everything, unless you choose to allow public website text, which the policy template lets you add. This week, swap in three examples from your own work.

How Do You Roll Out an AI Policy So People Follow It?

Give people an approved tool on day one, train them for 20 minutes, and collect signatures the same week. A ban with nothing approved behind it just moves the work to personal phones.

If you pay for a Microsoft 365 business plan, your staff can already use a safer AI tool at no extra cost. Microsoft Copilot Chat works when staff sign in with their work account, and Microsoft does not use those prompts to train its AI models. If you are not sure which Microsoft 365 plan you have, our Microsoft 365 services team can check for you.

Training matters as much as the tools, as Cliff Lashawn, one of our technical services managers, says.

"Even if we put the best tools in place, if you have employees that aren't well trained, they could still let in malicious actors."

Cliff Lashawn, vCTO and Technical Services Manager at Wolf Consulting

The free template holds the full agenda, survey and signature page, and the session runs in this order.

  1. Explain why you have the policy and the one-hour rule.
  2. Show the approved tool live on two real tasks.
  3. Walk through the data table with your own examples.
  4. Show how to ask for a new tool, add-on or note-taker.
  5. Cover what to do in the first hour after a mistake, then collect signatures.

With shift workers, run it once per shift. Wolf can run the session for you as part of our secure AI usage training. Then have your IT person block the apps and add-ons you have not approved.

Every few months, have someone check that those settings still work. Eli Person, who runs centralized services at Wolf, puts the habit simply.

"It's trust, but verify, with everything."

Eli Person, Centralized Services Manager at Wolf Consulting

Start with one team, the way Wolf does. When Wolf switched backup vendors in 2020 and 2021, it tested with a few clients first, then moved everyone else over the next three months, and it worked as expected. Before Friday, show one team how to open Copilot Chat with their work account.

What If Someone Pastes Client Data Into ChatGPT?

If client or personal data went in, act within the hour and save the evidence before anything else.

  1. Thank the person, then screenshot or export the chat and note the tool, the account and the time.
  2. Change any password or access key that was in the paste.
  3. Call your attorney and your cyber insurer before you tell anyone outside the company.
  4. Check the client's contract or NDA for a clause that says when to tell them.
  5. Once counsel agrees, delete the chat from the account.
  6. Write down what happened, who was told and what was done.

OpenAI's data policy says it may train on chats from personal ChatGPT accounts. By default, it does not train on chats from ChatGPT Business or Enterprise. IBM's 2025 breach study found that shadow AI added as much as $670,000 to an average breach. Add these steps to your incident response plan, or use the template's checklist if you do not have one yet.

What Do PA, Ohio and WV Breach Laws Require After a Paste?

If the paste held someone's name with their Social Security, license or bank account number, the law may make you tell them fast. Your own payroll and HR files count too. Put your attorney's number at the top of the policy so you can call fast. If it held a customer's drawings or prices, the contract decides what you owe.

Pennsylvania wants the people affected told without unreasonable delay. If more than 500 Pennsylvanians are affected, you must also tell the Attorney General and the credit bureaus. Ohio says as fast as possible and no later than 45 days, and West Virginia wants no unreasonable delay. Your attorney decides whether a paste counts as a breach.

What Else Do Owners Ask About AI Policies?

In short, personal ChatGPT is shadow AI, finding it costs nothing extra, and Ohio offers some legal protection.

Is ChatGPT considered shadow AI?

Yes, when it runs on a personal login, because those chats live in an account your company does not control. A company-managed ChatGPT Business (formerly Team) or Enterprise plan can be an approved tool.

Do we need to buy anything to find shadow AI?

No, the five checks above use what you already have.

Does a written AI policy give us any legal protection?

Of these three states, only Ohio offers that kind of protection. Ohio's safe harbor law can help in some breach lawsuits if your policy is part of a larger written security plan. A review by the firm Troutman Pepper names six states with this kind of law, and Pennsylvania and West Virginia are not on its list. In those states, the policy pays off by preventing the leak in the first place.

Get the Free AI Acceptable Use Policy Template

Start this week, because every week without a policy is another week of company data in accounts you cannot see.

Get the free AI Acceptable Use Policy template to receive the editable Word policy and the PDF guide. We can also write the policy with you, train your staff and set up the security controls behind it. Talk with our team, even if you have no draft yet. Wolf works with owners across Pennsylvania, Ohio and West Virginia from our Monroeville office, and you can call us at 412-444-7768.

Wolf Consulting
Want to see if we’re a fit?

Schedule a no-pressure consultation with our team.

Get started
Get Started

Step into a safer, Stronger Business.

When you’re ready to move beyond “good enough,” we’re here to help. Reach out to schedule a no-pressure consultation and find out whether we’re a fit.