Here's a safe bet: people in your business are already using AI tools for work. ChatGPT, Copilot, Claude, Gemini — pasting in a report to summarise, a spreadsheet to analyse, a tricky email to rewrite. Most of them haven't asked anyone, and a good number are doing it on personal devices you don't control.
That's "shadow AI" — AI use happening quietly, outside any policy or oversight. It's not usually malicious. It's people trying to work faster. But it carries real risk, and most businesses have no idea how much of it is going on.
Why it's a problem
- Data leaves the building. When someone pastes a client contract, customer data, or internal figures into a public AI tool, that information has left your control. Depending on the tool and its settings, it may be stored, processed elsewhere, or used to train future models. You can't un-share it.
- You can't govern what you can't see. If AI use is unofficial, there's no policy on what's acceptable, no guidance on what should never be pasted in, and no visibility of what's happening.
- Personal devices make it worse. A lot of shadow AI happens on personal phones and laptops — outside your management, your security controls, and your sight entirely.
- Compliance exposure. If you handle personal or regulated data, feeding it into an unapproved tool can quietly put you offside with GDPR and client obligations.
The wrong response
The instinct is often to ban it. That rarely works — it just pushes the behaviour further into the shadows, onto personal devices, where you have even less visibility. People will use AI because it genuinely helps them; the job isn't to stop them, it's to make the safe path the easy one.
Getting a grip on it
A sensible, proportionate approach looks like this:
- Acknowledge it's happening. Assume your team is using AI already, and ask — openly, without blame — what they're using and why.
- Put an AI Acceptable Use Policy in place. Plain-language rules: which tools are approved, what may never be entered (client data, personal data, credentials, anything confidential), and who to ask when unsure.
- Offer a safe, approved option. Give people a sanctioned tool with appropriate data protections so they don't need to reach for a random free one.
- Train people on the why. Most shadow AI comes from not realising the risk. A short, honest explanation changes behaviour more than a ban ever will.
- Bring devices into scope. The more work happens on managed, secured devices, the more you can actually guide and protect. Company data on unmanaged personal kit is the hardest part to control.
The Apple advantage: actually seeing AI on your Macs
Here's where being on well-managed Apple devices genuinely helps. Most security tools can't see AI tools running natively on modern Macs — which is a big part of why shadow AI stays invisible. Jamf has built a dedicated AI governance capability to close exactly that gap, and as a Jamf partner it's something we can put in place for you.
In plain terms, it lets you:
- Discover what's actually running — the AI apps, tools and even AI "agents" on your Mac fleet, so shadow AI stops being a guess.
- Enforce policy at the device level — approve the tools you're happy with, restrict the ones you're not, scoped by person or team, in a way people can't simply work around.
- Prove it — an exportable audit trail of what's allowed and what's been decided, which is exactly the kind of evidence emerging rules like the EU AI Act (and your own clients) will increasingly ask for.
It's shadow AI turned into managed AI: your team still gets the productivity, you get the visibility and control. (Jamf even builds in curated, vendor-validated policies for tools like Anthropic's Claude, so you're not starting from a blank page.)
Why this sits with your IT partner
AI risk isn't really a separate "AI problem" — it's the same data-governance and device-management question you already face, in a new outfit. Who can touch company data, on what devices, and under what rules? That's core to how a fleet should be managed and secured, which is exactly where a managed security and compliance approach earns its keep — especially when your data lives on well-managed Apple devices rather than scattered across unmanaged personal ones.
AI isn't going away, and the businesses that handle it well won't be the ones who banned it — they'll be the ones who made the safe way the easy way. If you'd like help drawing up an AI policy and getting visibility of what's happening, get in touch.
Ready to get your Apple fleet properly managed?
Free 30-minute discovery call. No commitment.
Book a free callMore from the blog
Zero-touch deployment for Apple devices, explained
No imaging, no manual setup. Here's how zero-touch deployment and Apple Business Manager get a new Mac working the moment it's switched on.
Managed ITIn-house Apple IT vs an Apple MSP: when does outsourcing make sense?
Hire someone to manage your Macs, or bring in an Apple MSP? An honest look at the real costs, trade-offs, and when each one is the right call.
