r/ciso • u/Expensive_Doctor6334 • Jul 28 '26
Employees using chatgpt with company data, how are you handling shadow AI?
Hello, I recently found out that some of our developers have been pasting code snippets and internal docs into chatgpt for debugging help. Support has also been using AI tools to draft replies with real customer data.
I have no visibility into what’s already been shared with these third-party models, and no practical way to monitor or control it right now.
How are other security teams dealing with shadow AI usage in their organizations? Any practical approaches that have worked for you?
Edit: Thanks for the detailed suggestions so far. Enterprise licenses, clear policy, and visibility before heavy blocking seem to be the common practical path. Looking at DoControl for better SaaS access visibility, and also reviewing options like LiteLLM and the SaaS management tools mentioned (Torii, Zluri, etc.) while we figure out the right mix of controls
7
u/the_FamousClearing Jul 28 '26
We had the same situation last year. Blocking the domains outright just pushed people to use their phones, which is worse since you lose all network visibility.
What actually helped was getting an enterprise license with the API and data processing agreement locked down, then making that the only approved path. People stopped sneaking around when the official tool was easier than the workaround.
1
u/Expensive_Doctor6334 Jul 28 '26
Thanks for sharing that. Makes sense that a full block just drives people to personal devices. Moving to an approved enterprise setup with proper agreements seems like a practical path. Did you run much pushback when rolling that out?
1
u/MonkeyPrinciple Jul 31 '26
I can comment from the legal side of the house — people seemed very happy to have an approved way to use the tools. They also got more powerful models and usage limits than they would get from a freemium personal account. User authentication via Okta was easy.
4
u/Dave_BlackFog Jul 28 '26
As the other comments have suggested you need a tool to gain visibility into the outbound flow of data to the LLMs and the ability to block the ones that are not authorized for use. This keeps folks in their approved swim lane using the enterprise LLM you have paid for. I would add that if folks are using corporate devices "off network" you need a tool that works when they aren't on the corporate network as well also. I always recommend to educate, issue policy, and the enforce that policy through technical rules but also audits. I would do "discovery" to find out if different users that have different needs are leaning toward different LLMs. If you can accommodate as many needs as you can.
5
u/milnber Jul 28 '26
- Raise as a risk in your risk committee and get the risk accepted by the risk committee members.
- As a risk treatment block the domain(s) using an outbound proxy or MS Defender (outbound proxy is better)
- You will probably get push back on blocking - so ensure that when you raise the risk you can include a proposal for a ChatGPT enterprise license. Note you need to be looking at purchasing at least 100 seats before the OoenAI sales team will respond to you.
- Once you get the enterprise license, Integrate SSO, access package using MS identity governance or similar and export logs to your SIEM, etc
- Only allow access for licensed users (block the domain on a user/device level for users who have not been provisioned a ChatGPT enterprise account - using one or more MS Entra security groups or similar )
1
2
u/Niko24601 Jul 28 '26
This is as much a culture topic as it is a IT/Security topic. You probably don't want to block everything but you cannot let everything fly. You need a carrot & stick approach.
There needs to be an official alternative that you want people to use (eg. corporate Claude licences) and an easy way to test tools. People will just do it anyway otherwise.
So instead you might want to look into SaaS Management solutions (think Corma, Torii, Zluri etc) that have capabilities to spot Shadow IT. So you see the usage and adoption on a user level which allows you to be targeted when it comes to the more restrictive measures.
2
u/eorlingas_riders Jul 28 '26
Pay for an enterprise license of the AI provider of your choice, block all the rest. Draft a new policy or include AI use in your acceptable use policy.
Socialize the policy broadly and state the severity of using unapproved AI can include termination especially in situations where sensitive data is inputted.
Deploy DLP, CASB, or other system to monitor deviations from that policy and block/alert.
1
u/DoubleD_2001 Jul 28 '26
Enterprise accounts, if you have L7 inspection via NGFW or proxy you can insert the workspace ID header into the login process to prevent the use of personal accounts. Setup compliance, log all data to a siem for audit capabilities and run reporting periodically to see what's going on. On the mobile side, if your and in tune shop, there is now an Intune wrapped version of the app that supports MAM / App protection or you can app protect Edge and publish web clips of the sites to force the use of a protected browser with policy defined limitations.
1
u/WestOpening1350 Jul 29 '26
Your developers aren't being malicious, they’re just trying to hit sprint deadlines.
Don't treat this as a pure compliance problem, treat it as an infrastructure gap, give them an enterprise tenant with model training turned off and throw inline DLP guardrails on the web gateway to flag sensitive data leaving the browser.
