# No AI policy yet? Your first 30 days of managing shadow AI

> Shadow AI is more than ChatGPT. A four-week plan for Irish SMBs to find the AI already in use, set three rules, write a one-page policy and plan what's next.

*Source: https://panoptic.ie/blog/no-ai-policy-first-30-days-managing-shadow-ai*

# No AI policy yet? Your first 30 days of managing shadow AI

Some of the AI in your business arrived without anyone choosing it. Here is a four-week plan to find it, decide what's allowed, and turn that into a policy and a plan.

[David Griffith](https://panoptic.ie/about#david-griffith), Managing Director · 7 October 2026

![A desk with a whiteboard, printed AI acceptable-use policy document, laptop with asset tag, and office phone.](https://panoptic.ie/_astro/blog_no_ai_policy_first_30_days_managing_shadow_ai_5b9510b0f1_wOwdt.png)

In short

Shadow AI is any AI tool used for work without the business knowing or agreeing. Most of it now arrives inside tools you already use. Spend week one finding what is running, week two naming an owner and deciding which tools are approved and which data never goes in, week three writing a one-page policy, and week four planning where AI should save your team time.

Your team is already using AI at work. Some of it they chose, like a ChatGPT tab or a free image tool. Some of it arrived on its own, through a software update or a calendar invite from a note-taking bot. If you have no AI policy, nobody in your business has decided what is allowed, and that gap is what people mean by shadow AI.

## Shadow AI is bigger than ChatGPT

Shadow AI is any AI tool used for work without the business knowing or agreeing. The obvious version is a staff member pasting a client email into a free chatbot. We covered that in [what to do when staff paste client data into ChatGPT](https://panoptic.ie/blog/what-to-do-when-staff-paste-client-data-into-chatgpt).

The less obvious version is harder to spot, because nobody signed up for anything:

- **Meeting note-takers** that join Teams, Zoom or Google Meet calls, record them, and email a summary to everyone, sometimes including people outside your business.
- **Browser extensions** that read the page you are on to offer help with writing or summarising.
- **AI features in software you already pay for**: accounting, design, practice management, CRM. They often switch on with an update.

Each of these can send client or patient data to a third party. Under [Article 28 of GDPR](https://eur-lex.europa.eu/eli/reg/2016/679/oj), you need a contract with any processor handling personal data on your behalf. A tool nobody knows about has no contract.

## Week one: find out what is already running

Start by asking, without blame. Ask your team which AI tools they use for work, and say plainly that nobody is in trouble. People hide what they think they will be punished for, and you need the honest list.

Then check what a staff survey misses:

1. **Connected apps.** In Microsoft 365, the Entra admin centre lists the third-party apps staff have signed into with their work account, and what each one can read. Google Workspace has a similar view. Meeting bots and AI writing tools show up here.
2. **Browser extensions.** Check a few machines by hand, or ask your IT provider to pull the list from your device management tool.
3. **Software you already own.** Look at the settings and release notes for your three or four main business systems. Note any AI feature and whether it is on.

Put everything on one list: the tool, who uses it, and what data goes into it. That list is the start of your policy.

## Week two: name an owner and make three decisions

Someone has to own this. In a business of 10 to 60 staff, that is usually the owner, a practice manager or an operations lead. It does not need to be a technical person. It needs to be someone with the authority to say yes or no.

That person makes three decisions:

- **Which tools are approved.** Pick one general assistant and pay for a business licence where the vendor agrees not to train its models on your data. Confirm that term in the contract, not the marketing page. Everything else stays off until someone asks and gets a yes.
- **Which data never goes in.** Client and patient records, payroll, bank details, and anything covered by professional confidentiality. Name the categories your trade handles.
- **Who checks output before a client sees it.** AI drafts letters, summaries and reports quickly, and it gets facts wrong with full confidence. A named person reads anything that leaves the building.

