Blog Article
The CISO's 30-Day Playbook to Regain Control of Shadow AI
69% of organisations suspect or have evidence that their staff use prohibited public GenAI (Gartner, 2025). Shadow AI is already here. This operational playbook gives you a week-by-week plan to discover, classify, govern, and monitor unsanctioned AI — in 30 days.
Why a CISO Playbook?
The CISOs we work with share the same observation: they know shadow AI exists in their organization, but they do not know at what scale or with what data. The lack of visibility creates paralysis: without an inventory, no policy can be defined; without a policy, no controls can be deployed; without controls, risk continues to grow.
This playbook breaks that cycle. In 30 days, you go from complete blindness to operational governance. Each week has a clear objective, concrete actions, and measurable results.
The plan is designed to be achievable with existing security team resources. It uses tools already available in most organizations and lightweight solutions like Noxys that deploy in minutes, not weeks.
Week 1: Discovery & Assessment
The goal of the first week is to get a complete picture of actual AI usage in your organization. Without this visibility, any action is blind.
Day 1-2: Deploy Browser Detection
Deploy a detection browser extension via your existing MDM/GPO/Chrome Enterprise policies. Noxys deploys in under 10 minutes with no infrastructure changes. The goal is to collect data in logging-only mode (no blocking) during this first week to establish a baseline.
Day 2-3: Cross-Reference Existing Sources
Cross-reference browser detection data with your existing sources: proxy logs (AI domains visited), DNS logs (queries to AI services), CASB reports (if available), and browser extension inventory in Active Directory. You will get a complete view of the AI attack surface.
Day 3-4: Identify Tools and Categories
Catalog all detected AI tools: generalists (ChatGPT, Claude, Gemini, Copilot), specialized (code tools, writing, image, video), and browser extensions. For each tool, document: data-use policy (training or not), server location (EU or non-EU), enterprise SSO support, compliance certifications (SOC 2, ISO 27001).
Day 4-5: Assess Data Exposure
Analyze detection data to identify types of sensitive data sent to AI tools: PII (names, addresses, IBANs), health data, trade secrets, credentials. Quantify: how many employees, which departments, what data types, which tools. This report will form the basis of your budget justification.
Day 5: Present Findings
Present the discovery report to leadership. Include: number of unsanctioned AI tools detected, percentage of employees affected, types of data exposed, and estimated financial risk (using IBM data on average breach cost). The goal is to obtain the mandate and budget for the following weeks.
Week 1 deliverable: complete AI tool inventory, data exposure mapping, financial risk report.
Week 2: Policy & Communication
Day 6-7: Draft AI Usage Policy
The policy must cover five points: approved AI tools (whitelist), prohibited data categories in prompts (PII, secrets, health data), department-specific rules (HR has different needs than R&D), graduated consequences for non-compliance (from warning to blocking), and the approval process for new tools.
Day 8-9: Classify Tools by Risk
For each detected tool, assign a risk level: low (EU servers, no data retention for training, enterprise SSO, SOC 2), medium (non-EU servers but GDPR-compliant, opt-out available), or high (non-EU servers, no opt-out, no DPA, no SSO). High-risk tools must be blocked or strictly coached.
Day 10: Communicate Internally
Communication is as important as the policy. Announce the approach positively: the goal is not to block AI but to secure it. Communicate three key points: the organization supports AI usage, approved tools are available or being deployed, and security rules also protect employees (their personal data is also exposed).
Week 2 deliverable: approved AI usage policy, tool risk classification, communication plan.
Week 3: Tool Deployment
Day 11-12: Activate Coaching Policies
Switch from logging mode to coaching mode. For medium-risk tools, display an educational message when the employee is about to enter sensitive data: “You are about to share [IBAN-type] data with [tool]. This tool is not approved. Do you want to continue?” Coaching is more effective than pure blocking because it educates without frustrating.
