AI acceptable use policy: how to control shadow AI without banning AI

What shadow AI is, why banning AI doesn't work, what data protection rules require, and how to write an AI acceptable use policy your team will actually follow.

Julian Martínez Arenas·Last updated: September 23, 2026

Key Takeaways

  • Shadow AI is the use of AI tools the company never approved, usually through employees' personal accounts. It's not a future problem: in Colombia, 82% of surveyed employees already use personal AI tools for work (EY, Work Reimagined, February 2026).
  • Security incidents involving shadow AI rose from 20% to 43% in one year, at an average cost of USD 5.39 million (IBM, Cost of a Data Breach Report 2026).
  • 68% of organizations that suffered a breach had no AI governance to manage AI or detect shadow AI (IBM, 2026).
  • In Colombia, using AI with personal data is already regulated: External Circular 002 of 2024 from the Superintendence of Industry and Commerce applies Law 1581 of 2012 to AI systems.
  • A policy that works doesn't ban AI. It defines what information can go into which tool, who reviews what AI produces, and which tools the company pays for so nobody has to use their own.

Your team already uses artificial intelligence. The question isn't whether you should allow it, but what information they're using it with and in which accounts. If the company hasn't said anything, each person decided alone, and most likely contracts, price lists, and customer data are going through free accounts nobody controls.

This guide explains what shadow AI is, why banning AI makes the problem worse, what regulation requires today, and how to write a short policy people will actually follow. It's part of our guide to artificial intelligence for businesses.

What is shadow AI?

Shadow AI is the use of artificial intelligence tools for work without the company having approved, contracted, or configured them. The typical example is an employee pasting a contract into the free version of a chatbot from their personal account to get a summary.

It's widespread. Microsoft and LinkedIn's Work Trend Index found in 2024 that 78% of AI users surveyed across 31 markets were bringing their own tools to work, rising to 80% at small and medium-sized companies. In Colombia, EY's Work Reimagined study reported in 2026 that 92% of surveyed workers use AI at work and 82% use personal tools.

Shadow AI isn't born of bad faith. It comes from people finding something that saves them time while the company offered no alternative.

Why doesn't banning AI work?

Banning AI doesn't work because the need people are meeting is still there, and the tool is on their phone. A ban only moves the use to where the company can no longer see it.

The most cited case is Samsung. In 2023, according to an internal memo reported by Bloomberg, company engineers accidentally uploaded internal source code to ChatGPT. Samsung responded by banning generative AI on its devices and networks, warned of sanctions up to termination, and started developing its own tools. A company the size of Samsung can build its own AI. A mid-sized company in Colombia can't.

In the micro and small businesses we supported in El Salvador, we saw something that confirms the point: AI comes in through the owner's phone, not through a company computer or a corporate subscription. A policy that only controls office equipment leaves out the place where AI is really used.

The alternative to banning is offering an approved tool that's just as convenient, with clear rules about what information can be used in it.

What risks does shadow AI create for a company?

The main risk is that confidential information ends up in services the company doesn't control, with no record of who uploaded it or why. IBM's Cost of a Data Breach Report 2026, based on 602 organizations that suffered a breach, found that security incidents involving shadow AI rose from 20% to 43% in one year, at an average cost of USD 5.39 million.

The same report shows why it happens. 68% of breached organizations had no AI governance, and only 40% used access controls on their AI models and data. In Latin America, the average cost of a breach rose from USD 3.81 million to 4.65 million.

There are other risks beyond information leaks, like invented answers nobody reviews or legal liability for what a chatbot says. We cover them in AI risks in business.

What does Colombian law say about AI use in companies?

As of September 2026, Colombia has no specific artificial intelligence law, but using AI with personal data is regulated. On August 21, 2024, the Superintendence of Industry and Commerce (SIC) issued External Circular 002, with guidelines for processing personal data in AI systems under Law 1581 of 2012.

Three of its points matter directly to a mid-sized company:

  • Data available on the internet isn't public just because it's there. Using it in an AI system requires authorization, like any other personal data.
  • If the AI use may be high risk, a privacy impact assessment is required, documented and done before the system is designed.
  • Security measures must be technical, human, administrative, and contractual, and they must be auditable. A written use policy is the foundation of those measures.

CONPES 4144 of 2025 set Colombia's National Artificial Intelligence Policy through 2030, but it's public policy and doesn't bind companies. The government's latest AI bill was shelved, and a new one filed in the current legislative session starts from scratch. This section is general guidance, not legal advice.

What should an AI acceptable use policy include?

An AI acceptable use policy should answer five questions in a few pages: which tools can be used, with what information, for which tasks, who reviews the result, and what happens if something goes wrong. If it runs longer than three pages, almost nobody will read it.

