Shadow AI governance for SMEs: find it, decide, keep control
Writing an AI policy is a one-week job. Keeping it true is the hard part: new AI tools appear monthly, staff adopt them without asking, and last quarter's approved list quietly stops matching reality. This guide covers the governance side of shadow AI for small and medium-sized enterprises (SMEs): how to find the artificial intelligence (AI) tools already in use, how to decide what to do with each one, and how to keep control without becoming the AI police. It ends with a free, editable policy template.
Why one policy is not enough
A KnowBe4 survey of Dutch organisations (report "From Agentic Risk to Human Wins", June 2026; no Belgian split published) measured the gap: 50% had no clear AI-use rules, 27% of employees reach for unapproved AI tools when the official ones are missing, and 58% already run autonomous AI agents. The telling number is the last one: AI use is no longer only people pasting text into chatbots. It is also software acting on its own, connected by one enthusiastic colleague.
- ! The tool list rots. AI vendors ship new products and features monthly. A shortlist approved in January is incomplete by April. Without a review rhythm, the policy describes a workplace that no longer exists.
- ! New hires never saw the policy. The policy was presented once, in a team meeting two years of staff turnover ago. Governance means the policy is part of onboarding, not folklore.
- ! Agents outlive their creators. An AI agent connected to your mailbox or customer data keeps running when the colleague who set it up changes roles or leaves. Someone must own it, or nobody does.
- ! The law now assumes you know. From 2 August 2026, Article 50 of the European Union Artificial Intelligence Act (EU AI Act) requires labels on certain AI-generated content and chatbots that identify themselves. You cannot meet a labelling duty for tools you do not know exist, so a current inventory is the legal floor, not a nice-to-have.
Step 1: Find what is actually in use
Discovery is not surveillance. The goal is an honest picture, and honesty needs safety: announce that the inventory carries no blame, then combine what people tell you with what your systems already know.
Ask, anonymously
A three-question survey gets most of the picture: which AI tools do you use for work, for what tasks, and with what kind of data? Anonymous, short, repeated twice a year. People answer honestly when the answer cannot hurt them.
Follow the money
Check card statements and expense claims for AI subscriptions. A €20-per-month charge is often the first hard evidence of a tool nobody mentioned.
Use the signals IT already has
Your IT partner can list the AI domains your network talks to (via DNS or firewall logs) and the browser extensions installed on managed machines. This finds the tools the survey missed, including ones embedded in other software.
Ask vendors the question
Your existing software suppliers keep adding AI features to tools you already approved. Ask each key vendor: which of your features send our data to an AI model, and where does it go? Shadow AI is sometimes shipped to you in an update.
Step 2: Decide per tool: approve, replace or block
For every discovered tool, make one of three calls. The criteria stay the same each time: is the input used to train someone else's model, where is the data stored, can you get a business account with admin control, and does the vendor sign a data-processing agreement?
- Approve the tools that pass and that people demonstrably need. Require business accounts, switch off training on your data where the setting exists, and put the tool on the approved list with a named internal owner.
- Replace popular tools that fail the criteria with an approved equivalent that covers the same need. A ban without a replacement just moves the use to private phones. The need is real; serve it with a tool you control.
- Block the small remainder: tools that handle forbidden data with no acceptable terms and no legitimate need. Block them technically where possible, and say why. An explained block is followed; a silent one is circumvented.
Autonomous agents deserve one extra rule: treat every AI agent like a new hire. It gets an owner (a person accountable for what it does), a written scope (which systems it may touch, which data it may read), and an offboarding step (when its owner leaves, the agent is re-assigned or switched off, and its credentials are revoked). An agent nobody owns is an account nobody watches.
Step 3: Keep control with a quarterly loop
Governance is the smallest set of habits that keeps the picture current. For an SME, four habits are enough:
One register, one owner
A single page or spreadsheet listing every approved tool and agent: name, purpose, data allowed, internal owner, review date. One named person owns the register itself. If your business already runs a compliance platform, keep the register there, next to the other evidence.
A quarterly review
Fifteen minutes, four questions: any new tools spotted since last quarter? Any approved tools no longer used (remove them, close the accounts)? Any vendor terms changed? Any agents without a current owner? Put it in the same calendar slot as your patch or access review.
Onboarding and offboarding
New staff get the AI policy with their laptop, not by osmosis. Leavers trigger a check: did they own any tools or agents in the register? Reassign before deactivating their accounts.
A no-blame incident route
Decide today who staff should tell when data ends up in the wrong tool, and promise no punishment for reporting. You can only limit damage you hear about, and you hear about it fast only when reporting is safe.
The free policy template
The download below is a complete, editable acceptable-AI-use policy in plain text (Markdown): open it in Word, your policy tool or any editor, replace the bracketed placeholders with your own names and tools, and you have a usable one-page policy plus the AI-tool register and the agent rules from this guide. No email wall; it is free to use and adapt.
- The one-page policy: approved tools, forbidden data categories, labelling duty, contact person
- The AI-tool and agent register as a fill-in table (tool, purpose, data allowed, owner, review date)
- The agent rules: owner, scope, offboarding
- The quarterly review checklist, ready to paste into a recurring calendar invite
Also available in Dutch and French; switch language on this page to download that version.
The MSP angle
For managed service providers (MSPs), shadow-AI governance is recurring work, which makes it a better service than a one-off policy delivery: the discovery signals (DNS, extensions, subscriptions) come from systems you already manage, the quarterly review fits the rhythm you already run for patching and access, and the register lives naturally next to the compliance evidence you already keep. Deliver the template as the starting artefact and the quarterly loop as the service.
FAQ
How is this different from an acceptable-AI-use policy?
The policy is the document; governance is what keeps it true. Our acceptable-AI-use guide walks through writing the one-page policy in five steps. This guide covers what surrounds it: finding the tools, deciding per tool, owning agents, and the quarterly review that stops the policy from rotting. The template below contains both the policy page and the governance pieces.
Can we just block AI tools at the firewall?
Blocking has a place, but as the last step, not the strategy. Staff use AI tools because they save real time; block everything and the use moves to private devices where you have zero visibility. Approve or replace first, block the remainder, and always say why a tool is blocked.
Do AI features inside our existing software count as shadow AI?
Yes, and they are the easiest kind to miss. A vendor update can add an AI assistant that sends your data to a model without anyone in your business choosing it. Ask your key vendors which features send data to AI models and where that data goes, and record the answers in the same register.
What is the minimum for a 10-person business?
The template filled in once, one named owner, and the quarterly fifteen-minute review. That is genuinely enough at that size: the point is not paperwork volume, it is that someone can answer "which AI tools do we use, with what data?" at any moment, including on 2 August 2026 when the EU AI Act labelling duties apply.
Further reading
-
Acceptable AI use at work: a practical policy for SMEs →
The companion guide: writing the one-page policy itself in five steps, from tool inventory to quarterly training.
-
AI-generated content: the EU labelling rules explained →
What Article 50 of the EU AI Act requires from 2 August 2026, who counts as provider versus deployer, and the voluntary Code of Practice.
-
AI-driven cyber threats: what SMEs need to know →
The attacker's side of AI: phishing, deepfake fraud, and why unmanaged AI infrastructure belongs in your patch schedule.