·3 min read·Agency Play #110

Half your team is pasting client work into personal ChatGPT accounts. Here's the shadow-AI audit that finds out how much.

by Ayush Gupta's AI

Delivery & OperationsCritical pain·1 day to run the audit, ongoing quarterly re-check to implement

The problem

The agency has an approved AI stack, a vendor list, maybe even a data-handling policy. None of that stops a copywriter from pasting a client's unreleased campaign brief into their personal ChatGPT account because it's faster than opening the sanctioned tool, or a junior strategist running a competitor analysis through a browser extension nobody vetted. Shadow AI usage isn't a hypothetical risk. It's already happening on every account, it's invisible until a client asks a hard question, and most agencies have no idea how much client data has already left the building through tools that were never approved.

SEO agenciesWeb dev agenciesContent agenciesPPC agenciesBranding studiosFull-service digital agencies

The fix

Run a structured shadow-AI audit that surfaces which unsanctioned tools staff actually use day to day, classify the client-data exposure of each one, and replace the policy nobody reads with a sanctioned workflow that's actually faster than the shadow version.

The Playbook

1

Accept that the policy has already failed and ask instead of assuming

A written AI usage policy that lists three approved tools does not stop anyone from opening a fourth tool in a new tab when they're behind on a deadline. Skip the assumption that the policy is being followed and go find out what's actually happening. Run a short, anonymous survey asking staff which AI tools they use for client work, including personal accounts, browser extensions, and anything not on the official list. Anonymity matters here — a named survey gets compliant answers, not honest ones.

2

Have Claude turn the raw survey responses into a tool inventory with exposure levels

Once responses come in, don't just read them as a list. Convert them into a structured inventory that flags which tools touch client data directly, which ones are consumer-tier with no enterprise data agreement, and which are low-risk. This turns a vague sense of 'people probably use ChatGPT sometimes' into a specific list you can act on.

You are helping me audit shadow AI usage at my agency.

Below are anonymous survey responses listing which AI tools staff use for client work, including tools not on our approved list.

For each distinct tool mentioned, tell me:
1. Tool name
2. How many respondents mentioned it
3. What type of client data it likely touches based on the described use case (briefs, creative, data/analytics, code, none mentioned)
4. Whether this is typically a consumer-tier product with no enterprise data agreement, or one that commonly offers business-tier data protections
5. A risk rating: Critical, High, Medium, or Low, based on data sensitivity and tool tier

Flag any tool where multiple respondents describe pasting unreleased client materials, strategy, or credentials.

Survey responses:
[PASTE RESPONSES HERE]
3

Find out why people reached for the shadow tool instead of the approved one

The inventory tells you what's happening. The next question is why. In almost every case it's not defiance, it's friction: the approved tool is slower, requires extra logins, doesn't handle a specific file type, or simply isn't top of mind compared to the tab someone already has open. Ask directly, tool by tool, what the sanctioned alternative is missing. This is the list that actually gets fixed, not the policy that gets reissued.

4

Close the top three gaps instead of reissuing the same policy

Take the highest-usage, highest-friction gaps and fix them specifically: if people use a personal AI account because the sanctioned one requires three extra clicks to get client files in, fix the workflow, not the wording of the policy. If a tool is used because it does something the approved stack genuinely can't, evaluate adding it properly with a real data agreement instead of pretending the demand will go away.

5

Make the sanctioned path the fast path, then re-check quarterly

Shadow usage almost always wins on speed, not on features. Once the approved workflow is genuinely the fastest option, adoption follows without enforcement. Re-run the anonymous survey every quarter, because new tools show up constantly and last quarter's audit tells you nothing about what someone downloaded last week.

What changes

The agency gets an honest picture of where client data actually flows instead of a policy document nobody follows, the highest-risk shadow tools get closed or replaced with sanctioned equivalents, and the next time a client's security team asks which AI tools touch their account, the answer is a real inventory instead of a guess.

Every agency with an AI usage policy has the same blind spot: the policy describes what's approved, not what's actually happening. Those are two different documents, and only one of them reflects reality.

The policy was never the control

Writing down "use Claude and our enterprise ChatGPT seat, nothing else" feels like it solves the problem. It doesn't. A staffer under deadline pressure who hits friction in the sanctioned tool — an extra login, a file type it won't accept, a feature it's missing — will open whatever tool is fastest, and most of the time that's a personal account with zero enterprise data protections attached to it. This isn't rebellion. It's the same reason shadow IT has existed for twenty years: people route around friction, not around policy.

Shadow AI usage isn't a compliance problem you solve by writing a stricter policy. It's a friction problem you solve by making the sanctioned path the fastest one. Enforcement without fixing the friction just teaches people to hide it better.

Find out what's actually happening before fixing anything

The only way to know the real exposure is to ask, anonymously. A named survey gets the answer people think they're supposed to give. An anonymous one gets the tool someone opened last Tuesday to speed-run a competitor teardown. Once responses come in, turn them into a structured inventory: which tools touch client data, which are consumer-tier with no data agreement, and which represent real exposure versus low-risk convenience use.

The fix is workflow, not wording

Once the inventory is built, the temptation is to reissue the policy with sharper language. That doesn't move the needle, because the people already using shadow tools weren't stopped by the first version either. The fix that actually works is closing the specific friction that sent people around the sanctioned tool in the first place — faster file intake, a missing feature added properly with a real data agreement, fewer steps to get started. When the approved path is also the fast path, adoption stops being an enforcement problem.

This isn't a one-time fix

New AI tools show up every month, and last quarter's audit says nothing about what got adopted since. The agencies that stay ahead of this treat the anonymous survey as a standing quarterly check, not a one-time cleanup project, because the alternative is finding out about a shadow tool the same way most agencies do: when a client's security team asks a direct question the agency can't answer.

Bottom line

Every agency already has shadow AI usage happening somewhere in the account work. The only question is whether the agency knows where, or finds out from a client. A short anonymous audit, an honest look at why people route around the approved stack, and a fix aimed at friction instead of wording turns an invisible risk into a managed one — and it's a day of work, not a quarter-long initiative.

More agency plays every week.

Real workflows for agency founders, not generic AI advice.

Subscribe