# Shadow AI Lunch & Learn - 30-minute Outline

## Objective

Help employees use AI productively without exposing company or customer data.

## Agenda

### 0-5 minutes: What is Shadow AI?

- AI tools used without approval or visibility
- Personal accounts used for work
- Browser, desktop, IDE, and API usage

### 5-15 minutes: Five common risks

1. Personal and customer data
2. Credentials and secrets
3. Source code and intellectual property
4. Contractual confidentiality
5. Regulatory and audit gaps

### 15-25 minutes: Safe usage process

- Approved tools: [link]
- Prohibited data: [policy link]
- How to request a new tool: [request link]
- Who to contact: [security contact]

### 25-30 minutes: Questions and commitment

Ask each participant to identify one workflow where AI can be used safely.
