Glossary and Where to Start
Terms used across these notes, defined plainly, and the routes through the collection for the common situations.
Reference · Reference
Amnesty — the commitment that discovery findings carry no consequences. The thing that determines whether the answers are accurate.
The recommendations in “Glossary and Where to Start” become easier to sustain when implementation work has visible owners, dates and review time. Teams evaluating this implementation guide can use it to coordinate the operational side of AI adoption and identify where governance tasks are being missed, without treating activity data as evidence of misconduct or as a substitute for asking people why they chose a tool.
For an independent benchmark, compare the local approach with ICO guidance on AI and data protection; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.
Classification-based rule — a rule about what kind of information may go where, rather than about which tools are allowed. Survives tool change, which tool-based rules do not.
Client-side redaction — warning or blocking before content is sent, without transmitting it for inspection. Achieves the data protection purpose without creating a log of what people typed.
Embedded feature — AI capability arriving inside software you already approved. Invisible to network and endpoint discovery, and the fastest-growing category.
Register — a record of AI uses, not AI tools. One tool can be several entries.
Shadow AI — use of tools the organisation has not provided or approved. Better read as a measurement of the gap in provision than as misconduct.
Subprocessor — whoever else handles the data, including the model provider behind a vendor's interface. Rarely volunteered and frequently the party that matters.
Tolerated — in use, assessed as low risk, not formally approved. A category most organisations operate and few name.
Terms used loosely elsewhere
"Enterprise-grade" usually means a contract exists, not that the model differs. The capability is generally identical to the consumer tier.
"Zero data retention" means on their systems, for a defined scope. Check what it excludes.
"Privacy-preserving" means several different things. Ask what leaves the device and what the provider does with it.
And any percentage about shadow AI adoption comes from a survey commissioned by somebody selling controls.
Where to start
You suspect it is happening: finding what is already in use, then asking people directly.
You are about to ban something: why blanket bans do not work.
You have a policy nobody follows: writing a policy people will follow, then classification-based rules.
You are buying monitoring: what you can monitor technically, then prompt content.
Something went in: incidents.
The board is asking: sizing the risk honestly, then reporting to the board.
If you read only three
Why blanket bans do not work, because it determines the whole shape of the response.
Classification-based rules, because it is the only kind of rule that survives the tools changing.
And prompt content, because that line, once crossed, cannot be uncrossed.
A closing note
No products, suppliers or models are named here, deliberately. The field moves faster than any list, and every comparison online is written by somebody selling one of the options.
No adoption percentages, for the reason given above.
And nothing here is legal advice. Requirements in this area differ substantially by jurisdiction and sector, and are arriving quickly.
What the collection argues
Shadow AI is not misconduct but information: every instance says the task was hard enough that somebody went looking, and the approved route did not cover it.
A ban does not end the use. It ends the visibility, and moves the activity to personal devices and personal accounts where there are no logs, no contracts and no controls.
Write rules about information rather than about tools, because the categories change on a scale of years and the tools change on a scale of months.
And monitor the destination rather than the content — because a prompt is a draft, not a destination, and an organisation that reads them will be reading things people never meant to send to anybody.
The point
Every instance of shadow use says the task was hard enough that somebody went looking, and the approved route did not cover it..