Across businesses globally, employees use AI for research, first drafts, document review, coding support, meeting notes, and data analysis, and New York City businesses are no different.
The governance issue starts when that work moves through personal accounts, unreviewed browser extensions, or AI services connected to company systems without formal approval. That unapproved use is shadow AI.
To bring shadow AI under company control, businesses need a way to review and approve AI use. AI whitelisting defines which platforms, accounts, users, data classes, and integrations are permitted.
An AI acceptable use policy sets the rules for employees using approved tools.
Business leadership defines permitted uses and acceptable risk, while IT configures the controls, employees follow usage and data-handling rules, and legal and compliance teams review applicable obligations.
This blog shows how businesses can put that structure into practice.
Shadow AI refers to AI tools, accounts, extensions, or integrations employees use for company work without formal review or approval. It often starts with a routine task rather than an intentional policy violation.
Common examples include:
Using a personal ChatGPT, Claude, Gemini, or other AI {account for company work
Installing an AI meeting assistant without IT review
Connecting an AI coding tool to a company repository
Adding an AI browser extension that reads company pages or documents
Uploading client files, spreadsheets, or internal records to an unapproved AI service
Connecting an AI product to email, cloud storage, CRM records, or shared drives without authorization
The risk comes from gaps in data, access, compliance, and output review:
Data Exposure: Confidential, client, financial, employee, or proprietary information could enter a service not approved for that type of data.
Access Control Gaps: The company loses control over who retains access, especially when personal accounts or unmanaged services remain active after an employee changes roles or leaves.
Contractual & Compliance Exposure: Unreviewed AI use could conflict with client agreements, privacy requirements, records policies, or industry-specific obligations.
Limited Auditability: IT may have little record of who used the service, what information was entered, which systems were connected, or what actions took place.
Unreliable Business Output: Incorrect calculations, fabricated citations, incomplete summaries, or flawed code could influence client work or internal decisions if employees don't review the results.
Before a company approves or restricts AI tools, it needs an accurate view of what employees already use.
For each AI service, record:
Product and plan or account type
Department and business owner
Business purpose
Data entered or accessed
Connected systems
Authentication method
Administrative owner
Retention setting
An MSP can pull part of this information from identity records, SaaS inventories, endpoint-management tools, browser-extension records, and expense reports.
Those sources will not capture every personal subscription or embedded AI feature, so employees and department managers should also disclose the tools they use for company work.
A short internal form can capture the tool, account type, business task, data involved, and any connected systems.
That gives the technical team enough information to review each use case without turning the inventory into a lengthy exercise.
Once the inventory is complete, assess the platform together with the work employees use it for.
Review:
How the provider handles company data
Identity and administrative controls
Retention and logging
Connected applications and permissions
Sensitivity of the information involved
Business consequence of inaccurate output or data exposure
A simple internal rating such as Low, Moderate, High, or Prohibited helps teams apply the same standard across departments.
Once a company decides an AI platform is suitable for business use, the approval needs to define more than the vendor. It should specify the account type, permitted data, approved users, and the company systems the platform can access.
AI whitelisting defines that scope. For each approved tool, document:
Product and subscription plan
Company-managed workspace or account
Approved users or departments
Approved business tasks
Permitted data classes
Authentication requirements
Retention settings
Authorized apps, connectors, or integrations
Each platform handles business administration differently, so approval should reflect the controls available in the plan the company selects.
Choose between ChatGPT Business and Enterprise based on company administration requirements.
Confirm how users authenticate and how administrators manage workspace access.
Check which Apps or Company Knowledge sources employees can use.
Set rules for business data, retention, and connected internal sources.
Select the Team or Enterprise plan according to the company’s account-management requirements.
Confirm SSO, provisioning, administrative roles, and audit capabilities available under the selected plan.
Set the required retention configuration.
Approve connected services individually rather than granting broad access across company systems.
Confirm licensing and user assignment through the Microsoft 365 environment.
Check SharePoint, OneDrive, and Teams permissions before employees receive Copilot access.
Correct excessive source-system permissions that could expose more company information than intended.
Confirm the auditing and retention controls the company will use through Microsoft 365 and Microsoft Purview.
Decide which Gemini features employees can use within Google Workspace.
Assign access through the appropriate organizational units or user groups.
Check which Workspace data employees already have permission to access.
