{"id":26074,"date":"2026-09-21T08:27:39","date_gmt":"2026-09-21T12:27:39","guid":{"rendered":"https:\/\/www.sherweb.com\/blog\/?p=26074"},"modified":"2026-09-21T08:27:39","modified_gmt":"2026-09-21T12:27:39","slug":"shadow-ai-governance-msps","status":"publish","type":"post","link":"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/security\/shadow-ai-governance-msps\/","title":{"rendered":"Shadow AI: What MSPs need to do when clients adopt AI tools without IT approval"},"content":{"rendered":"<h2><b><span data-contrast=\"auto\">Key takeaways<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h2>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Senior decision-makers use unapproved AI tools at more than twice the rate of the staff they manage, 65% against 31%, per <\/span><a href=\"https:\/\/www.trustedtechteam.com\/blogs\/security\/shadow-ai-executives-workplace-risk\"><span data-contrast=\"none\">TrustedTech and Censuswide research<\/span><\/a><span data-contrast=\"auto\"> from March 2026.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"2\" data-aria-level=\"1\"><a href=\"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-risk-browsers\/\"><span data-contrast=\"none\">Shadow AI<\/span><\/a><span data-contrast=\"auto\"> governance is the set of policies, technical controls and review processes an organization uses to find, assess and manage AI tools adopted without IT approval.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">MSPs should audit real usage through OAuth grants, browser extensions, DNS logs and department interviews before revising any AI policy.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">Every tool found in an audit belongs in one of three buckets: approve as is, restrict to specific users or replace with a governed alternative.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"5\" data-aria-level=\"1\"><span data-contrast=\"auto\">Shadow AI governance can be sold as a recurring service line built on the security skills an MSP already has.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<hr \/>\n<p><span data-contrast=\"auto\">Your quarterly OAuth review turns up an app you&#8217;ve never heard of. Three people on the client&#8217;s sales team granted it read access to their mailboxes four months ago. It&#8217;s an AI note taker, and nobody mentioned it.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">That&#8217;s just one example of shadow AI, and by the time you find it, the policy question is already behind you. Shadow AI governance is the set of policies, technical controls and review processes an organization uses to find, assess and manage AI tools that employees adopt without IT approval.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">We covered what shadow AI is and where it hides in <\/span><a href=\"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-risk-browsers\/\"><span data-contrast=\"none\">a previous blog post<\/span><\/a><span data-contrast=\"auto\">. This one picks up after the discovery moment, with five steps to run when unapproved AI tools show up in a client environment.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Shadow AI is a discovery problem before it&#8217;s a policy problem<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Most clients already have an AI policy somewhere. The issue is that it was probably written before anyone checked what people were actually using, and just says something about using approved tools responsibly.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/www.trustedtechteam.com\/blogs\/security\/shadow-ai-executives-workplace-risk\"><span data-contrast=\"none\">Research from TrustedTech and Censuswide<\/span><\/a><span data-contrast=\"auto\">, fielded in March 2026 across 2000 employees in the US and UK, found that 48% of employees use unapproved AI tools at work. The seniority split matters more than the headline number. Senior decision-makers use unapproved tools at more than twice the rate of the people they manage: 65% against 31%.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The implication here is that the person who signed off on the AI policy is more likely to be working around it than the staff it was written for. That changes how you open the conversation, because a compliance-first approach puts you on the wrong side of the person who approves your budget.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">It also tells you something about motive. Nobody is routing around IT to be difficult. They&#8217;re doing it because a tool saves them an hour a day and the approval process takes three weeks.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Step 1: Audit what&#8217;s actually in use<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Start with discovery, because you can&#8217;t triage tools you haven&#8217;t found. Five checks will surface most of what&#8217;s running:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Conversations with department heads.<\/span><\/b><span data-contrast=\"auto\"> Ask what their team uses and what problem it solves, not whether anyone broke policy. Marketing, sales and finance are usually the heaviest users.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"2\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Browser extension review.<\/span><\/b><span data-contrast=\"auto\"> Most AI tools arrive as extensions. Pull the installed extension list through Intune or your RMM and compare it against what you&#8217;d approve.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"3\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">OAuth grant review in the Microsoft 365 tenant.<\/span><\/b><span data-contrast=\"auto\"> In Entra ID, work through enterprise applications: which third-party apps users have consented to and what permissions those apps hold and who granted them. This is where note takers, email assistants and CRM add-ons show up.