Shadow AI at Work: How to Write an Employee AI Usage Policy

In most companies, AI did not arrive as a decision. Someone opened a browser tab to summarise a customer email, it worked, and showed a colleague. Six months later the same company may run dozens of AI tools, most on personal accounts, with no record anywhere. That pattern has a name — shadow AI — and the fix starts with one document: an employee AI usage policy.
Shadow AI is any AI tool that enters business processes without the organisation's knowledge, approval or oversight. The problem is not the tools; it is that nobody knows which data goes where. This article looks at the management side: a tool inventory, approval and access, a one-page policy. What employees should never paste into a tool is covered in our AI and personal data protection guide.
What is shadow AI, and why does nobody notice?
Traditional IT procurement leaves a trail: a contract, an invoice, an installation — somebody always knows. Generative AI tools leave almost none of that: a free tier, a browser tab, a personal email account. No accounting line, no inventory row.

The second reason is intent: people reach for these tools to finish work, not to break rules. The usage is not hiding — nobody has thought to ask.
PagerDuty's Shadow AI Survey, published on 11 June 2026, puts numbers on it: among 1,250 office workers in the US, UK, Australia and Japan, 66% had used an unapproved AI tool while believing it breached company policy, 88% had entered work-related information into one, 34% customer data and 31% financial information or confidential company documents. The sample is employees at large, high-revenue companies — so this happens even where there is a dedicated IT team and a budget. Not an SME measurement, but informative.
What the numbers say — and do not
IBM and the Ponemon Institute published the Cost of a Data Breach Report 2026 on 29 July 2026, based on 602 organisations across 16 countries and 17 industries breached between March 2025 and February 2026. The sample matters: these percentages describe already-breached organisations, weighted towards large ones, and cannot be read as "this share of SMEs" anywhere, including Turkey.
Within that sample, the share of incidents connected to shadow AI rose from 20% to 43% in a single year, and the share of organisations with no AI governance at all rose from 63% to 68% — the gap is widening, not closing. Among organisations breached through an AI model or application, 92% had no appropriate AI access controls at the time. In the same sample, the share applying a strict approval process before deploying AI fell from 45% to 38%. What shapes the outcome is the governance around the model, not the model's capability.
For Turkey there is no comparable AI measurement. In Kaspersky's SME research from early September 2026 (18 countries, 616 respondents in the SME segment), 58% of Turkish respondents — companies with 100 to 499 employees — reported at least one cybersecurity incident in the past year. A small sub-sample, but it points somewhere.
Step one: which tools are in use?
An inventory comes before a policy: only then do you know who the rule speaks to. One list, five columns:
- The tool's name and how it is reached (browser, desktop app, inside other software)
- What it is used for (proposals, customer emails, code, spreadsheets)
- What data goes into it (general, internal documents, customer data, financial data)
- Which account signs in (company or personal)
- Who uses it, and whether there is an alternative
The fastest way to collect this is a twenty-minute conversation with each team, on one condition: nobody is penalised in the first round. An employee who expects consequences will not list the tool; they will make it invisible. Keep the inventory with your other data assets, as in our piece on data security and backup.
Step two: approval and access — company or personal account?
The most valuable column is usually "which account". With a personal account the company has no handle: when the person leaves, the history goes with them, nobody can see what was entered, and you cannot manage settings. A company account fixes all three and leaves a record. The other half of this step is narrowing access by role: not everyone needs every tool, and a short approved list makes training and oversight easier.
There is a security argument too. According to Kaspersky, more than 33,300 attacks aimed at SMEs and disguised as popular AI services were blocked between January and April 2026 — roughly five times the same period in 2025 — mostly through fake download pages reached from search engines. The most imitated names were ChatGPT (42%), Claude (24%) and DeepSeek (20%); those percentages measure how often each name is used in counterfeit copies, not flaws in the services themselves. The risk sits in where the tool was downloaded from, as in our phishing protection guide: a familiar name on a fake page.
How do you write a workplace AI usage policy?
