Shadow AI at Work: A Governance Playbook for LA Businesses
The Decision You Are Actually Making
Most owners think the question is “should we adopt AI?” It isn’t. Your staff adopted AI months ago. Verizon’s 2025 Data Breach Investigations Report found that 15% of employees were routinely accessing generative AI systems on their corporate devices, and that a majority of them were signed in with personal, non-corporate accounts. That means the data is already leaving — it is just leaving through a door you don’t control and can’t audit.
So the real decision is narrower and more useful: do you block AI, tolerate unmanaged AI, or sanction a governed AI environment your people actually prefer to the unmanaged one? Every other AI question — Copilot vs. a standalone enterprise subscription, which department goes first, what the policy says — hangs off that one choice.
This post walks the decision the way we walk it with Southern California clients: what shadow AI costs when it goes wrong, the four postures and their real tradeoffs, what California law will require of you, the specific technical controls that do the enforcement, and a phased rollout that doesn’t stall in committee.
What Shadow AI Actually Costs When It Goes Wrong
The abstract risk becomes concrete fast. IBM’s 2025 Cost of a Data Breach Report put the global average cost of a breach at $4.44 million and isolated shadow AI as its own cost driver: organizations with high levels of shadow AI saw measurably higher breach costs than organizations with little or none, a meaningful share of breached organizations reported an incident involving shadow AI, and — the most damning finding for a small business — nearly every organization that suffered an AI-related security incident lacked proper AI access controls.
That last point is the whole argument. The failure mode is almost never a sophisticated attack on a model. It is an ungoverned account, an unmanaged browser session, and no visibility into what was pasted where.
And the exposure isn’t only breach cost. For a Los Angeles professional-services firm, the realistic damage list looks like this:
- Confidentiality breach. A paralegal pastes a draft settlement agreement into a consumer chatbot to “clean up the language.” That is now a disclosure question, not an IT question.
- NDA violation. An assistant summarizes an unreleased project’s deal memo. The NDA governing that project does not have an exception for productivity tools.
- Client-contract breach. Enterprise clients increasingly include AI-use and subprocessor clauses in their vendor agreements. Unsanctioned AI use can breach a contract you already signed.
- Discovery and audit exposure. You cannot produce, hold, or defend records that live in an employee’s personal chatbot history.
- Wrong answers, confidently delivered. Ungoverned AI produces unreviewed work product with no citation trail.
None of those get solved by a memo. They get solved by where the account lives and what controls wrap it.
The Four Postures, Compared
There are only four real positions. Pick deliberately.
| Posture | Data exposure | Employee behavior | Audit & eDiscovery | Admin burden | Best fit |
|---|---|---|---|---|---|
| Hard block (network + DNS filtering, no AI allowed) | Low on managed devices; unchanged on personal phones | Drives use to personal devices — the least visible channel | Nothing to audit, but nothing to prove either | Low to set up, high to police | Regulated workloads with a genuine prohibition; short-term stopgap only |
| Ignore it (status quo, no policy, no controls) | Highest — consumer accounts, personal logins, no retention control | Widespread, invisible, inconsistent | None. Prompts and outputs are unrecoverable | None until an incident, then enormous | No one. This is the posture IBM’s shadow-AI cost premium is measuring |
| Sanctioned AI inside your Microsoft 365 tenant (Copilot governed by Entra + Purview) | Lower — data stays under tenant identity, labels, and retention | High adoption because it works inside Outlook, Teams, Word | Prompts and responses are discoverable and retainable | Moderate; requires permissions cleanup first | Most SMBs and professional-services firms already standardized on Microsoft 365 |
| Standalone enterprise AI subscription (business-tier account from a major AI vendor, SSO-connected) | Lower — but data governance lives in a second console | High adoption; often stronger raw model capability | Depends entirely on the vendor’s admin and export features | Moderate; a second identity and DLP surface to manage | Teams doing heavy analysis or engineering work outside the Office surface |
The two right-hand postures are not mutually exclusive, and for many firms the honest answer is both: Copilot for document- and email-adjacent work, one sanctioned standalone tool for the handful of power users who need it. What matters is that both are connected to your identity provider and neither is a personal login.
The hard block deserves one warning. Blocking works only for the device and network you control. In a city where much of the workforce is hybrid and everyone has a phone, a block without a sanctioned alternative reliably produces the ignore posture with extra steps — the usage moves off-network and out of sight. Use a block to buy time while you stand up the sanctioned path, not as the destination.
