Skip to main content
AI GovernanceComplianceCybersecurityMicrosoft 365Los Angeles

Shadow AI at Work: The AI Use Policy California Businesses Need

· By Ashkaan Hassan

The Question Owners Are Actually Asking

The question that lands on our desk almost every week now is not “should we adopt AI.” That decision made itself. It is: our people are already using AI tools we never approved — what do we do about it this quarter?

That is a different and much more urgent problem. Adopting AI is a strategy conversation you can schedule. Unapproved AI is an active data-handling issue with regulatory, contractual, and insurance consequences, and it is accumulating exposure every day you leave it alone.

This post walks the actual decision: the four options on the table, what California law already requires of you today, where your prompts physically go under each option, the clauses a policy needs to survive a client audit or a carrier’s questionnaire, and how to enforce the policy with controls instead of hope. It is written for the Southern California businesses we work with most — law firms, entertainment companies, and professional services shops where confidentiality is the product.

What Shadow AI Actually Looks Like Inside Your Business

“Shadow AI” sounds abstract until you inventory it. In a typical professional-services office it looks like this:

  • A paralegal pastes three pages of a deal memo into a free chatbot to get a plain-English summary before a client call.
  • A producer’s assistant uploads an unreleased script to a consumer transcription or summarization service to pull a scene list.
  • A bookkeeper drops a client-provided bank statement into an AI spreadsheet tool to reconcile it faster.
  • A business development lead connects an AI notetaker to their calendar. It now silently joins client calls and stores recordings and transcripts in an account you have never seen, under a personal email address.
  • Someone installs a browser extension that promises “AI everywhere,” granting it read access to every page they visit — including your practice management system and your Microsoft 365 mailbox in the browser.

None of these people are doing anything malicious. Every one of them is trying to do their job faster. And every one of these actions moves client-confidential material outside your control, usually into a consumer account you do not own, cannot audit, cannot legally hold, and cannot produce from in a dispute.

The scale is not speculative. IBM’s Cost of a Data Breach Report 2025 found that roughly one in five organizations reported a breach connected to shadow AI, and that 97% of organizations reporting an AI-related security incident lacked proper AI access controls. That second number is the real story: the failure mode is not exotic model attacks, it is nobody governing who can connect what to which data.

The cost context matters too. The same report puts the global average breach cost at $4.44 million, with the United States average at a record $10.22 million — the highest of any region studied.

The Third-Party Angle LA Firms Keep Missing

Every AI tool your team signs up for is a new vendor relationship you did not vet, contract with, or add to your vendor inventory. That matters because third parties have become one of the fastest-growing breach vectors: Verizon’s 2025 Data Breach Investigations Report found third-party involvement in breaches doubled year over year, appearing in 30% of breaches versus 15% the prior year.

For Los Angeles entertainment and legal clients this compounds. Studio and network vendor agreements routinely impose specific confidentiality, subcontractor-disclosure, and information-security obligations. An AI notetaker that a coordinator connected on their own is, contractually, an undisclosed subprocessor handling protected material. When the studio’s security questionnaire asks you to list every third party that touches their content, the honest answer has to include tools nobody in management knew existed.

The same logic applies to law firms with outside counsel guidelines, accounting firms with engagement-letter confidentiality terms, and any business with a cyber policy that asked whether you maintain an approved-software inventory.

The Four Options on the Table

There are really only four postures. Most businesses drift into the worst one by default.

OptionWhere your data goesAdmin visibility & controlCompliance defensibilityRealistic adoptionBest fit
Do nothing (status quo)Consumer accounts you do not own; retention and training terms vary by tool and change without noticeNone. No inventory, no logs, no offboardingWeakest. You cannot answer a client audit or carrier questionnaire truthfullyHigh usage, zero controlNobody. This is the option you are choosing by not choosing
Blanket banOfficially nowhere; in practice, to personal phones and home devicesPoor. Blocking at the network pushes usage off-network where you see nothingLooks strong on paper, fails on evidence — you cannot prove a negativeLow compliance, high resentmentShort-term stopgap during an active incident or a hard contractual freeze
Consumer tools + written policyVendor-controlled consumer tenancy; protections depend on the user picking the right settingsLimited. Some visibility via endpoint and browser controls, little inside the toolModerate — a policy without enforcement is a document, not a controlGood, because people keep the tools they likeVery small teams with low-sensitivity data and tight budgets
Enterprise-licensed AI in your own tenantInside your organization’s service boundary, under your identity, retention, and eDiscovery controlsStrong. Admin center, audit logs, conditional access, data loss prevention, license-level on/offStrongest. You can produce logs, policies, and a vendor list on demandHighest, if you actually train peopleMost professional-services firms handling client-confidential material

The fourth option is where most of our clients land, and the reason is not that enterprise AI is smarter. It is that enterprise AI is governable. When AI runs under your organizational identity — in Microsoft 365, for example — Microsoft documents that Copilot prompts and responses stay within your service boundary and are not used to train the foundation models, and the activity is subject to the same retention, audit, and eDiscovery machinery as the rest of your tenant. That is the difference between an AI answer you can defend and one you cannot explain.