### A fourth decision for meeting note-takers

Decide when recording bots are allowed. Recording and transcribing a call means telling the people on it. [Articles 13 and 14 of GDPR](https://eur-lex.europa.eu/eli/reg/2016/679/oj) set out what you must tell people about how their personal data is used, and a bot that joins unannounced does not do that. A common, workable rule is to allow them on internal calls and keep them off client calls. The [Data Protection Commission](https://www.dataprotection.ie) publishes guidance if you want the detail.

## Week three: write it down on one page

A one-page policy that people read beats a twelve-page policy nobody opens. Cover the approved tools, the data that never goes in, the review rule, and who to ask when unsure. Our [August article](https://panoptic.ie/blog/what-to-do-when-staff-paste-client-data-into-chatgpt) sets out what that page should contain.

Then switch off what you have decided against. Remove unapproved extensions, block meeting bots you have not approved, and change your Microsoft 365 settings so staff cannot connect new apps to their work account without sign-off. Your IT provider can make these changes in an afternoon.

There is a legal reason for the briefing as well as a practical one. Since February 2025, [Article 4 of the EU AI Act](https://eur-lex.europa.eu/eli/reg/2024/1689/oj) has required businesses that use AI systems to take measures to ensure their staff have a sufficient level of AI literacy. A short policy, a fifteen-minute team briefing, and a written record that it happened are a sensible place to start.

## Week four: turn the policy into a plan

A policy says what is allowed. A strategy says where AI should earn its keep in your business. The policy is the easier place to start, and it makes the strategy safer.

Once the policy is in place, ask where AI could save your team real time. Drafting standard letters, summarising long documents and sorting inbound email are common starting points. Pick one, try it with the approved tool for a month, and measure the result. Our piece on [six questions to settle before AI touches your workflow](https://panoptic.ie/blog/six-questions-before-ai-touches-your-workflow) covers the controls for that step.

Put AI on the agenda every quarter. New tools and new features arrive every month, and your week-one list will be out of date by Christmas.

## No AI policy or strategy yet? Talk to us today

If you read this and realised nobody in your business owns AI, you are in a common position, and it is fixable in a month. Through our [Technology Success Program](https://panoptic.ie/services/technology-success-program), a named advisor reviews what AI is running in your business, helps you write the one-page policy, and builds AI into your technology roadmap with quarterly reviews.

[Get in touch](https://panoptic.ie/contact) and we will start with the week-one review.

What is shadow AI?

Shadow AI is any AI tool used for work without the business knowing about it or agreeing to it. It includes free chatbots staff use on their own, browser extensions, meeting note-taking bots, and AI features that switch on inside existing software after an update. The risk is that client or company data goes to a third party with no contract, no oversight and no record.

Are AI meeting note-takers a GDPR risk?

They can be. A note-taker records and transcribes everyone on the call, often sends the recording to an outside service, and may email summaries to all attendees. GDPR Articles 13 and 14 require you to tell people how their personal data is used, and Article 28 requires a contract with any processor. A bot that joins unannounced meets neither, so decide in advance when they are allowed.

What's the difference between an AI policy and an AI strategy?

An AI policy sets the rules: which tools are approved, which data must never go into them, and who checks AI output before it reaches a client. An AI strategy decides where AI should save time or money in your business, which tasks to try first, and how to measure the result. Write the policy first, because it makes every step of the strategy safer.

Who should own AI in a small business with no IT department?

The owner, a practice manager or an operations lead, whoever has the authority to approve or refuse a tool. The role does not need technical skill. It needs someone who keeps the list of approved tools current, answers staff questions, and reviews the policy every quarter. Your IT provider can handle the settings and the technical checks behind those decisions.

How often should a small business review its AI policy?

Every quarter is a sensible rhythm for most small businesses. AI features appear in existing software through routine updates, and new tools reach staff every month, so a policy reviewed once a year will miss most of what changed. A quarterly check of connected apps, extensions and software settings takes under an hour once the first review is done.

[All blog posts](https://panoptic.ie/blog)

## Start with a free IT review.

You'll get a clear picture of where you're exposed today, and what it looks like to have your whole IT covered as one managed system. No obligation.

[Talk to us ](https://panoptic.ie/contact)[See how we onboard](https://panoptic.ie/how-we-onboard)