What California Law Will Actually Require of You
California is out ahead of the rest of the country, and the deadlines are close enough to plan against.
AB 2013, the Generative AI Training Data Transparency Act, took effect January 1, 2026 and requires developers of generative AI systems made available to Californians to publish documentation about their training datasets. You are almost certainly not a “developer” under this law — but it changes your diligence. Vendor training-data disclosures are now a document you can ask for and read before you sign.
SB 942, the California AI Transparency Act, targets large consumer-facing platforms via a monthly-user threshold, so most Southern California SMBs fall outside its “covered provider” definition. Relevant if you build a public AI feature; not relevant if you merely use one.
The CPPA’s automated decisionmaking technology (ADMT) regulations are the ones that bite. Under the finalized CCPA regulations, businesses using ADMT to make significant decisions about Californians — hiring, promotion, compensation, allocation of work — face a compliance deadline of January 1, 2027, along with new risk-assessment and cybersecurity-audit obligations phasing in on their own schedules. If anyone in your HR stack is using AI to screen resumes or rank candidates, that is an ADMT question and it belongs on your near-term roadmap, not your eleventh-hour panic list.
For law firms specifically, the State Bar of California has issued practical guidance on generative AI in the practice of law, which ties AI use directly to the duties of confidentiality and competence. The operative point: entering client confidential information into a generative AI tool that lacks adequate confidentiality protections implicates Rule 1.6. “The tool was convenient” is not a defense.
Finally, if you want a defensible framework rather than a pile of rules, use the NIST AI Risk Management Framework. Its core functions — Govern, Map, Measure, Manage — give you a structure auditors, insurers, and enterprise clients already recognize, which matters more than any bespoke policy you write from scratch.
The Technical Controls That Do the Real Work
Policy sets expectations. Controls set outcomes. If you are on Microsoft 365 — as most of our Southern California clients are — here is the actual stack, in the order it should be built.
Fix permissions before you turn on AI. This is the step everyone skips and everyone regrets. Copilot respects existing permissions, which means it will faithfully surface the HR folder that has been shared with “Everyone except external users” for years. Run SharePoint Advanced Management or an access review, kill org-wide sharing links, and clean up over-permissioned sites first. AI does not create the oversharing problem; it makes it instantly searchable.
Anchor everything to identity. Enforce SSO and conditional access on every sanctioned AI tool through Microsoft Entra ID. Require managed or compliant devices for access. Block personal-account sign-in to AI apps on corporate devices. If a tool cannot be put behind your identity provider, it is not a sanctioned tool.
Apply sensitivity labels and DLP. Microsoft Purview lets you label client matter files, deal documents, and financials, then write data loss prevention policies that stop labeled content from being pasted into unapproved browser destinations. Endpoint DLP covers the paste-into-a-browser path that traditional email DLP misses entirely — and that path is exactly how shadow AI leaks.
Set retention deliberately. Copilot prompts and responses are stored in the user’s mailbox and are subject to retention policies, eDiscovery, and legal hold. Decide the retention period on purpose. For litigation-exposed firms, that decision belongs to counsel, not to IT.
Understand the data boundary. Microsoft’s documentation is explicit that Microsoft 365 Copilot does not use your tenant’s business data to train the underlying foundation models, and that prompts and responses stay within the service boundary. Consumer chatbots on personal accounts frequently make the opposite default choice. That single distinction is the strongest argument you have for moving people onto the sanctioned path.
Cover the endpoint. Microsoft Defender for Business is built for small and midsize organizations and is bundled into Microsoft 365 Business Premium alongside Entra ID P1 and Purview capabilities. A large share of the AI governance stack is already sitting in a license many LA firms own and have never configured. Before you buy anything new, find out what you are already entitled to.
Discover what is already in use. Turn on cloud app discovery and pull the report. Nearly every organization we assess is surprised by AI tools in active use that leadership had never heard of. You cannot govern an inventory you have not taken.
Writing an AI Policy People Will Actually Follow
Most AI policies fail because they are written as prohibitions against a tool people find genuinely useful. A policy that fights productivity loses. Write yours around four questions instead:
Which tools are approved? Name them explicitly. “Approved AI tools are X and Y, accessed through your company account.” A named list beats a category description, because employees do not classify tools the way policies do.
What data can go in? Use a tiered rule tied to your sensitivity labels, not to vague adjectives. Public and internal content: fine. Client-confidential, matter-specific, NDA-covered, personal information, financial records, credentials: only in the sanctioned environment, and for some categories, not at all. Give concrete examples from your actual business — a redlined agreement, a cast list, a P&L — because that is what makes it stick.