Day 13-14: Block Critical-Risk Usage
For high-risk tools (no opt-out from training data, non-EU servers, no DPA), activate selective blocking: block prompts containing sensitive data while allowing legitimate uses (generic text generation, brainstorming). Granularity at the prompt level, not the domain level, is essential to avoid blocking productive usage.
Day 15: Deploy Approved Tools
Offer approved alternatives for each blocked or coached AI tool. If you block free ChatGPT access, provide an enterprise version with opt-out from training data, SSO, and DPA. If you do not yet have an approved alternative, in-context coaching is your safety net.
Day 16-17: Train Teams
Organize short training sessions (30 minutes) by department. Cover three points: which tools are approved and why, which data must never be entered in a prompt, and how coaching tools will help them daily. Live sessions are more effective than generic e-learning.
Week 3 deliverable: active policies (coaching + blocking), approved alternatives deployed, teams trained.
Week 4: Monitoring & Iteration
Day 18-20: Analyze Metrics
After one week of active policies, analyze the results: number of coaching alerts, number of blocks, most frequently detected data types, departments with the most incidents, behavior modification rate after coaching (do employees modify their prompt or do they persist?). These metrics guide policy adjustments.
Day 21-23: Adjust Policies
Use metrics to refine. If a department has a high false positive rate, adjust classification rules for that department. If a medium-risk tool generates too many coaching alerts, consider switching to selective blocking. If employees persist after coaching, reinforce targeted training for that department.
Day 24-26: Extend Coverage
Extend detection to secondary channels: AI desktop applications (Copilot Desktop, Cursor), internal API integrations using unofficial keys, and mobile tools. Complete shadow AI coverage goes beyond the web browser.
Day 27-30: Document and Sustain
Document the entire process: tool inventory, applied policies, 30-day results, key metrics. Create a monthly review process: each month, re-evaluate detected tools (new ones appear every week), update risk classification, and adjust policies. Shadow AI is a dynamic problem: governance must be dynamic too.
Week 4 deliverable: operational dashboard, monthly review process, sustained governance.
30-Day Summary
| Week | Goal | Key Deliverable |
|---|---|---|
| 1 | Discovery | Full inventory + risk report |
| 2 | Policy | AI policy + risk classification |
| 3 | Deployment | Active policies + approved tools |
| 4 | Monitoring | Dashboard + monthly review |
Common Pitfalls to Avoid
Blocking Without Offering Alternatives
Blocking all AI tools without offering an approved solution pushes employees toward workarounds (personal VPNs, phone-based tools, copy-pasting outputs from unmanaged devices). Shadow AI does not disappear: it moves.
Waiting for the Perfect Policy Before Acting
Shadow AI grows every day. Waiting for a perfect policy approved by all departments means letting risk increase. Better to deploy an imperfect policy in coaching mode (non-blocking) and iterate than to remain without visibility for months.
Neglecting Ongoing Training
An annual awareness session is not enough. In-context coaching — directly in the browser, at the moment the employee is about to make a mistake — is 3 times more effective at permanently changing behavior. Noxys coaching alerts serve this function.
Start Your Free Shadow AI Diagnostic
Noxys gives you complete visibility in under 10 minutes. Start on the free discovery tier. No credit card required.
FAQ
Does the 30-day playbook work for SMBs?
Yes, and it is even easier to deploy in an SMB. With fewer employees, detection and training are faster. The free discovery tier covers a first organisation-wide scan. SMBs often have fewer security resources, which makes automated governance all the more valuable.
Should we block ChatGPT immediately?
No. Blocking without an alternative leads to workarounds. The correct approach is: week 1, log (see the shadow AI); week 2, classify by risk; week 3, coach ChatGPT free tier and selectively block prompts containing sensitive data. The enterprise version of ChatGPT with opt-out and DPA can be approved.
How to measure the playbook's ROI?
Four indicators: number of shadow vs approved tools detected (shadow reduction), weekly sensitive data incidents (risk reduction), AI license savings (redirection to approved tools), and documented regulatory compliance (audit trail for GDPR auditors).