Shadow AI: How to Stop Staff Pasting Client Data Into Free Tools

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Shadow AI: How to Stop Staff Pasting Client Data Into Free Tools.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Shadow AI: How to Stop Staff Pasting Client Data Into Free Tools.

Give staff an approved AI tool on a business plan that is quicker to reach than the free one, write a one-page rule saying which client details never go into any AI, block the free sites on work browsers, and make owning up to a slip safe. Blocking without an alternative just moves the pasting to personal phones.

The free tool itself is rarely the whole problem. The risk is that client details land in a personal account the business cannot see, audit or delete, and consumer chats may be used to improve the vendor's models unless the person has switched that off. Business plans from the main vendors don't train on business content by default, so the fix is mostly about moving the work, not banning AI.

Follow me on Instagram@sagnikteaches

Why client data ends up in free chatbots

People paste client data into free tools because they are trying to get work done faster, not because they are careless. If you fix the reason, the behaviour changes. If you only forbid the behaviour, it goes quiet and carries on. Spotting shadow AI in your team is the first half of the job; the table below is the second half, matching each reason to a fix.

Connect on LinkedInSagnik Bhattacharya
Why they do itWhat it looks likeWhat actually fixes it
No approved tool existsStaff use whatever they found at homeA business-plan tool, set up and bookmarked for them
The approved tool is slower to reachTwo logins and a VPN versus one tabSingle sign-on, a pinned tab, the app on work phones
Nobody said what counts as client data"I only pasted the complaint, not the file"A traffic-light list with real examples from your work
They fear being told offNobody admits to anything, everA written promise that first reports won't be punished
The job genuinely needs client detailLetters, summaries and replies to named peopleAn approved tool plus a habit of stripping identifiers

Step 1: Make the approved tool faster than the free one

Start with what your office software already includes, because it costs nothing extra and staff are already signed in.

Subscribe on YouTube@codingliquids
  • Microsoft 365 business plans include Microsoft 365 Copilot Chat at no extra cost. When staff sign in with their work account, enterprise data protection applies, and Copilot Chat shows a green shield near the top of the screen to confirm it. Teach people to look for that shield; if it is missing, they are in the consumer version.
  • Google Workspace plans now include the Gemini app, and Workspace business content is not used to train Google's models by default. Staff must be signed in with the work account, not a personal Gmail, for that to hold.
  • If you want ChatGPT or Claude specifically, ChatGPT Business costs $25 per user a month on monthly billing or $20 on annual billing, and Claude Team Standard is priced the same way. Both need at least two seats, so a one-person business pays for two or uses an individual plan with the training switch turned off.

Then remove every bit of friction. Pin the approved tool as the first bookmark on every work browser, set it as the start page if people live in it, install the app on work phones, and switch on single sign-on where the plan offers it so there is no extra password. A shared Project with your house style and standard documents makes the approved tool more useful than the free one, which matters more than any rule. Setting up company AI accounts instead of personal logins covers the account side in detail.

What to load into the approved tool so it beats the free one

The single biggest reason staff drift back to free apps is that the approved tool feels generic. Give it the firm's own material and it becomes the obvious choice. For a small electrical contractor, the shared Project might hold:

  • The current price list and call-out charges, dated, so drafts quote the right figures.
  • Standard terms, payment terms and the wording used on quotes.
  • Five good past quotes and three good complaint replies, with customer names and addresses removed.
  • The firm's email sign-off, phone number and service area description.
  • A short instruction block: "Write for homeowners, plain words, no jargon, always say the price includes parts and labour unless stated."

That takes about 45 minutes to assemble from files the office already has, and it means a prompt like "quote for fitting six downlights and two extra sockets in a kitchen" comes back in the firm's own format. A free chatbot can't do that without someone pasting the price list in every time, which is exactly the habit you are trying to stop.

For a small electrical contractor with six office and field staff on Microsoft 365 Business Standard, the cheapest version of this step is free: Copilot Chat is already in the plan, so the work is 30 minutes of pinning it in browsers and a ten-minute demo. If two estimators later want ChatGPT for longer documents, two Business seats on annual billing add $40 a month.

Step 2: Write a traffic-light data rule on one page

Most AI policies fail because they say "don't share sensitive data" and leave staff to decide what that means at 4.55 on a Friday. A traffic-light list gives examples from your own work. Here is a filled-in version for a three-clinician podiatry practice, written to fit on one sheet.

AI DATA RULE (podiatry clinic, one page, reviewed every 6 months)

RED: never goes into ANY AI tool, approved or not
- Patient name together with any condition, treatment or photo
- Dates of birth, home addresses, phone numbers of patients
- Card numbers, bank details, insurance policy numbers
- Anything from a safeguarding or complaint investigation file

AMBER: approved tool only (work account, green shield showing),
       and only after names and identifiers are removed
- "Patient A" style case questions for letter drafting
- Complaint emails with names, dates and addresses stripped
- Appointment and no-show numbers without names

GREEN: any tool is fine
- Our public price list, opening hours and treatment pages
- Generic social posts, leaflets, job adverts
- Questions about software, spreadsheets, wording

Not sure? Treat it as RED and ask the practice manager.
Pasted something by mistake? Tell the practice manager the
same day. First reports are never treated as misconduct.