Who reviews the output? Require that a human owns every AI-assisted deliverable that leaves the building. The person who sends it is accountable for it. No exceptions for “it was just a summary.”
What gets disclosed? Decide in advance whether AI assistance is disclosed to clients, and check your existing client agreements and vendor contracts for clauses that already answer this. Many enterprise MSAs signed in recent years contain AI provisions the signer has forgotten about.
Then pair the policy with training. Breach investigations consistently find the human element central to most incidents, and AI governance is squarely a human-element problem. A short, specific, example-driven training session beats a long document nobody opens.
Special Cases: Entertainment, Talent, and Anything Under NDA
If you are an entertainment-law firm, a production company, a management or talent shop, or a post house, your AI risk profile is not the generic SMB profile. Three things are different.
Your NDAs are the binding constraint, not your policy. Unreleased titles, casting decisions, deal terms, and dailies are covered by agreements that predate anyone’s AI policy and contain no carve-out for productivity tools. The safe assumption is that pasting covered material into any third-party system is a disclosure until your counsel says otherwise in writing.
Guild and vendor agreements increasingly carry explicit AI provisions. Consent, credit, and notification terms around AI-generated or AI-assisted material now appear routinely in production and talent agreements. Your IT controls need to be able to demonstrate compliance, which in practice means retained logs and per-matter access boundaries — not just a policy PDF.
Access boundaries beat blanket rules. In a firm handling multiple studios or competing talent, the meaningful control is that AI cannot retrieve across matters it shouldn’t. That is a permissions architecture problem inside SharePoint and Teams, solved with properly scoped sites, sensitivity labels, and restricted search scopes. It is unglamorous work, and it is the single highest-value thing an entertainment-adjacent firm can do before enabling AI.
A Rollout That Doesn’t Stall
Run it in three phases. Do not compress them.
Phase one — see the ground truth. Pull a cloud app discovery report to inventory AI tools already in use. Run an access review on your top file repositories and remediate org-wide and anonymous sharing links. Inventory your licenses to learn which governance capabilities you already own. Ask your leadership team, without blame, what they are actually using and why — the “why” tells you which use cases the sanctioned tool must cover to win.
Phase two — build the sanctioned path. Stand up the approved tool behind SSO and conditional access. Deploy sensitivity labels to your highest-risk content and write endpoint DLP rules for the paste-to-browser path. Set retention on AI prompts and responses in consultation with counsel. Pilot with a small, motivated group — usually operations and marketing, not your most sensitive practice area — and collect real use cases.
Phase three — publish, train, enforce. Release the policy, deliver short training built on the pilot group’s actual examples, then turn on blocking for unsanctioned consumer AI on managed devices. Enforcement last, and only once the sanctioned alternative genuinely works. Reversing that order is why AI policies get ignored.
Then review quarterly. This category is changing faster than your annual policy cycle, and the CPPA’s deadline will arrive on schedule regardless of your calendar.
How to Tell Whether Your IT Provider Is Ready for This
The MSP market is repositioning hard around AI right now, and the marketing has outrun the delivery in many cases. A few questions separate the two:
- “Can you show me every AI tool currently in use across our environment?” If they cannot produce a discovery report, they have no visibility, and everything else is theory.
- “What will Copilot surface that shouldn’t be surfaced?” A ready provider answers with a permissions and oversharing assessment. An unready one answers with a feature list.
- “Where do our AI prompts live, and how long are they retained?” The right answer references mailbox storage, retention policies, and eDiscovery — and asks who your counsel is.
- “Which governance capabilities are already in the licenses we hold?” A provider whose first move is to sell you new licenses before auditing your existing entitlements is optimizing for the wrong thing.
- “How does this map to our compliance obligations?” Look for specific references to the CCPA regulations, your industry’s confidentiality rules, and a recognized framework like NIST’s — not a generic assurance that they “take security seriously.”
The underlying test is whether your provider treats AI as a governance problem attached to your identity and data estate, or as a product to resell. Only one of those survives an incident.
We Solve Problems is a Los Angeles managed IT services provider that helps Southern California businesses — with particular depth in entertainment law and professional services — get AI governance right before it becomes an incident. We assess what is already in use, clean up the permissions and oversharing that AI would otherwise expose, configure the Microsoft 365 security and compliance controls you may already be licensed for, and put a policy in place that your team will actually follow. If your staff is using AI and you cannot yet see it, start a conversation with us — the discovery step alone usually changes the plan.