Skip to content
Noxys

Blog Article

The CISO's 30-Day Playbook to Regain Control of Shadow AI

69% of organisations suspect or have evidence that their staff use prohibited public GenAI (Gartner, 2025). Shadow AI is already here. This operational playbook gives you a week-by-week plan to discover, classify, govern, and monitor unsanctioned AI — in 30 days.

CISOAI GovernanceShadow AISecurityCompliance

Why a CISO Playbook?

The CISOs we work with share the same observation: they know shadow AI exists in their organization, but they do not know at what scale or with what data. The lack of visibility creates paralysis: without an inventory, no policy can be defined; without a policy, no controls can be deployed; without controls, risk continues to grow.

This playbook breaks that cycle. In 30 days, you go from complete blindness to operational governance. Each week has a clear objective, concrete actions, and measurable results.

The plan is designed to be achievable with existing security team resources. It uses tools already available in most organizations and lightweight solutions like Noxys that deploy in minutes, not weeks.

Week 1: Discovery & Assessment

The goal of the first week is to get a complete picture of actual AI usage in your organization. Without this visibility, any action is blind.

Day 1-2: Deploy Browser Detection

Deploy a detection browser extension via your existing MDM/GPO/Chrome Enterprise policies. Noxys deploys in under 10 minutes with no infrastructure changes. The goal is to collect data in logging-only mode (no blocking) during this first week to establish a baseline.

Day 2-3: Cross-Reference Existing Sources

Cross-reference browser detection data with your existing sources: proxy logs (AI domains visited), DNS logs (queries to AI services), CASB reports (if available), and browser extension inventory in Active Directory. You will get a complete view of the AI attack surface.

Day 3-4: Identify Tools and Categories

Catalog all detected AI tools: generalists (ChatGPT, Claude, Gemini, Copilot), specialized (code tools, writing, image, video), and browser extensions. For each tool, document: data-use policy (training or not), server location (EU or non-EU), enterprise SSO support, compliance certifications (SOC 2, ISO 27001).

Day 4-5: Assess Data Exposure

Analyze detection data to identify types of sensitive data sent to AI tools: PII (names, addresses, IBANs), health data, trade secrets, credentials. Quantify: how many employees, which departments, what data types, which tools. This report will form the basis of your budget justification.

Day 5: Present Findings

Present the discovery report to leadership. Include: number of unsanctioned AI tools detected, percentage of employees affected, types of data exposed, and estimated financial risk (using IBM data on average breach cost). The goal is to obtain the mandate and budget for the following weeks.

Week 1 deliverable: complete AI tool inventory, data exposure mapping, financial risk report.

Week 2: Policy & Communication

Day 6-7: Draft AI Usage Policy

The policy must cover five points: approved AI tools (whitelist), prohibited data categories in prompts (PII, secrets, health data), department-specific rules (HR has different needs than R&D), graduated consequences for non-compliance (from warning to blocking), and the approval process for new tools.

Day 8-9: Classify Tools by Risk

For each detected tool, assign a risk level: low (EU servers, no data retention for training, enterprise SSO, SOC 2), medium (non-EU servers but GDPR-compliant, opt-out available), or high (non-EU servers, no opt-out, no DPA, no SSO). High-risk tools must be blocked or strictly coached.

Day 10: Communicate Internally

Communication is as important as the policy. Announce the approach positively: the goal is not to block AI but to secure it. Communicate three key points: the organization supports AI usage, approved tools are available or being deployed, and security rules also protect employees (their personal data is also exposed).

Week 2 deliverable: approved AI usage policy, tool risk classification, communication plan.

Week 3: Tool Deployment

Day 11-12: Activate Coaching Policies

Switch from logging mode to coaching mode. For medium-risk tools, display an educational message when the employee is about to enter sensitive data: “You are about to share [IBAN-type] data with [tool]. This tool is not approved. Do you want to continue?” Coaching is more effective than pure blocking because it educates without frustrating.

