Guide

Manage Unapproved AI Use in Your Team

Make AI use visible through clear guidance, a safe reporting path, proportionate risk review, and an approved way to do useful work.

By AgentShelfUpdated September 28, 2026

Agentshelf Knowledge Guide

Give staff clear rules for AI use, an easy way to ask for help, and an approved way to do the work. When you learn about unapproved or undisclosed use, first find out what task was done, what information was shared, which account was used, and what actions were taken. Match the response to what was actually exposed.

Understand one undisclosed use case

An employee reports using an AI service that the organization has not reviewed to summarize an internal support ticket and draft a reply. The employee confirms sharing the ticket’s contact field and service-problem description from a personal account, using no connected systems. The draft has not been sent. The organization cannot verify whether the external service retained the information.

The initial review records the confirmed facts, pauses further sharing, and gives the data and security owners a clear next step:

AI use review — initial decision

  • Task: Summarize an internal support ticket and prepare a reply.
  • Confirmed: Contact field and service-problem description were entered through a personal account; no connected systems were used.
  • Immediate step: Stop adding internal ticket data while the data owner and security contact review the sharing.
  • Next step: Use an approved workflow to draft the reply and keep a person responsible for sending it.
  • State: No reply sent; external retention is unknown, so deletion is not assumed.

This response focuses on a concrete exposure and a path to resume the useful work. It does not assume misconduct or claim that the organization can retract information already shared.

Six linked oversight steps—set boundaries, test, review, decide, monitor, and reassess—surround a person responsible for the decision

A responsible person stays at the center of the review cycle.

Build visibility without treating every use alike

  1. Publish plain-language guidance. Say which kinds of information are allowed in which approved environments, which actions need review, and where to ask before trying a new tool. Update the guidance when an approved path changes.
  2. Offer a reporting route. Publish the organization’s named AI-use or security intake channel; if there is no dedicated channel, direct staff to their manager and the designated data or security contact. Ask for the service, task, information category, account used, connected systems, and whether anything was sent or changed. Do not ask employees to paste sensitive content again when a description is enough.
  3. Create a proportionate inventory. Record the use case, data types, user group, service or system, account owner, connected sources, outputs, and whether the result triggers another action. Keep only details needed for governance.
  4. Triage by exposure and consequence. A low-impact task using public material may need documentation and an approved alternative. A workflow that shares sensitive records, connects business systems, or influences a consequential decision may need security, privacy, legal, or process-owner review before use continues.
  5. Resolve the workflow. Support a suitable approved use, redesign its information and permissions, or stop a use that the organization cannot accept. Assign an owner and a review date.

An inventory is a starting point, not a control by itself. Use it to connect each use to a responsible owner, an appropriate decision, and a maintained alternative. Avoid collecting employees’ personal prompts or unrelated activity just to increase visibility.

Return to the task with a safer route

For the support-ticket example, the data owner and security contact can decide whether the shared fields require incident handling under the organization’s policy. The team can then test an approved drafting workflow using a representative ticket, confirm what information it can read, and keep a person responsible for sending the reply. If an approved path is unavailable, document the unmet need and decide whether to defer the task.

Do not treat an approval label or an internal account as proof that every data flow is appropriate. Confirm where information goes, who can access it, how it is retained, and whether the configured service supports the needed controls.

Review the outcome when the tool, data, users, or connected actions change. Pair this process with the team governance checklist, operating-boundaries guide, and security review checklist.

Your privacy choices

We use optional assistant personalization, analytics, and advertising technologies only when you allow them. Necessary site functions remain active. Cookie Policy