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"4\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">DNS and traffic logs.<\/span><\/b><span data-contrast=\"auto\"> Filter for known AI domains over a 30-day window. Volume and user counts tell you which tools are daily habits and which were one-off experiments.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"2\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" data-aria-posinset=\"5\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Embedded AI features in approved SaaS.<\/span><\/b><span data-contrast=\"auto\"> Vendors switch these on by default. Check the client&#8217;s CRM, helpdesk, meeting platform and document tools for AI features nobody deliberately enabled.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">Record what you find in one sheet: tool, users, data it touches, how it authenticates and what it connects to. That sheet is your deliverable for the next conversation and the artifact you update every quarter once governance is running. For more on the monitoring side, see our guide to <\/span><a href=\"https:\/\/www.sherweb.com\/blog\/microsoft-ecosystem\/office-365\/ai-threat-detection-for-msps\/\"><span data-contrast=\"none\">AI threat detection for MSPs<\/span><\/a><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">One caveat on scope: if people use personal devices for work, your visibility stops at what you manage. Be sure to mention that in the report rather than presenting a partial picture as a complete one.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Step 2: Have the client conversation without the blame<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Next, present your findings as a productivity signal and a risk map rather than a list of violations. The framing you use in the first two minutes decides whether the client treats this as a security incident or a planning exercise.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Open with adoption<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Ask questions like: How many people are using these tools? Which departments are they in How long has it been happening? It\u2019s important that clients understand that their employees started using these tools because they work, and the usage volume tells you where the business has a workflow problem worth solving.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Walk the risk map, tool by tool<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">At this point, you should examine the full risk picture and be open with your clients. Let them know which app has read access to their mailboxes, which stores meeting transcripts on servers nobody can audit and which allows the vendor to train on submitted content. Specifics move a client toward decisions.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Someone will ask about banning all the tools that were identified. The risk there is that blanket bans move usage onto personal devices and personal accounts, which costs you the visibility you just spent a week building.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Close by setting expectations for the next 30 days<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Make a triage decision on every tool found, and create a short policy and a request route for new tools. Ask for a named owner on the client side, because decisions about which data can leave the tenant are business decisions.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Step 3: Triage every tool: approve, restrict or replace<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Sort every tool on your sheet into one of three buckets: approve as is, restrict to specific users and uses or replace with a governed alternative. Four questions decide the bucket.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"8\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">What data does the tool touch? <\/span><\/b><span data-contrast=\"auto\">A marketing team running published copy through an AI writing assistant is a different risk from a bookkeeper pasting client financials into the same tool.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"8\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"2\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Does the vendor train on inputs? <\/span><\/b><span data-contrast=\"auto\">Check the tier the client is actually on, not the vendor&#8217;s enterprise marketing page. Free and consumer tiers often permit training on submitted content. Business tiers usually don&#8217;t, and they usually come with a data processing agreement.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"8\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"3\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">How does it authenticate?<\/span><\/b><span data-contrast=\"auto\"> A tool signed into with a personal account sits outside your control entirely. SSO through the client&#8217;s tenant is the minimum bar for anything touching business data.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"8\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"4\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">What is it connected to? <\/span><\/b><span data-contrast=\"auto\">An app with read access to a mailbox is a data flow, not a feature. Broad OAuth scopes belong in the restrict or replace bucket by default.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">For anything working with data inside Microsoft 365, <\/span><a href=\"https:\/\/info.sherweb.com\/microsoft-365-copilot-guide-for-msp\"><span data-contrast=\"none\">Copilot<\/span><\/a><span data-contrast=\"auto\"> is the natural replacement candidate. It runs inside the tenant boundary, respects the permissions you&#8217;ve already configured and reports into Purview and conditional access alongside everything else you manage.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">You might hear an objection here. One common pushback from clients is that they\u2019re already using another AI tool that they prefer, so why would they pay to use Copilot?