Day 13-14: Block Critical-Risk Usage

For high-risk tools (no opt-out from training data, non-EU servers, no DPA), activate selective blocking: block prompts containing sensitive data while allowing legitimate uses (generic text generation, brainstorming). Granularity at the prompt level, not the domain level, is essential to avoid blocking productive usage.

Day 15: Deploy Approved Tools

Offer approved alternatives for each blocked or coached AI tool. If you block free ChatGPT access, provide an enterprise version with opt-out from training data, SSO, and DPA. If you do not yet have an approved alternative, in-context coaching is your safety net.

Day 16-17: Train Teams

Organize short training sessions (30 minutes) by department. Cover three points: which tools are approved and why, which data must never be entered in a prompt, and how coaching tools will help them daily. Live sessions are more effective than generic e-learning.

Week 3 deliverable: active policies (coaching + blocking), approved alternatives deployed, teams trained.

Week 4: Monitoring & Iteration

Day 18-20: Analyze Metrics

After one week of active policies, analyze the results: number of coaching alerts, number of blocks, most frequently detected data types, departments with the most incidents, behavior modification rate after coaching (do employees modify their prompt or do they persist?). These metrics guide policy adjustments.

Day 21-23: Adjust Policies

Use metrics to refine. If a department has a high false positive rate, adjust classification rules for that department. If a medium-risk tool generates too many coaching alerts, consider switching to selective blocking. If employees persist after coaching, reinforce targeted training for that department.

Day 24-26: Extend Coverage

Extend detection to secondary channels: AI desktop applications (Copilot Desktop, Cursor), internal API integrations using unofficial keys, and mobile tools. Complete shadow AI coverage goes beyond the web browser.

Day 27-30: Document and Sustain

Document the entire process: tool inventory, applied policies, 30-day results, key metrics. Create a monthly review process: each month, re-evaluate detected tools (new ones appear every week), update risk classification, and adjust policies. Shadow AI is a dynamic problem: governance must be dynamic too.

Week 4 deliverable: operational dashboard, monthly review process, sustained governance.

30-Day Summary

WeekGoalKey Deliverable
1DiscoveryFull inventory + risk report
2PolicyAI policy + risk classification
3DeploymentActive policies + approved tools
4MonitoringDashboard + monthly review

Common Pitfalls to Avoid

Blocking Without Offering Alternatives

Blocking all AI tools without offering an approved solution pushes employees toward workarounds (personal VPNs, phone-based tools, copy-pasting outputs from unmanaged devices). Shadow AI does not disappear: it moves.

Waiting for the Perfect Policy Before Acting

Shadow AI grows every day. Waiting for a perfect policy approved by all departments means letting risk increase. Better to deploy an imperfect policy in coaching mode (non-blocking) and iterate than to remain without visibility for months.

Neglecting Ongoing Training

An annual awareness session is not enough. In-context coaching — directly in the browser, at the moment the employee is about to make a mistake — is 3 times more effective at permanently changing behavior. Noxys coaching alerts serve this function.

Start Your Free Shadow AI Diagnostic

Noxys gives you complete visibility in under 10 minutes. Start on the free discovery tier. No credit card required.

FAQ

Does the 30-day playbook work for SMBs?

Yes, and it is even easier to deploy in an SMB. With fewer employees, detection and training are faster. The free discovery tier covers a first organisation-wide scan. SMBs often have fewer security resources, which makes automated governance all the more valuable.

Should we block ChatGPT immediately?

No. Blocking without an alternative leads to workarounds. The correct approach is: week 1, log (see the shadow AI); week 2, classify by risk; week 3, coach ChatGPT free tier and selectively block prompts containing sensitive data. The enterprise version of ChatGPT with opt-out and DPA can be approved.

How to measure the playbook's ROI?

Four indicators: number of shadow vs approved tools detected (shadow reduction), weekly sensitive data incidents (risk reduction), AI license savings (redirection to approved tools), and documented regulatory compliance (audit trail for GDPR auditors).

Related articles