Why did the company block ChatGPT in the first place?
Almost always out of fear of leakage, not hostility to innovation: the moment an employee pastes a contract, code or a customer list into an external tool, the company loses control of that data.
Every CISO knows the precedents: Samsung banned generative-AI tools on company devices in May 2023 after engineers pasted internal source code into ChatGPT (per Bloomberg); major US banks — JPMorgan among them — restricted use in early 2023; Italy's regulator even blocked ChatGPT temporarily in March 2023. Add GDPR fines up to €20M or 4% of global turnover, and blocking looks safe.
The problem your CISO is solving is real — some things should never be pasted into ChatGPT under any policy. The open question: is a blanket ban the right fix, or just the fastest one?
Why is the personal-phone workaround the riskiest move?
Because a workaround doesn't remove the risk — it removes the oversight. That's exactly Shadow AI: the same sensitive data flows to the same tools, with no logs, no enterprise settings, and nobody knowing where it went.
- It's already the norm: per the Microsoft and LinkedIn Work Trend Index 2024 (31,000 respondents, 31 countries), 75% of knowledge workers already use AI at work — about 78% of them bring their own tools (BYOAI).
- The exposure becomes personal: a paste from a private account is still a company data leak — except now you can't claim you followed procedure.
- And the terms are worse: a personal account runs on consumer terms — check the vendor's current policy — with none of the company's contractual protections.
What middle path can you offer IT?
One simple rule: external AI tools get anonymized copies only. Instead of arguing about which tool is allowed, change the question to what is allowed into the tool — once the answer is "only documents after anonymization", most of security's objection disappears.
It also complements blocking controls: DLP stops files at the gate, anonymization cleans the content itself. And when cleaning runs entirely in the browser, the original never reaches any server — the tool adds no new risk of its own.
How do you pitch the CISO? A step-by-step script
- Gather a measurable business need — two or three tasks where AI saves real hours weekly, in numbers: "summarizing 20 requirements documents a month", not "everyone uses it".
- Acknowledge the risk up front — one sentence showing you understand why the ban exists. A CISO who feels understood listens differently.
- Propose one clear rule — external AI tools receive anonymized copies only; originals never leave the organization.
- Ask for a bounded pilot — one team, one month, one document type, reviewed at the end. Small pilots are easy to approve.
- Bring a draft policy — hand over a ready company AI policy template instead of waiting for someone to write one.
- Ask for a decision in writing — even a reasoned "no" defines what would have to be true for a "yes".
What if only Copilot is allowed?
That's the most common outcome: everything blocked, one sanctioned tool left. It beats zero — but one tool never covers every need, and that gap pushes people into Shadow AI. The Copilot-only policy guide covers this scenario in depth — same conclusion: a safe channel beats a wall.