On the cost side, the honest framing is qualitative: a ban has the lowest visible line item and the highest hidden risk; enterprise licensing converts unpredictable, per-incident exposure into a predictable, budgeted operating cost with controls attached. That trade — unpredictable to predictable — is the same one that makes managed IT worth it in the first place.

What California Law Already Requires of You

A lot of coverage about AI regulation is about frontier model developers. That is not you, and those obligations mostly do not apply to a fifty-person firm in Century City. But several California requirements land squarely on ordinary businesses, and they are already in motion.

Automated decisionmaking technology under the CCPA. The California Privacy Protection Agency’s updated CCPA regulations extend consumer rights into automated decisionmaking, with obligations including pre-use notice, opt-out rights, and risk assessments for businesses that use ADMT to make significant decisions about Californians — think hiring, promotion, lending, or housing. The regulations phase in on a defined schedule, with ADMT compliance required by January 1, 2027, and risk-assessment obligations attaching to processing conducted in the interim. Read the current text and timeline on the CPPA’s regulations page rather than relying on summaries — this package has moved.

Automated decision systems in employment. California’s Civil Rights Council adopted regulations making clear that using automated-decision systems in hiring and other employment decisions does not shield an employer from FEHA liability, with recordkeeping obligations attached. They took effect October 1, 2025. If your recruiter is using an AI resume screener, you are the responsible party, not the vendor. Details are published by the California Civil Rights Council.

Breach notification still applies, AI or not. If confidential personal information walks out through an AI tool, California’s breach notification duties do not care what the vector was. Businesses must notify affected Californians and, where a single breach affects more than 500 California residents, submit a sample copy of the notice to the Attorney General, per the California DOJ’s breach reporting requirements. Those submissions are published publicly.

Existing law is the floor, not the ceiling. Unfair competition, false advertising, civil rights, and professional responsibility rules all apply to AI-assisted conduct without any new statute. Lawyers in particular carry unchanged duties of competence, confidentiality, supervision, and candor when using generative tools — an AI hallucination in a filing is a sanctionable event attributed to the attorney, not the model.

Where Your Prompts Actually Go

Before you write a policy, get precise about the mechanics, because “the AI keeps your data” is too crude to be useful.

Three things vary by tool and by plan tier:

  1. Training use. Does the provider use your inputs to improve models? Consumer tiers frequently do by default and offer an opt-out buried in settings. Business and enterprise tiers typically do not. This is a per-product, per-tier question — verify it in the vendor’s documentation, not in a blog post.
  2. Retention. Even when data is not used for training, prompts and outputs are usually retained for some period for abuse monitoring. Ask how long, who can access it, and whether retention is configurable.
  3. Tenancy and identity. Is the account owned by your organization or by the employee? This is the one that bites hardest. When a staffer leaves, an organization-owned account is offboarded with everything else. A personal account walks out the door with your client’s material still in its history, and you have no legal hook to retrieve it.

For risk framing, the NIST AI Risk Management Framework is the most useful free structure available. Its four core functions — Govern, Map, Measure, Manage — give you a defensible skeleton, and “Map” is the one businesses skip. You cannot govern an inventory you have never taken.

The Policy: Clauses That Actually Matter

Most AI policies we are handed to review are one page of aspiration. Here is what a policy needs to be usable by an employee at 4:45 p.m. on a deadline, and defensible to a client’s auditor:

  1. An approved tools list, by name. Not “approved enterprise tools.” The actual product names, and the actual tiers. Everything not on the list is unapproved until reviewed. Include a named person who can add to the list and a turnaround expectation for requests, or people will route around it.
  2. A data classification tier tied to permitted use. Three tiers is plenty: public/internal, confidential (client work product, contracts, personnel files), and restricted (privileged material, unreleased content under NDA, regulated personal data, credentials). State plainly which tier may go into which tool. Vague standards get resolved in favor of whatever is fastest.
  3. The human-review requirement, scoped. “A qualified person reviews AI output before it goes to a client, court, counterparty, or the public.” Name the accountable role. Add explicit citation-verification language for anything legal or factual.
  4. A meeting-recording and notetaker rule. This is the single most common real-world violation in Los Angeles offices. Cover consent, which tool is permitted, where recordings are stored, and how long they are kept. California is a two-party consent state for confidential communications — an AI notetaker that joins silently is a legal problem before it is an IT problem.
  5. A no-personal-accounts rule for work data. Work AI happens under your organizational identity. Full stop. This is what makes offboarding, audit, and eDiscovery possible.
  6. Client and contractual constraints. Some outside counsel guidelines and studio vendor agreements restrict AI processing or require disclosure. The policy should require checking engagement terms before using AI on that client’s matter, and name where those terms live.
  7. A disclosure standard. When you tell clients AI was involved, and in what work product. Decide it once, in writing.
  8. Prohibited uses, enumerated. Employment screening decisions without review, anything touching regulated personal data outside approved systems, generating likenesses or voices of real people without cleared rights, and feeding credentials or security configurations into any model.
  9. A safe-harbor reporting clause. If someone pasted something they shouldn’t have, you need to hear about it in an hour, not a quarter. Say explicitly that prompt self-reporting will not be punished. Without this clause, your incident response starts weeks late.
  10. Review cadence and version date. AI tooling changes monthly. A policy with no review date is stale on arrival.