Approve connections to additional company services individually.
Once the company defines the approved scope, a Managed Service Provider or internal IT team applies those requirements to the platform.
This includes multi-factor authentication, single sign-on where supported, user provisioning and removal, administrative roles, permission settings, and connector authorization.
This step makes the approved policy enforceable through the company’s technical environment before employees begin using the platform.
An AI acceptable use policy should tell employees what information is off-limits, how they must check AI-generated output, and what to do when something goes wrong.
Employees should not enter the following information unless the company has specifically approved the use case and data involved:
Passwords, MFA codes, API credentials, or security tokens
Client-confidential information
Personal, employee, or medical information
Payment-card or banking data
Nonpublic financial information
M&A or board materials
Privileged communications
Proprietary source code
Vulnerability or incident details
Contract-restricted information
The final list should reflect the company’s data classification, client agreements, industry requirements, and applicable privacy or compliance obligations.
Employees should:
Follow the permitted-data rules for the AI service they use
Check facts, calculations, citations, summaries, and code before relying on AI-generated output
Follow human-review requirements for client-facing, financial, employment, security, or other higher-impact work
Report accidental disclosure, suspicious output, or unauthorized AI activity through the company’s security process
Training should use examples employees recognize, such as contract review, financial spreadsheets, meeting notes, code, or internal reports.
Staff should know what information is restricted, when someone else must review the output, and where to report a problem.
After deployment, a Managed Service Provider helps keep AI use aligned with the company’s approved policy and technical settings.
Ongoing support should include:
Monitoring available identity, endpoint, application, and vendor logs for unapproved AI activity
Checking access changes, inactive accounts, and policy exceptions
Reviewing new AI features or integration requests before they enter the managed environment
Supporting incident response when AI use involves company data, credentials, or unauthorized access
Maintaining the approved-tool register and technical documentation
Recording exceptions with an owner, reason, and review date
It also supports policy enforcement through the controls available across managed devices, accounts, browsers, and applications.
NIST’s AI Risk Management Framework calls for ongoing monitoring and periodic review of AI risk-management activities, and organizations determine how often those reviews should occur.
A quarterly or twice-yearly review gives the company a regular point to reassess approved tools, exceptions, vendor changes, and new business uses.
Add a review after a significant product change, security incident, new integration request, or any change affecting regulated or contract-controlled information.
Businesses that need this work coordinated with their wider IT environment can use iTeam Technology’s IT consulting services.
Use this checklist as a final review before the policy is approved, updated, or rolled out.
Policy owner and approval authority assigned
Permitted AI uses and user groups established
Restricted-data categories specified
Human-review rules and exception process in place
Process for requesting new AI tools or use cases established
AI inventory current
Approved tools technically assessed
Access and security settings applied
Authorized integrations recorded
Approved-tool register maintained
Permitted-data rules communicated
Human-review responsibilities understood
Incident-reporting process communicated
Required AI policy training completed
Contractual, privacy, regulatory, and professional obligations assessed
Shadow AI becomes manageable when the company has a current inventory, a defined approval process, company-controlled accounts, specific data rules, and technical supervision tied to the written policy.
iTeam Technology brings more than 25 years of experience supporting New York City businesses and professional services firms. Its technical team helps assess AI usage, configure approved platforms, manage identity and access controls, document technical settings, monitor managed systems, and support policy enforcement as AI products change.
Create an effective AI Governance Policy with iTeam Technology to define approved tools, permitted data, access requirements, employee rules, and the technical controls behind them.
Use the company-managed environment approved for that platform for business activity. Personal accounts sit outside company administration, provisioning, offboarding, and the settings selected for company use.
Technical restrictions are useful when paired with a documented request process for new products and use cases. The company should base blocking decisions on its security architecture, employee workflows, risk tolerance, and available management controls.
Business leadership approves the business purpose and accepted risk. The MSP or internal IT team performs the technical assessment and configures approved controls. Legal or compliance professionals review obligations tied to regulated, contractual, privacy, privileged, or professional information.
No. Product approval and data approval are separate decisions. The approved record should specify which data classes are permitted for the exact account, configuration, use case, and integration set.
Quarterly or twice yearly is a practical operating cadence for many organizations, with additional review after significant product changes, new integrations, security incidents, repeated exceptions, or changes affecting regulated or contract-controlled information.