In many companies, AI arrived without a project, budget or formal decision. Employees opened their own accounts and began using ChatGPT, Gemini and similar tools for emails, spreadsheet analysis and document preparation. The tools may be useful, but when nobody knows which services are in use or which data is being entered, the organisation has a Shadow AI problem.
Employee curiosity is not the main issue. Business data can end up in private accounts, services without a company agreement or conversations the company cannot access later. A complete ban usually pushes usage further into the shadows. A short and understandable AI policy is more practical.
Data that should not be entered into unapproved AI tools
Contracts, client records, health information, payroll, bank statements, passwords, API keys and complete internal databases should not be copied into unapproved services. The same applies to supplier documents marked confidential or containing personal information.
Even when an employee only wants help rewriting a paragraph, the complete document may contain much more information than the task requires. Remove names, amounts, addresses and other identifiers, or use an approved business AI account with suitable controls.
Create a short list of approved tools
A business does not need to approve ten different platforms. One or two managed services with business accounts, administrative control and clear rules may be enough. Employees then know where they can work, while IT can require MFA, manage users and remove access when someone leaves.

The policy should also list approved uses: generating ideas, summarising public information, drafting a procedure or analysing anonymised data. Practical examples are more useful than a thirty-page policy that nobody reads.
Every AI result needs a responsible owner
AI-generated text is not automatically accurate. Proposals, technical instructions, legal documents and client-facing information must be reviewed by a responsible person. A simple rule works well: the person using the result is responsible for reviewing it before it is sent or published.
Review is particularly important when an AI tool combines information from several documents. A misread date, amount or contract condition can sound convincing and still create a serious business problem.
Include AI accounts in onboarding and offboarding
A private employee AI account should not become the only place where important instructions, project history or business workflows exist. The process must remain available to the company. Business AI accounts should be documented, protected with MFA and included in employee onboarding and offboarding procedures.

Large vendors increasingly treat AI agents as separate digital identities that need an owner, restricted permissions and an expiry date. A small business can apply a simpler version of the same principle: every tool and automation needs a responsible person.
Keep the policy short enough to use
A practical AI policy can fit on one or two pages. It should answer five questions: which tools are approved, which data is prohibited, when anonymisation is required, who checks the result and where an employee reports an error or suspicious incident.
NBG TEAM helps businesses organise user accounts, Microsoft 365 and Google Workspace access, device security and practical rules for AI tools. The purpose is not to slow employees down. It is to prevent useful technology from becoming an invisible route for company data to leave the business.
Sources and further reading
For help with your specific business environment, see our business IT support service.



