An IT manager posted a question at the end of July 2026 that drew 142 upvotes and 226 replies: employees are using ChatGPT and other AI tools, IT has no visibility, and legal is unhappy. Blocking it hurts people who are genuinely working faster.
The replies are the most useful public record of how this is being handled right now, because they come from people running it rather than selling it. They also disagree sharply, and the disagreement is more instructive than any single answer.
Three things in that thread deserve wider attention: a failure pattern that recurred independently three times, the reason most organisations are stuck that has nothing to do with technology, and a question nobody could answer.
What is shadow AI?
Shadow AI is employees using AI tools the organisation has not approved, on work data. It is the same shape as shadow IT a decade ago, with one difference that changes the risk: the failure mode is not an unsanctioned app sitting on a laptop, it is customer records, source code or contract text pasted into a service the company has no agreement with.
The original poster framed the tension precisely. It is hard to block without damaging productivity, because the people doing it are using the tools to do good work.
The most-supported answer is block first, then sanction
The top reply, at 132 points, argues for blocking everything, then granting approved access to chosen services on paid enterprise accounts with logging and granular controls. Train staff, tell them explicitly that uploading company data to unapproved systems is prohibited, and accept that all of it depends on leadership being willing to back it.
Several practitioners describe exactly that in production. One deployed a proxy alongside Microsoft Purview and Defender, restricting access to a single vendor's enterprise account locked to domain-joined devices through Entra single sign-on. Another scanned the environment with Microsoft Defender to discover which AI tools were in use, tagged everything unapproved, and blocked it, describing the effect on ungoverned use as immediate. They also report a significant rise in helpdesk tickets in the weeks that followed.
The strongest version of this argument is not really about blocking. It is that a blocked tool with no sanctioned alternative just moves the problem, so the block only works when it arrives with a licensed, trained, genuinely usable replacement.
The most-repeated objection is that blocking moves the problem
A dozen contributors made the same point independently: a full block does not remove the behaviour, it removes your visibility of it.
One described a company that provided a monitored corporate ChatGPT; staff moved to a different machine and reported that they did not use AI. Another pointed out that no network control reaches a personal phone, where a camera and an assistant app will move a document out of the building without touching your network at all. A third noted the quieter version: signing into a note-taking app on both a work and personal machine turns copy-paste into something that looks like note-taking.
The most concrete data point on this came from an organisation that tried a full block and abandoned it after roughly 72 hours, once department heads escalated it to senior leadership.
The counter-proposal that recurs is to treat it as data classification rather than tool permission. Identify the handful of flows where exposure is genuinely material, customer records, source code, contracts, anything under a data processing agreement, and write rules for those rather than for a website. One contributor added the metric that matters: not how many AI domains you blocked, but how much activity moved into the sanctioned tenant.
The pattern nobody is talking about: the sanctioned tool gets rejected
Three organisations described the same sequence independently, and it undermines the tidy version of the block-and-sanction plan.
Block the consumer tools. Buy the safe corporate option. Users find it materially worse than what they were using. Shadow use resumes.
In one case the progression was explicit: ChatGPT blocked, Microsoft Copilot provided, staff complained it was not good enough, and the organisation ended up buying enterprise licences for a different vendor instead. Another reported buying Copilot enterprise and still finding people on personal accounts because they rated the alternative higher. A third put it flatly: even when you give people tools, they want a specific model, and they will work around you to get it.
This matters because the sanctioned-alternative strategy is the one almost everyone recommends, and it fails quietly when the sanctioned tool is chosen for procurement convenience rather than for whether people will actually use it. The lesson is uncomfortable for anyone whose AI strategy is "we already pay for it": if the approved path is slower or worse than the unapproved one, you have not built a path, you have built a detour.
The real blocker is that nobody wants to sign
The most quoted-back comment in the thread has nothing to do with technology. An IT manager described blocking for a fortnight, watching tickets pile up from people who said they could not do their jobs, and ending up in a middle ground where AI is technically permitted because nobody will sign an official policy, since signing means owning the risk.
That is the actual state of play in a large number of organisations, and it produced the thread's sharpest disagreement.
One side argues that until the business writes and enforces a policy, this is not IT's problem: IT can monitor, but enforcement and consequences come from above, and a policy written by IT alone will be circumvented because IT does not know what every department needs.
The other side argues that many IT managers own governance, risk and compliance for technology, so it demonstrably is their problem, and that answering "how do I solve this" with "someone else should" is not leadership.
The most useful resolution came from a third contributor, who separated "not my problem" from "not my place": it is IT's job to advise leadership on the risk and let them decide; if they decide a policy is needed, IT drafts it within company governance and leadership communicates it; if they decide no policy is needed, that is documented accepted risk, and only at that point does it stop being IT's problem.
That framing is worth adopting because it gives an IT manager a defensible position either way, and it converts an argument about ownership into a decision someone has to record.
The question nobody answered
One contributor asked what everyone is doing about the fact that ordinary Google Search now has AI built into it.
The thread moved on. Nobody had an answer.