Enforce It With Controls, Not Trust

A policy nobody can violate accidentally beats a policy everybody has signed. The technical layer, roughly in order of return:

  • Identity first. Require organizational sign-in for approved AI tools via your identity provider, and use conditional access to block access from unmanaged devices. If AI is only reachable through a managed identity on a managed device, most shadow AI dies quietly.
  • Discover before you block. Pull the actual list of AI services in use from your cloud access and endpoint telemetry. You will find tools nobody mentioned in the survey. Discovery informs which tools to sanction, not just which to kill.
  • Audit OAuth grants. In Microsoft Entra ID, review third-party application consents and turn off unrestricted user consent to unverified publishers. That browser extension “with AI” is usually an OAuth grant against your tenant, and it is the quietest hole in most Microsoft 365 environments.
  • Turn on data loss prevention for the paths that matter. Sensitivity labels on client matter folders, DLP policies that catch client identifiers and regulated data heading into browser uploads, and endpoint controls on copy/paste into unapproved sites.
  • Fix permissions before you deploy enterprise AI. This is the step people skip and regret. Tenant-wide AI assistants surface anything a user already has access to — so an overshared SharePoint site that was harmless when nobody could find it becomes a search result. Run a permissions and oversharing remediation pass before rollout, not after the first awkward discovery.
  • Log it. Ensure AI activity lands in your audit log with sufficient retention. When a client asks what happened, “we have logs” is the entire difference between an inconvenience and a crisis.

A Realistic Rollout for a Southern California Business

Week one — discover. Inventory AI usage from telemetry and a short, blame-free staff survey. Pull the OAuth grant list. Identify the three workflows people are actually using AI for; those are your real requirements.

Week two — decide and document. Pick the posture from the table above. Draft the policy with the clauses above, sized to your business. Check your cyber insurance application and your top client contracts for language you must align to.

Week three — configure. Stand up the approved tooling under organizational identity, run the permissions remediation, enable conditional access and DLP, and set logging retention. Block the specific unapproved tools that carry real exposure — not the entire category, which just relocates the problem to personal phones.

Week four — train and launch. Twenty-five minutes of live training beats a signed PDF. Show two real examples of good use and two of policy-violating use drawn from your own workflows. Publish the request path for new tools and answer the first requests fast enough that people believe it works.

Then review quarterly. Approved-tool lists rot faster than any other document in your IT program.

How to Tell If It Is Working

Measure four things, and be honest about them:

  • Coverage: the share of AI activity in your telemetry that runs through approved, organizationally-owned accounts. This should climb steadily. If it doesn’t, your approved tools are too slow or too locked down and people are routing around them.
  • Request throughput: how long it takes to get a new tool reviewed. Slow review is the primary cause of shadow AI, not employee indifference.
  • Self-reports: you want more of these in the first quarter, not fewer. Zero reports means the safe-harbor clause isn’t believed.
  • Audit readiness: can you produce, within a business day, your approved tool list, your policy with a version date, your AI-related audit logs, and evidence of training? That bundle is what a client auditor, an insurance carrier, and a regulator all ask for — and it is the concrete deliverable that turns “we take AI seriously” into something you can prove.

The businesses that get this right are not the ones with the strictest rules. They are the ones where the fast path and the safe path are the same path.

We Solve Problems runs AI and IT for businesses across Los Angeles and nationwide — managed IT, cybersecurity, and Microsoft 365 on one side, and AI operations that find the manual work in your business and automate it safely on the other. We do this work daily for entertainment and professional-services firms where confidentiality is the whole business, which means we handle the unglamorous parts first: the permissions cleanup, the OAuth audit, the policy that survives a client questionnaire, and the training that makes people actually use the approved path. If your team is already using AI and nobody owns the governance, request a consultation and we will start with the discovery step — you cannot govern what you have not mapped.