AI Whitelisting & Shadow AI: How to Build an Approved Tools Policy

Across businesses globally, employees use AI for research, first drafts, document review, coding support, meeting notes, and data analysis, and New York City businesses are no different. The governanc

 AI Whitelisting & Shadow AI_ How to Build an Approved Tools Policy
  

Across businesses globally, employees use AI for research, first drafts, document review, coding support, meeting notes, and data analysis, and New York City businesses are no different.

The governance issue starts when that work moves through personal accounts, unreviewed browser extensions, or AI services connected to company systems without formal approval. That unapproved use is shadow AI.

To bring shadow AI under company control, businesses need a way to review and approve AI use. AI whitelisting defines which platforms, accounts, users, data classes, and integrations are permitted.

An AI acceptable use policy sets the rules for employees using approved tools.

Business leadership defines permitted uses and acceptable risk, while IT configures the controls, employees follow usage and data-handling rules, and legal and compliance teams review applicable obligations.

This blog shows how businesses can put that structure into practice.

What is Shadow AI & How Does it Create Business Risk?

Shadow AI refers to AI tools, accounts, extensions, or integrations employees use for company work without formal review or approval. It often starts with a routine task rather than an intentional policy violation.

Common examples include:

  • Using a personal ChatGPT, Claude, Gemini, or other AI {account for company work

  • Installing an AI meeting assistant without IT review

  • Connecting an AI coding tool to a company repository

  • Adding an AI browser extension that reads company pages or documents

  • Uploading client files, spreadsheets, or internal records to an unapproved AI service

  • Connecting an AI product to email, cloud storage, CRM records, or shared drives without authorization

The Business Risks of Shadow AI

The risk comes from gaps in data, access, compliance, and output review:

  • Data Exposure: Confidential, client, financial, employee, or proprietary information could enter a service not approved for that type of data.

  • Access Control Gaps: The company loses control over who retains access, especially when personal accounts or unmanaged services remain active after an employee changes roles or leaves.

  • Contractual & Compliance Exposure: Unreviewed AI use could conflict with client agreements, privacy requirements, records policies, or industry-specific obligations.

  • Limited Auditability: IT may have little record of who used the service, what information was entered, which systems were connected, or what actions took place.

  • Unreliable Business Output: Incorrect calculations, fabricated citations, incomplete summaries, or flawed code could influence client work or internal decisions if employees don't review the results.

How to Assess AI Tools Already in Use?

Before a company approves or restricts AI tools, it needs an accurate view of what employees already use.

Build an AI Inventory

For each AI service, record:

  • Product and plan or account type

  • Department and business owner

  • Business purpose

  • Data entered or accessed

  • Connected systems

  • Authentication method

  • Administrative owner

  • Retention setting

An MSP can pull part of this information from identity records, SaaS inventories, endpoint-management tools, browser-extension records, and expense reports.

Those sources will not capture every personal subscription or embedded AI feature, so employees and department managers should also disclose the tools they use for company work.

A short internal form can capture the tool, account type, business task, data involved, and any connected systems.

That gives the technical team enough information to review each use case without turning the inventory into a lengthy exercise.

Risk-Rate the Tool & Its Use Case

Once the inventory is complete, assess the platform together with the work employees use it for.

Review:

  • How the provider handles company data

  • Identity and administrative controls

  • Retention and logging

  • Connected applications and permissions

  • Sensitivity of the information involved

  • Business consequence of inaccurate output or data exposure

A simple internal rating such as Low, Moderate, High, or Prohibited helps teams apply the same standard across departments.

How to Whitelist & Configure Approved AI Tools?

Once a company decides an AI platform is suitable for business use, the approval needs to define more than the vendor. It should specify the account type, permitted data, approved users, and the company systems the platform can access.

AI whitelisting defines that scope. For each approved tool, document:

  • Product and subscription plan

  • Company-managed workspace or account

  • Approved users or departments

  • Approved business tasks

  • Permitted data classes

  • Authentication requirements

  • Retention settings

  • Authorized apps, connectors, or integrations

  • Administrative owner

What to Check Before Approving ChatGPT, Claude, Copilot, or Gemini?

Each platform handles business administration differently, so approval should reflect the controls available in the plan the company selects.

ChatGPT

  • Choose between ChatGPT Business and Enterprise based on company administration requirements.

  • Confirm how users authenticate and how administrators manage workspace access.

  • Check which Apps or Company Knowledge sources employees can use.

  • Set rules for business data, retention, and connected internal sources.

  • For Enterprise deployments, account for controls such as domain verification, SSO, and SCIM.

Claude

  • Select the Team or Enterprise plan according to the company’s account-management requirements.

  • Confirm SSO, provisioning, administrative roles, and audit capabilities available under the selected plan.

  • Set the required retention configuration.

  • Approve connected services individually rather than granting broad access across company systems.

Microsoft 365 Copilot

  • Confirm licensing and user assignment through the Microsoft 365 environment.

  • Check SharePoint, OneDrive, and Teams permissions before employees receive Copilot access.

  • Correct excessive source-system permissions that could expose more company information than intended.

  • Confirm the auditing and retention controls the company will use through Microsoft 365 and Microsoft Purview.

Gemini

  • Decide which Gemini features employees can use within Google Workspace.

  • Assign access through the appropriate organizational units or user groups.

  • Check which Workspace data employees already have permission to access.

