tyler-smith.com · Questions & Answers

We suspect some of our team members are using personal AI accounts to write proposals and process internal client data because our official software deployment is moving too slowly. How do we stop this shadow IT risk without killing our employees' operational initiative?

When employees secretly use unauthorized personal accounts, it is usually a sign that your operational systems are too slow or restrictive. Do not respond with a heavy-handed ban that kills innovation. Instead, address this risk head-on by bringing it to your weekly Level 10 Meeting and using the IDS process to find a permanent solution.

First, make it clear to the team that processing client data on personal accounts violates client confidentiality and exposes the firm to severe security risks. However, you must offer an immediate alternative. Give your team access to secure, company-approved corporate accounts with enterprise-level data privacy controls. These accounts ensure that any data entered into the system remains private and is not used to train public models.

Next, establish a simple, one-page usage policy inside your operating manual. This policy should specify that while AI can be used to brainstorm ideas or draft initial outlines, a human must always review and edit the final output. The employee in that seat remains fully accountable for the accuracy of the work. By providing the right tools and setting clear boundaries, you eliminate the security risk while helping your team work faster.

Category: AI-Powered Operations

← All questions