Employees use ChatGPT, Copilot and dozens of smaller AI tools — often without IT knowing. This “shadow AI” is the new shadow IT: convenient, quickly adopted, but with data-leak and compliance risks that fall outside your ISMS. The answer is not to ban it, but to bring it into scope. After all, ISO 27001 asks for control over where your information goes — and AI tools are a new, fast-growing channel.
Why shadow AI is an ISMS risk
- Data leaks: company data or personal data ending up in prompts to external models.
- Confidentiality: customer information reused elsewhere as training data.
- Integrity: incorrect or fabricated output (“hallucinations”) slipping into decisions.
- Supply chain: sub-processors and model providers you never formally assessed.
Each point touches the core of ISO 27001: confidentiality, integrity and availability. Link them to your privacy and risk assessment.
From ban to policy
A blanket ban does not work — it only pushes use deeper into the shadows. More workable is a short AI usage policy: which tools are approved, which data categories may not go in, and where an employee reports a new tool. Combine that with a simple AI inventory: which tools are in use, for what purpose, with what data. That register is immediately your first step towards ISO 42001.
What a workable AI policy looks like
Keep it to one page people actually read. The core elements:
- Approved tools: a short list of AI services judged safe enough, with the permitted use per tool.
- Data boundary: a clear rule linked to your data classification — for example “no confidential or personal data in public AI tools”.
- Reporting route: where an employee submits a new tool for assessment, so the list grows rather than ages.
- Responsibility for output: AI is an aid, not a source of truth — the employee remains accountable for what happens with the output.
Practical controls for SMEs
Start light and build out. Business subscriptions with a data opt-out (where your input is not used for training) are often far safer than free consumer versions — that difference alone removes a lot of risk. Add awareness so people understand the risk: one concrete example (“never paste a customer contract into a free chatbot”) lands better than ten lines of policy. And record choices and exceptions — that is exactly the evidence an auditor wants to see.
The bridge to ISO 42001
Anyone using AI seriously will sooner or later meet ISO 42001 — the standard for AI management systems. You need not certify to it now, but the steps you take for shadow AI (inventory, policy, per-tool risk assessment) are exactly the foundation. See it as working ahead: you resolve an acute ISO 27001 risk and lay the basis for responsible AI management.
What the auditor wants to see
Not a thick AI report, but evidence that you are in control: the AI usage policy, the inventory of tools in use, the data boundary linked to your classification, and a sign that employees are aware of it (for example a short awareness session or onboarding item). Also show that the list is alive — that tools have been assessed and sometimes rejected.
Common mistakes
- Banning everything — pushes use into the shadows and produces no evidence.
- Allowing free consumer versions for work — often without a data opt-out, so your data feeds the model.
- No inventory — without visibility of which tools are in use, you can control nothing.
- Policy without awareness — if no one knows the rule, it does not exist.
Getting started
Start this week with two things: a short inventory (“which AI tools do we use, with what data?”) and one rule on what may not go in. That pulls shadow AI out of the blind spot and brings it into your ISMS. Want to know more about AI governance? See ISO 42001 or take the free readiness scan.