Keep the rule short enough to pin by the reception desk. If you want the longer policy behind it, writing an AI usage policy walks through the full version; the one-pager is what people will actually read.

Step 3: Close the side doors on work browsers

Once there is a good alternative, blocking the free tools on company devices is reasonable. The cheapest route for most small firms is Chrome Enterprise Core, Google's free browser management, which lets you push a URL blocklist to managed Chrome browsers from the Google Admin console. Microsoft Edge has equivalent policies if your devices are managed through Microsoft tools.

There is one detail that trips people up. If your approved tool is ChatGPT Business, Claude Team or the Gemini app, it lives on the same web address as the free version. Blocking chatgpt.com or claude.ai blocks your paid workspace too. In that case, block the tools you have not approved, and control the approved one by habit and sign-in: staff use the work login, and personal accounts are off-limits on work devices. Where your approved tool has a different address from the consumer one, you can block the consumer site outright.

Two more side doors are worth closing:

  • AI browser extensions. "Summarise this page" and "write my email" extensions can read everything in the browser, including client portals. Chrome Enterprise can restrict which extensions are allowed. Spotting fake AI apps and risky extensions explains what to look for.
  • Free meeting note-takers. A free bot that joins client calls sends the whole conversation to a vendor you never assessed. Decide which one, if any, is approved.

Personal phones are the gap you cannot close with settings. That is exactly why Step 1 comes first: if the approved tool is quicker, most people stop reaching for their own phone.

Step 4: Teach the "strip before you paste" habit

Even in the approved tool, staff should remove identifiers they don't need. The AI almost never needs a name or address to draft a good reply. Here is a before and after from a plumbing firm answering an angry customer.

Before (what a busy office manager might paste):

Reply to this for me: "This is Mrs [surname], [house number and
street], [mobile number]. Your engineer fitted my boiler on 3 March
and it has leaked twice. I want a refund of the $1,850 or I'm going
to review you everywhere."

After (same job, nothing identifying):

Draft a calm reply from a small plumbing firm to a customer whose
new boiler (fitted about three weeks ago) has leaked twice. She
wants a full refund and is threatening bad reviews. We will offer
a free inspection within 48 hours and a repair or replacement of
the faulty part at no cost. Don't promise a refund. Under 150 words.

The second prompt produces a better draft, because it tells the AI what the firm will actually offer, and the office manager adds the customer's name in the email client afterwards. Anonymising client data before you paste it into AI has more patterns, including how to handle spreadsheets.

Step 5: Make it safe to report a slip, and know what to do next

Someone will paste the wrong thing eventually. What matters is that you hear about it the same day. Put the no-blame promise in writing, and have a short routine ready so the response is calm and quick.

Picture a pharmacy where a dispenser pastes a list of 30 repeat-prescription customers, with names and medicines, into a free chatbot to turn it into a tidy collection rota. She tells the manager an hour later. A sensible response looks like this:

  1. Within the hour: the dispenser deletes the chat, and checks whether the account's model-training switch (in ChatGPT it sits under Data controls) was on. If it was, she turns it off.
  2. Same day: the manager writes down what was pasted, how many people it concerns, which tool and account, and the time. No names in the incident note beyond what is needed.
  3. Same day: the manager contacts the pharmacy's data-protection adviser to decide whether this must be reported and whether customers should be told. Reporting deadlines under data-protection law such as the GDPR can be short, so don't wait for a weekly meeting.
  4. Within the week: fix the cause. Here, the rota job moves into the approved tool with initials instead of names, or into a spreadsheet template that needs no AI at all.

Treat the dispenser who reported it as the person who helped, not the person who failed. The next slip will be reported only if this one was handled well.

Grey areas staff will ask about

  • "The client sent me their own spreadsheet and asked me to use AI on it." The client's permission covers them, not the other people in the file. Use the approved tool only, and remove columns you don't need before uploading.
  • "The AI button is inside Word, Canva or our email app." Built-in AI features send text to a vendor just like a chatbot does. Add the ones you allow to the green or amber list by name, and treat unknown ones as red.
  • "I dictated voice notes about a job and want them tidied up." Voice notes often contain names and addresses said out loud. Same rule: approved tool, and edit the names out of the transcript before asking for a summary.

Announce it in a message people will read

Staff respond better to a short note that starts with what they gain. Something like this works as an email or a pinned message:

Subject: Our AI tool, and one rule about client details

From today, please use [approved tool] for any AI help at work.
It's pinned in your browser and signed in with your work account.
Look for the green shield (Copilot) / our company name in the corner.

It's better than the free apps for our work: it has our price
list, templates and past letters loaded, and nothing you type is
used to train anyone's AI.