<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Answer on data grounds rather than arguing about model quality. Copilot&#8217;s answers draw on the client&#8217;s own documents, mail and chats, with their existing permissions applied to every response, which is what a consumer account can&#8217;t do at any price. Where a team has a use case outside tenant data, approve a business tier of the tool they want with SSO and a signed agreement. Approving the right tool properly beats losing it to a personal account you can&#8217;t see.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Step 4: Put governance in place<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Governance runs on three layers. It\u2019s important to have all three covered, because if you skip one then the other two stop working.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Policy and approval workflow<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">The acceptable use policy basics are in <\/span><a href=\"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-risk-browsers\/\"><span data-contrast=\"none\">our previous blog post on Shadow AI<\/span><\/a><span data-contrast=\"auto\">, so what this adds is specificity. Name the data categories that can never go into an external AI tool at this client: client PII, payment data, health records, unreleased financials and source code. Name the approved tools and keep that register somewhere people will actually look.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Then build the request path. If asking for a new tool takes three weeks, people stop asking. A one-page form, a five business day turnaround and a named approver is enough. That path is what makes the policy hold, because it gives people a legitimate way to get what they were going to get anyway.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Technical controls<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">The controls that carry the most weight are:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">DNS filtering<\/span><\/b><span data-contrast=\"auto\"> to block restricted tools<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"2\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Data loss prevention and sensitivity labels<\/span><\/b><span data-contrast=\"auto\"> in Purview so regulated content can&#8217;t be copied out<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"3\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Conditional access<\/span><\/b><span data-contrast=\"auto\"> so AI apps are reachable only from managed devices<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"4\" data-aria-level=\"1\"><b><span data-contrast=\"auto\">Defender for Cloud Apps<\/span><\/b><span data-contrast=\"auto\"> for app discovery and OAuth consent governance\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">Our guides on <\/span><a href=\"https:\/\/www.sherweb.com\/blog\/microsoft-ecosystem\/office-365\/ai-data-security-for-msps\/\"><span data-contrast=\"none\">AI data security for MSPs<\/span><\/a><span data-contrast=\"auto\"> and <\/span><a href=\"https:\/\/www.sherweb.com\/blog\/microsoft-ecosystem\/office-365\/ai-identity-security\/\"><span data-contrast=\"none\">AI identity security<\/span><\/a><span data-contrast=\"auto\"> go deeper on configuring these.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Set user consent policies so people can&#8217;t grant permissions to new third-party apps on their own. That single change stops most of what you found in Step 1 from happening again.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">User training<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">When it comes to training, it\u2019s important to have at least one session repeated annually that covers two things: what not to paste into an AI tool and how to request a new one. Use real examples from the audit. &#8220;Don&#8217;t paste client data&#8221; is abstract. &#8220;Don&#8217;t paste the contract we found in a chat transcript last month&#8221; is not.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This is the time to raise one more thing while you have the client&#8217;s attention. For small and medium businesses, the data hygiene and data governance is typically far behind where it needs to be to have proper AI adoption. Permission sprawl and unlabeled data are why sanctioned AI rollouts stall six months in. Tell clients to budget the governance work ahead of any AI project, as it\u2019s a necessary prerequisite.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Want the full picture on securing client AI adoption?<\/span><\/b> <a href=\"https:\/\/info.sherweb.com\/ai-cybersecurity-guide-msps\"><span data-contrast=\"none\">Download the Sherweb AI cybersecurity guide for MSPs<\/span><\/a><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Step 5: Turn governance into a recurring service<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">This is an opportunity to package this work as a service line instead of a one-time project. The audit becomes a fixed-fee AI risk assessment. The policy, controls and training become an implementation engagement. The quarterly review becomes recurring revenue.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Make the quarterly review the product<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">That quarterly review is what holds it together. Re-run the audit, report new tools found, flag OAuth grants added since last quarter and update the register. Put it on the QBR agenda alongside patch compliance and backup testing. Clients who see a report every quarter treat AI governance as an operating cost rather than a project that ended.