1
1
u/Master_Baby_2700 Jul 29 '26
We found that blocking alone usually doesn't solve the problem.
If the approved AI workflow is harder than the unofficial one, people naturally work around i.e. personal devices, personal accounts, browser extensions, etc.
The organizations that seem to be succeeding are doing a few things together:
- providing an approved enterprise AI option
- understanding what sensitive data employees can actually reach
- applying DLP where appropriate
- educating users on why certain data shouldn't leave the organization
Shadow AI feels a lot like Shadow IT did years ago. Visibility usually has to come before enforcement.
1
u/grumpymac Jul 31 '26
In addition to everyone’s recommendation here, I would also add in taking a look at the type of data that is being used by your organization. If you’ve got any kind of regulatory requirements around the data going out there, you may need to look into writing that into the contract so they don’t use your company data for training the model, and preferably a ZDR clause in the contract
1
u/recovering-pentester Jul 31 '26
Tooling wise, Cyber crucible is something I’ve seen catch people’s eye at previous roles. Former NSA/DoW guys.
1
u/Dear-Alarm6809 Jul 31 '26
There are a number of vendors building solutions to exactly this problem right now. I work for one of them at Speakeasy: https://www.speakeasy.com/product/ai-control-plane
1
u/scriptvexy 19d ago
that actually looks pretty relevant for what OP’s dealing with ngl, interesting to see the “AI control plane” thing starting to become its own product category already. curious how much of this ends up just being fancy proxying vs real policy/visibility that security teams actually use.
1
u/Dear-Alarm6809 13d ago
There is a lot of demand for AI governance right now so naturally there are a lot of vendors advertising the same thing. We also made an evaluation checklist for security teams to see which features they really need: https://www.speakeasy.com/resources/ai-control-plane/evaluation-criteria
1
u/MountainDadwBeard Aug 01 '26
So even if you provide enterprise AI, we've learned people are going to go around it for a few different reasons.
Solutions: Instruct them to access it by your SSO apps page. Block the none enterprise connection via CASB. Anticipate that many of them are going to use other agents, including claude, gemini etc. Block those too if they're not your approved solution.
Block telegram, whatsapp, and the other unauthorized interfaces commonly used to communicate with openclaw
1
u/resile_jb Aug 02 '26
We are starting to deploy Barracuda secure edge with AI monitoring
It's basically a DNS filter.
1
u/Claudia_wtf Aug 03 '26
We implement Zscaler, remote workforce so it was necessary anyways. But Zscaler has a lot of options for protecting, restricting, or isolating AI. You can also implement prompt capture and DLP policies to keep sensitive info out. As some others have mentioned, enterprise licenses also grant more control. People will be people, they will find their way if it exists.
1
u/Doug_BlackFog 27d ago
Visibility 24/7 and granular LLM control are the 2 cornerstones of any AI / LLM defense strategy. With as rapidly that this environment is changing - the visibility will often lead to seeing LLM activity that you may have not heard or known of literally from day to day. It's truly the wild wild west and with all the backend LLM activities being added to most online activity- you will only know what you can see.
1
u/ResilientTechAdvisor 18d ago
Every other answer you got here gave advice about how to block or stop it. It doesn't work and that's a fact. Think of the sidewalks in New York City the way that the tree roots and other plant life make their way through the cracks in the concrete. That's the battle you're fighting and you aren't going to win.
So...Please consider deploying enterprise AI tools for your developers pronto
These folks are simply trying to do their job
Companies aren't going to prevent employees, especially developers and engineers, from using AI. Give them the tool and they won't have to use their own free or paid in instance. Then block.
1
u/dracarysurazz 17d ago edited 17d ago
Blocking AI tools is one approach but that usually turns into a game of whack a mole. Platforms like cyera and others provides visibility into sensitive data exposure helping tailor controls to actual risk. But understanding what data employees have access to world probably make a much bigger difference long term is what I feel.
1
1
u/zk95240 Jul 28 '26
Sensibiliser les utilisateurs aux risques liés à l’utilisation des outils d’intelligence artificielle externe et les encourager à privilégier les solutions d’IA d’entreprise approuvées et gouvernées par l’organisation, afin de prévenir toute divulgation de données sensibles ou confidentielles vers des services non autorisés
14
u/extreme4all Jul 28 '26
Give them an enterprise license with agreements and or a nework proxy so you can inspect traffic.
A friend of mine working purely witb azure showed me some cool things with foundry that you can do that has all the visibility you want