On 5 March 2026 Turkey's data protection authority, the KVKK, published a guideline titled "Use of Generative Artificial Intelligence Tools in the Workplace". Its subject is this article's: employees bringing AI tools into work without the organisation's knowledge or approval. One point matters in Turkey: the guideline is not binding. It creates no new obligation; it is a reference showing the Board's expectations and assessment criteria, and the official text sits on kvkk.gov.tr.
The guideline highlights five things: an internal rule set covering which tools may be used, for what purpose, under which conditions and with which information; and awareness work so employees do not paste confidential information or personal data into tools. It also stresses human oversight, output that is never the sole basis for a decision, role-based access limited to approved tools, and an accessible policy with regular training.
In practice a single page carries all of it. The headings we suggest: permitted tasks, the approved-tool list, data types that never go into a tool, how output is verified, which account signs in, who is told when something goes wrong, and who reviews the page and how often. The tool inventory, the company-versus-personal account split and the incident channel are our own recommendations, not obligations from the guideline. For the broader framework, our data privacy compliance guide is a good start. This is a management practice, not legal advice: have a lawyer or data protection adviser check the text first.
Why doesn't banning AI work?
The most common first reaction is a blanket ban. But a ban does not end usage; it moves it from company accounts to personal ones, which is what makes it invisible. The authority agrees: its guideline recommends guidance, balance and awareness rather than prohibition.
The other half of visibility is skill: if the person using the tool cannot spot where the output is wrong, a policy will not help on its own — our AI literacy guide for teams covers that side.
What should you do on Monday morning?
Week one is the inventory: send team leads the five-column list, collect the answers in one place, and say plainly that nobody will be penalised. Week two is decisions: which tools are approved, which move to company accounts, which data types are off-limits. Week three is the document: write the page, put it where everyone can reach it and walk through it once.
The bar rises when employee data is involved; we showed how the same logic plays out with biometric data in our article on biometric attendance and the KVKK decision.
A policy is not a one-off task
AI tools change quickly: new versions ship, free-tier limits shift, teams move on. The document must keep pace, so write the review schedule in from the start and name an owner. The authority's companion "Generative Artificial Intelligence and Personal Data Protection Guideline (in 15 Questions)" works as a checklist. When something does go wrong, the steps in our data breach response plan apply to AI-related incidents too.
If you want help building the inventory, setting up the approval flow or fitting the policy to your real processes, look at our services or get in touch.
Frequently Asked Questions
- Is a workplace AI usage policy legally required?
- The guideline on the use of generative AI tools in the workplace, published by Turkey's Personal Data Protection Authority (KVKK) on 5 March 2026, is not binding. It is a reference document showing the Board's expectations and assessment criteria rather than a source of new obligations. Even so, writing the rules down is useful management practice wherever personal data is processed. The official text is on the guidelines section of kvkk.gov.tr, and your own situation is a question for a lawyer.
- How do we find out where shadow AI is being used?
- The fastest route is not technical monitoring but a short inventory conversation with each team: which tool, for which task, with which data, and on which account. Saying at the start that nobody will be penalised in this first round is the part that decides the outcome; without it, the riskiest usage never makes the list. Keeping the collected answers in one place and refreshing them quarterly is a sufficient starting point for most small and mid-sized companies.
- Should we ban employees from using personal AI accounts?
- In most companies a ban removes the visibility, not the usage: the tool simply moves off company accounts and carries on under personal ones. Turkey's data protection authority makes a similar point, recommending an organisational approach based on guidance, balance and awareness rather than prohibition. In practice, a short approved-tool list, company accounts for those tools and role-based access works better than a ban.
- How long should the policy be, and how often should it be updated?
- One page is enough for most small and mid-sized companies: permitted tasks, the approved-tool list, data types that never go into a tool, how output is verified, which account is used, and who is told when something goes wrong. Long documents do not get read, so they do not get followed. Because tools change quickly, assign an owner and review it at least quarterly, and have a lawyer or data protection adviser check it before it goes live.
Need help with this topic?
Contact Us