Answers
How do you stop staff putting company data into AI tools with no oversight?
Zachary King, Cofounder and CEO at Works · LinkedIn
Short answer
Not with a policy memo. Staff paste company data into personal chatbots because it works. Ban it and they'll carry on from phones and personal accounts, which is worse. Give them approved tools on business accounts, loaded with context that makes them better than the workaround. Then fix permissions properly, with scoped access.
Do this week
Survey what your team actually uses. No punishment, no shame. That list is where working governance starts.
Transcript
How do you stop staff putting company data into AI tools with no oversight?
This is called shadow AI. And you don't stop shadow AI with a policy memo. You give people a sanctioned path that's better than their workaround.
People paste company data into their private chatbots because it works. It's useful. It's a great tool. If you ban it, they'll just keep doing it on their phones, doing it from their personal accounts, and that's even worse. Give them approved tools on business accounts, loaded with the context that makes it genuinely better than using their own personal ChatGPT account.
Then fix permissions properly. A prompt telling the AI to behave is not a permission model, I'm afraid. Scoped access is. Each tool and each agent gets its own credentials, so your existing systems log exactly what was touched, by who and when. That's how we set up every client: sanctioned tools that people actually prefer, and access narrow enough that your audit trail can see who touched what and when.
This week, survey what your team is actually using. No punishment, no shame, because you need to know the truth. That list is where working governance starts.
Want this built inside your business?
Tell us where the work piles up. We will show you what it takes to ship it.
Let's talk →