Section What it defines Example rule
Approved tools Which tools the company pays for and configures "We use the AI assistant included in our office suite with a corporate account"
Information classification Which data can go into each tool "Never upload IDs, bank details, or customer contracts to personal tools"
Permitted uses Which tasks AI can be used for "Drafts, summaries, translations, and analysis of internal data"
Human review Who reviews before anything leaves the company "A person reviews everything that goes to a customer before it's sent"
Transparency When AI use must be disclosed "Customers are told when a deliverable was generated mainly with AI"
Incidents What to do if something was uploaded that shouldn't have been "Notify [owner] the same day, with no sanction if reported in time"

The most useful piece is information classification. Three levels are enough for most companies:

Level What it includes Where it can be used
Public Already published information: website, catalogs, news Any tool
Internal Processes, internal reports, drafts without third-party data Only approved tools with a corporate account
Confidential Personal data, contracts, negotiated prices, customer information Only approved tools with a corporate account, preferably after removing or anonymizing sensitive data

How to write an AI acceptable use policy, step by step

This is the order we recommend for a mid-sized company. It can be done in two or three weeks, without outside lawyers for the first version, although someone with legal judgment should review it before it's published.

1. Find out which tools your team already uses

Run a short anonymous survey: which AI tools they use, for which tasks, and with what kind of information. If it's anonymous, they'll tell you the truth. That map shows you where the real risk is and what people need.

2. Classify your information into three levels

Use the public, internal, and confidential table, and put concrete examples from your company at each level. "Customer data" is abstract. "The receivables file in Excel" is clear.

3. Approve and pay for at least one corporate tool

If the company doesn't offer an alternative, the policy is a disguised ban. Check what you already pay for first, since many office suites and ERPs already include AI features, and check the contract for what the vendor does with your data.

4. Write short rules for each information level

One rule per line, in company language, not lawyer language. "Don't upload contracts to your personal account" gets followed more than a paragraph on confidentiality. Include a rule on how to prepare information: remove what the task doesn't need, and anonymize names and IDs when working with data about people.

5. Define who reviews what AI produces

Establish that everything that goes to a customer, an authority, or a supplier is reviewed by a named person. AI writes with great confidence even when it's wrong, and responsibility stays with the company.

6. Train with your own team's cases

Emailing the document isn't enough. Run a short session with real examples from the step 1 survey: this is allowed, this isn't, and why. People remember cases, not clauses.

7. Review it every six months

Tools change fast. Every six months, check which new tools appeared, what incidents happened, and which rules nobody follows, because a rule nobody follows is badly written or not understood.

Real case: the AI use rules at Suricata Labs

At Suricata Labs we use AI every day with information from the companies and programs we support, so our policy starts with the same rule we recommend in this guide: we don't upload client data to tools without a corporate account. If a tool only exists in someone's personal account, it doesn't touch client information.

The second rule comes one step before the tool. Before using a document with AI, we curate it to remove confidential or sensitive information the task doesn't need. A sales analysis doesn't need customer names, and a diagnostic doesn't need the general manager's ID number. What doesn't go into the tool can't leak.

The third is anonymizing data when the task does need to work with information about people or companies. We replace names, IDs, and contact details with codes, and the AI works on that version. The analysis is just as useful and the risk drops to almost nothing.

The three rules work together: the corporate account controls where information ends up, and curation and anonymization control what information gets there. In the programs we run for the OEI in El Salvador we also learned that these rules have to apply on any device, because in most companies AI comes in through someone's phone, not through an office computer.

Frequently asked questions about AI use policies and shadow AI

Is it illegal for my employees to use ChatGPT for work?

Using ChatGPT or similar tools for work isn't illegal. What can break the law is uploading personal data about customers, employees, or suppliers without authorization or security measures, because in Colombia that's governed by Law 1581 of 2012 and SIC External Circular 002 of 2024. That's why the policy must say what information can be used in each tool.

Does a small or mid-sized company need an AI use policy?

Yes, and it costs less than for a large one. A mid-sized company can have a useful policy in two or three pages, with an information classification and one approved tool. The risk of not having one doesn't depend on size: it only takes one person uploading the customer database to a personal account.

Which AI tools are safe to use in a company?

Enterprise versions with corporate accounts are safer, because they let you control who has access and usually include contractual terms about how your data is used. No tool is safe because of its brand. What matters is checking in the contract whether the vendor uses your data to train models, where it's stored, and how it's deleted.

Who should be responsible for the AI policy in a company?

It should be someone with authority to change processes, not just the IT team. In a mid-sized company it usually works for management to own the policy and for someone from IT or operations to maintain it, with legal support to review anything involving personal data.

How often should the AI use policy be updated?

Every six months, or sooner if a new tool spreads across the team or an incident happens. A policy written a year ago probably doesn't mention tools your team uses every day.

A good policy shows in people using it

The goal of an AI use policy isn't having a signed document. It's letting your team use AI to work better without putting the company's or its customers' information at risk. If people keep using personal accounts after it's published, what's missing isn't more control: it's an approved tool that's just as useful.

If you want to build the policy with your team, at Suricata Labs we start from how people already use AI, and connect it to the first processes where it's worth applying.

Explore our AI services | Schedule a conversation

Read also: AI risks in business and how to control them

Last updated: September 23, 2026

About the author

Julian Martínez Arenas

Julian Martínez Arenas

CEO of Suricata Labs | Business Growth Consultant & AI Strategy

CEO of Suricata Labs, consultant in business growth strategies and Artificial Intelligence implementation to empower businesses.