The one rule: no client names, contact details, health details or
payment details go into ANY AI tool. The one-page list is attached
and pinned by reception.

If you ever paste something you shouldn't have, tell me the same
day. You won't be in trouble for telling me. You would be for
hiding it.

Checking it has worked after 30 days

You don't need surveillance software to know whether the change stuck. Three checks are enough for a small team:

  • Usage in the approved tool. On Microsoft 365, the admin centre has a Copilot usage report showing active users over 7, 28, 90 or 180 days. If only two of nine staff show up after a month, the others are using something else.
  • An anonymous three-question check. "Which AI tools did you use for work last week?", "Did the approved tool do what you needed?", "What made you use something else?" The third answer tells you what to fix.
  • A look at real outputs. Ask two or three people to show you a recent piece of AI-assisted work and the prompt behind it. You'll spot missing anonymising faster this way than in any log.

How a nine-person hearing-aid shop closed the gap in a month

Take a hearing-aid shop with nine staff: three audiologists, four front-of-house staff and two repair technicians. This is an illustration, but the pattern is common. When the owner asked with a no-blame promise, five of the nine said they used free chatbots, mainly for referral letters to doctors, replies to complaints and reformatting hearing-test notes.

The shop was already on Microsoft 365 Business Standard, at $14 per user a month on annual billing, so Copilot Chat cost nothing extra. The audiologists wanted help with longer clinical letter templates, so the owner added two ChatGPT Business seats on annual billing at $20 each: $40 a month in total. Setup time looked like this:

TaskWhoTime
Write the traffic-light rule with shop examplesOwner and lead audiologist90 minutes
Pin Copilot Chat, block unapproved AI sites and extensions in ChromeOwner, following the admin help pages60 minutes
Build a shared Project with letter templates and the price listLead audiologist45 minutes
Team session: demo, rule, what to do after a slipEveryone30 minutes
30-day check: usage report plus three questionsOwner20 minutes

About four hours of staff time and $40 a month. At the 30-day check, the usage report showed eight of the nine staff active in Copilot Chat over the previous 28 days. The ninth, a technician, said he didn't use AI at all. One front-of-house member reported pasting a customer's full name and hearing results into a free app during week two, before the rule had sunk in; it was handled with the routine in Step 5, and her report is what prompted the owner to add "hearing test results" to the red list by name.

The lesson the owner drew was simple: the free apps lost because the approved tool had the shop's own templates in it, not because of the block list.

Where these controls backfire

A few approaches make shadow AI worse, and they are worth avoiding from the start.

  • Blocking everything with no replacement. Staff move to personal phones, where you have no controls at all, and stop telling you anything.
  • A twelve-page policy. Nobody reads it, so everyone is technically in breach and nobody knows the actual rule. Keep the one page and let the long version sit behind it.
  • Punishing the first person who reports. You will never hear about a slip again.
  • Forgetting the side routes. Browser extensions, meeting bots and AI features inside other apps (design tools, email add-ons) all send data out. List them when you write the rule.
  • Setting it and never checking. New free tools appear every month. Put a six-monthly review of the rule and the block list in the diary.

If you'd rather map your tools and data with someone before choosing a plan, that is part of what my AI implementation consultation covers. Either way, the order matters: a better approved tool first, the rule second, blocks third. Get that order right and most of the pasting stops by itself.

Shadow AI questions owners ask next

Is it enough to tell staff to switch off training in their free account?

It helps, but it does not solve the problem. The chats still sit in a personal account you cannot see, audit or delete when that person leaves, and the setting can be switched back on at any time. Treat the training switch as damage limitation for accidents, and move real client work into a business account the company controls.

Can I see which AI sites my staff have been using?

Partly. If you manage work browsers through Chrome Enterprise Core or a similar tool, you can apply policies and see some browser reporting, and many firewalls and DNS filters show which sites were visited. None of that covers personal phones. Asking directly, with a no-blame promise, usually tells you more than logs do.

Should contractors and locum staff follow the same rule?

Yes, and they are often the biggest gap because they bring their own tools and accounts. Put the one-page data rule in their onboarding pack, give them a seat on the approved tool for the length of the engagement if they handle client data, and remove the seat on their last day.

Do I have to report it if someone pasted client data into a free chatbot?

Possibly. Whether it counts as a reportable breach depends on what was pasted, how many people it concerns, the likely harm and the data-protection law that applies to you. Record the facts straight away, then ask your data-protection adviser or a solicitor, because some reporting deadlines are short and counted in days.

Further reads

Sources: OpenAI ChatGPT Business pricing and data controls; Anthropic Claude plans page; Microsoft Learn, Enterprise data protection in Microsoft 365 Copilot Chat; Google Chrome Enterprise Help, Allow or block access to websites; Chrome Enterprise Core product page; Microsoft 365 admin centre Copilot usage report documentation.

Want an approved AI setup your staff will actually use?

On a 1:1 call we'll look at which tools your team is really using, pick the business plan that fits the tools you run already, and draft the one-page data rule with you.

Book a 1:1 call with me