Blog

Cyber Security Guidance
In Plain English.

Practical advice on Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance, cyber basics and common issues affecting smaller businesses. The aim is to make cyber topics easier to understand and more useful in practice.

Grey AI Use Inside Organisations

Grey AI Use Inside Organisations

Many organisations have already adopted AI, even if the board has never approved it.

That adoption often happens quietly. A member of staff uses a free AI tool to rewrite an email. Someone uploads a proposal to make it more concise. A manager asks a chatbot to summarise a meeting note. A developer asks for help with code. A sales team uses AI to draft a client response. A policy owner pastes a document into a tool and asks for improvements.

None of that necessarily starts with bad intent. Most grey AI use comes from convenience, pressure and a genuine desire to do better work faster.

The problem is that the organisation may lose control of information before anyone realises AI has entered the workflow.

What grey AI use means

Grey AI use means staff use AI tools without clear approval, governance, supplier assessment or data rules.

The tool may work well. The employee may save time. The output may look professional. But the risk sits in the input, the output and the terms that govern the service.

Staff may upload:

·        Client names and contact details.

·        Contracts and commercial terms.

·        Pricing models.

·        HR notes.

·        Security findings.

·        Vulnerability reports.

·        Incident reports.

·        Audit evidence.

·        Source code.

·        Board papers.

·        Supplier information.

·        Internal strategy documents.

That information may fall under confidentiality obligations, data protection law, client contracts, employment rules or intellectual property protections. An AI tool does not remove those obligations.

The web filtering analogy

Most organisations already understand internet filtering. They do not leave every user to decide which websites create malware, adult content, gambling risk, phishing risk, copyright issues, file sharing problems or data leakage. They set acceptable-use rules, use security tooling, block risky categories, approve exceptions and review incidents.

AI needs the same discipline, but with an additional challenge. Traditional web filtering mostly controls what comes into the organisation. AI governance also controls what goes out.

A member of staff using an unmanaged AI tool may send company information into a third-party system without supplier due diligence, contractual review, retention rules or audit visibility.

That risk looks similar to emailing a client proposal to a personal account so a friend can tidy it up. The intention may be harmless. The person helping may mean well. But the company has still moved confidential information outside approved controls.

Who owns responsibility?

AI governance needs shared ownership.

·        The board and senior leadership own risk appetite.

·        IT and security own technical controls.

·        Legal and compliance own contractual, regulatory and data protection considerations.

·        Procurement owns supplier due diligence.

·        Managers own how their teams use approved tools in practice.

·        Staff own daily judgement and must follow policy.

·        Vendors own transparency, safety controls and honest terms.

No single group can carry the whole burden.

Practical controls

Organisations should take a controlled adoption approach.

·        Create an AI acceptable-use policy.

·        List approved AI tools.

·        Block or restrict high-risk unmanaged tools where appropriate.

·        Define data that must never enter unmanaged AI.

·        Map AI use to information classification.

·        Train staff using real examples.

·        Review AI suppliers before use.

·        Confirm whether inputs and outputs train models.

·        Set rules for public content, client work and code.

·        Create an incident route for accidental disclosure.

·        Make approved AI easy to access.

The last point matters. If the safe route feels harder than the risky route, staff will find shortcuts.

A balanced position

Organisations should not ban AI by default. Bans often push use underground, which makes risk harder to see.

They should also avoid blind trust. AI tools can help productivity, but they handle information. That means they belong inside security governance, supplier assurance and data protection controls.

A simple staff test helps: would I send this information to an unknown external supplier without approval?

If the answer is no, it should not go into an unmanaged AI tool.

AI governance does not need to feel complex. It needs to feel normal. Treat AI like internet access, cloud storage and email security. Give staff clear rules, safe tools and a route to ask before they paste.