  • Approve connections to additional company services individually.

Configure Company Access Before Rollout

Once the company defines the approved scope, a Managed Service Provider or internal IT team applies those requirements to the platform.

This includes multi-factor authentication, single sign-on where supported, user provisioning and removal, administrative roles, permission settings, and connector authorization.

This step makes the approved policy enforceable through the company’s technical environment before employees begin using the platform.

How to Build an AI Acceptable Use Policy for Employees?

An AI acceptable use policy should tell employees what information is off-limits, how they must check AI-generated output, and what to do when something goes wrong.

Define Restricted Information

Employees should not enter the following information unless the company has specifically approved the use case and data involved:

  • Passwords, MFA codes, API credentials, or security tokens

  • Client-confidential information

  • Personal, employee, or medical information

  • Payment-card or banking data

  • Nonpublic financial information

  • M&A or board materials

  • Privileged communications

  • Proprietary source code

  • Vulnerability or incident details

  • Contract-restricted information

The final list should reflect the company’s data classification, client agreements, industry requirements, and applicable privacy or compliance obligations.

Set Employee Usage Rules

Employees should:

  • Follow the permitted-data rules for the AI service they use

  • Check facts, calculations, citations, summaries, and code before relying on AI-generated output

  • Follow human-review requirements for client-facing, financial, employment, security, or other higher-impact work

  • Report accidental disclosure, suspicious output, or unauthorized AI activity through the company’s security process

Train for Compliant AI Use

Training should use examples employees recognize, such as contract review, financial spreadsheets, meeting notes, code, or internal reports.

Staff should know what information is restricted, when someone else must review the output, and where to report a problem.

How an MSP Handles Configuration, Monitoring, Enforcement, & Review?

After deployment, a Managed Service Provider helps keep AI use aligned with the company’s approved policy and technical settings.

Ongoing support should include:

  • Monitoring available identity, endpoint, application, and vendor logs for unapproved AI activity

  • Checking access changes, inactive accounts, and policy exceptions

  • Reviewing new AI features or integration requests before they enter the managed environment

  • Supporting incident response when AI use involves company data, credentials, or unauthorized access

  • Maintaining the approved-tool register and technical documentation

  • Recording exceptions with an owner, reason, and review date

It also supports policy enforcement through the controls available across managed devices, accounts, browsers, and applications.

Review the Policy on a Defined Schedule

NIST’s AI Risk Management Framework calls for ongoing monitoring and periodic review of AI risk-management activities, and organizations determine how often those reviews should occur.

A quarterly or twice-yearly review gives the company a regular point to reassess approved tools, exceptions, vendor changes, and new business uses.

Add a review after a significant product change, security incident, new integration request, or any change affecting regulated or contract-controlled information.

Businesses that need this work coordinated with their wider IT environment can use iTeam Technology’s IT consulting services.

AI Acceptable Use Policy Checklist

Use this checklist as a final review before the policy is approved, updated, or rolled out.

Company leadership

  • Policy owner and approval authority assigned

  • Permitted AI uses and user groups established

  • Restricted-data categories specified

  • Human-review rules and exception process in place

  • Process for requesting new AI tools or use cases established

  • Policy review schedule set

Managed Service Provider / IT

  • AI inventory current

  • Approved tools technically assessed

  • Access and security settings applied

  • Authorized integrations recorded

  • Approved-tool register maintained

Employees

  • Permitted-data rules communicated

  • Human-review responsibilities understood

  • Incident-reporting process communicated

  • Required AI policy training completed

Legal / compliance

  • Contractual, privacy, regulatory, and professional obligations assessed

 

Set Effective AI Governance Standards with iTeam Technology

Shadow AI becomes manageable when the company has a current inventory, a defined approval process, company-controlled accounts, specific data rules, and technical supervision tied to the written policy.

iTeam Technology brings more than 25 years of experience supporting New York City businesses and professional services firms. Its technical team helps assess AI usage, configure approved platforms, manage identity and access controls, document technical settings, monitor managed systems, and support policy enforcement as AI products change.

Create an effective AI Governance Policy with iTeam Technology to define approved tools, permitted data, access requirements, employee rules, and the technical controls behind them.

Talk to Our iTeam Experts

Frequently Asked Questions (FAQs)

1. Should employees use personal ChatGPT, Claude, Gemini, or Copilot accounts for company work?

Use the company-managed environment approved for that platform for business activity. Personal accounts sit outside company administration, provisioning, offboarding, and the settings selected for company use.

2. Should a company block AI products that have not been approved?

Technical restrictions are useful when paired with a documented request process for new products and use cases. The company should base blocking decisions on its security architecture, employee workflows, risk tolerance, and available management controls.

3. Who approves a new AI tool?

Business leadership approves the business purpose and accepted risk. The MSP or internal IT team performs the technical assessment and configures approved controls. Legal or compliance professionals review obligations tied to regulated, contractual, privacy, privileged, or professional information.

4. Does approval of an AI platform mean confidential company data is approved for use with it?

No. Product approval and data approval are separate decisions. The approved record should specify which data classes are permitted for the exact account, configuration, use case, and integration set.

5. How often should an AI acceptable use policy be reviewed?

Quarterly or twice yearly is a practical operating cadence for many organizations, with additional review after significant product changes, new integrations, security incidents, repeated exceptions, or changes affecting regulated or contract-controlled information.