It is the most important question in it. Every control described above assumes AI is a destination you can allow or deny: a site, an app, a subscription. When the search box is an AI interface, and when already-approved platforms quietly add AI features, the category itself stops being a place you can block.
One person running a third-party monitoring platform described exactly this: the hard part was not ChatGPT, Claude and Gemini, which are easy to find. It was that tools already approved and in the environment had added AI sub-services, and working out what was using what became the real project.
What tooling do people actually name?
The thread names a lot of products. Grouped by what they do, and reported as practitioner mentions rather than as recommendations:
| Category | Named in the thread |
|---|---|
| Discovery, which AI is in use | Microsoft Defender for Cloud Apps, Microsoft Purview, CrowdStrike Data Protection, Threatspike |
| SaaS and licence discovery | Flexera, Snow, Zylo, Productiv, 1Password |
| Browser and endpoint control | LayerX, Check Point Browse GenAI DLP |
| Network and SASE | Zscaler DLP, Netskope, Darktrace, Cisco Umbrella, Fortinet FortiOS 8.0.0 UTM |
| AI gateways and proxies | Cloudflare AI Gateway, OpenRouter, LiteLLM, SurePath, Amazon Bedrock, Databricks Unity AI Gateway |
| Prompt and runtime protection | Palo Alto Prisma AIRS (formerly LLM Guard, via the Protect AI acquisition), Lakera (acquired by Check Point) |
| Device and identity control | Microsoft Entra Conditional Access, Intune MAM and MDM |
Two notes on that list. Microsoft publishes admin guidance on shadow AI within Microsoft 365 for organisations already in that estate. And one contributor flagged that a well-known open-source guardrail project is now inside a commercial product following acquisition, which is worth checking before assuming a tool you evaluated last year still exists in the same form.
The monitoring creates its own problem
One contributor described a firewall vendor's new inspection service that uses deep packet inspection to detect LLM use and surface the prompt text the employee typed and the files they attached.
Their reaction is the one to sit with: in Europe, that capability is itself a data protection problem, and they expect organisations to push back hard against deploying it.
They are right to flag it. A tool that logs what staff typed into a chatbot is processing personal data about employees, and deploying it engages the same obligations as any other workplace monitoring. Under UK GDPR that means a lawful basis, transparency, and in most cases a data protection impact assessment before switching it on.
Solving a data protection problem with a tool that creates a data protection problem needs to be a decision, not a default.
Two things worth avoiding
Personal subscriptions used for business work. One organisation described a light-touch policy that permitted AI use provided staff registered with a work email, paid for an individual account personally, and signed an acceptable use policy. A contributor pointed out two problems: using a personal subscription for business work is likely to breach the provider's terms, and individual tiers frequently lack the ability to prevent data being used for training or reviewed. That combination adds licensing exposure to the data exposure you were trying to fix.
Assuming a signed policy is a control. Several people noted that an acceptable use policy without monitoring or consequences gives you a pretext for dismissal and very little else, and that if staff are on personal accounts you have no way to demonstrate a breach in the first place.
What this suggests for a UK organisation
Discover before you decide. Almost everyone who reported success started by finding out what was actually in use, and several were surprised. You cannot write a proportionate policy against a problem you have not measured, and the discovery tools listed above will tell you in days.
Get the risk decision recorded, whichever way it goes. The most valuable outcome is not a block, it is a named person accepting a documented position. Advise, let leadership decide, and write down what they decided.
Choose the sanctioned tool on whether people will use it. This is the failure pattern above, and it is entirely avoidable. Ask the people currently going around you which tool they want before you buy the one that is easiest to procure.
Write rules for data, not for websites. New AI products appear weekly and existing products acquire AI features silently. A rule that says "no customer records, no source code, no contract text" survives that; a blocklist does not.
Treat monitoring as a data protection decision. If the control inspects prompts, do the impact assessment first.
For the policy itself, our AI acceptable use policy for small UK businesses, with a free template and checklist is the practical starting point, and our guide to AI governance policies for mid-market organisations of 250 to 1,000 staff covers the governance layer above it.
On the specific risks, we have covered how to stop Copilot surfacing confidential data to the wrong people in a 365 tenant, and separated fact from fiction in NCSC guidance on ChatGPT, Copilot and sensitive business data. For the wider regulatory position, see UK AI regulation compared with the EU AI Act, and for organisations considering keeping the data entirely in-house, self-hosted alternatives covers that route.
Sources
r/ITManagers, Our employees are using ChatGPT and other AI tools at work and IT has basically no visibility, posted 29 July 2026, 142 points and 226 comments. All practitioner accounts, quoted positions and reported outcomes in this article are drawn from that thread and are the contributors' own descriptions of their organisations, not independently verified. Contributors are pseudonymous.
Microsoft Learn, Microsoft 365 admin guidance on shadow AI agents, and product documentation for Microsoft Purview, Microsoft Defender for Cloud Apps, Entra Conditional Access and Intune.
Vendor product documentation for the tools named by contributors, including Palo Alto Networks Prisma AIRS following the Protect AI acquisition, and Check Point following the Lakera acquisition.
Information Commissioner's Office guidance on employment practices and monitoring at work, and on data protection impact assessments, for the section on prompt inspection.