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">There&#8217;s a renewal angle too. Cyber insurance questionnaires and audit checklists have started asking about AI usage controls, and a client who can point to a policy and quarterly documentation answers those questions faster. Frame that as risk reduction and less paperwork, not as meeting a specific standard.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Why this is the AI service line to start with<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Many MSPs may hold back from selling AI services because they don&#8217;t feel that they have the skills to do the business consulting element that&#8217;s required to make an AI pilot successful. However, they might have the IT skills to do the data hygiene and governance.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">That&#8217;s the argument for starting here. Shadow AI governance is discovery, policy, tenant controls and user training. You can launch it with the security skills already on your team, and it earns you a seat at the table when the client&#8217;s bigger AI conversation starts. Our piece on building an <\/span><a href=\"https:\/\/www.sherweb.com\/blog\/microsoft-ecosystem\/office-365\/msp-security-strategy-for-ai\/\"><span data-contrast=\"none\">MSP security strategy for AI<\/span><\/a><span data-contrast=\"auto\"> covers how this fits a wider security offer.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">When to escalate: Signs of real exposure<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Most of what you\u2019ll find when going through these steps is routine. However, you may encounter situations aren&#8217;t, and they need action the same day rather than a line on the triage sheet.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><span data-contrast=\"none\">Regulated data in a consumer tool<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">If health records, payment data or client files went into a free-tier tool whose terms permit training on submitted content, treat it as a possible disclosure. Scope it, document it and get the client&#8217;s legal or compliance contact involved.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Broad OAuth grants to unvetted vendors<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Permissions like<\/span><i><span data-contrast=\"auto\"> Mail.Read<\/span><\/i><span data-contrast=\"auto\"> across an organization, or <\/span><i><span data-contrast=\"auto\">Files.ReadWrite.All<\/span><\/i><span data-contrast=\"auto\"> granted to an app nobody can identify are standing data pipelines out of the tenant. Revoke first, investigate second.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">AI tools wired into finance or client systems<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">An assistant with write access to an accounting platform or a CRM can act, not just read. Treat it like any other privileged integration: named owner, documented scope, reviewed quarterly.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Making AI use safe is the advisory role<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Shadow AI showed up in your clients&#8217; environments because it works. Your job is to make it safe to use on terms you can see and control. That&#8217;s advisory work, and it&#8217;s billable.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Want help building a security offer around client AI adoption? <\/span><a href=\"https:\/\/info.sherweb.com\/sherweb-cloud-services-for-msps\"><span data-contrast=\"none\">Schedule a call with the Sherweb team<\/span><\/a><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Shadow AI FAQs<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">What is shadow AI?<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Shadow AI is the use of AI tools inside a business without approval from IT or security. Our <\/span><a href=\"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-risk-browsers\/\"><span data-contrast=\"none\">shadow AI explainer blog<\/span><\/a><span data-contrast=\"auto\"> covers where it hides and why standard discovery tools miss it.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">What are the risks of shadow AI?<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">The main risks are data exposure through inputs submitted to tools that may train on them, unmonitored OAuth connections between third-party apps and business systems, no audit trail when regulated data leaves the environment and business decisions made on output nobody verified.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">How can you detect shadow AI?<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Detect shadow AI by reviewing OAuth grants and enterprise applications in the Microsoft 365 tenant, auditing installed browser extensions, filtering DNS and web traffic logs for known AI domains, checking SaaS apps for AI features enabled by default and asking department heads directly what their teams use.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">How can you prevent shadow AI?<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Prevent shadow AI by restricting user consent for third-party apps, publishing an approved tool register with a fast request process, applying DNS filtering and data loss prevention policies, and giving people a sanctioned tool good enough that they stop looking elsewhere.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Key takeaways\u00a0 Senior decision-makers use unapproved AI tools at more than twice the rate of the","protected":false},"author":177,"featured_media":26075,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[753],"tags":[1071,1200],"class_list":["post-26074","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-ai","tag-shadow-ai"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Shadow AI governance for MSPs: An action plan | Sherweb<\/title>\n<meta name=\"description\" content=\"Are your clients using unapproved AI tools? Follow this shadow AI governance playbook for MSPs, from audit to policy.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Shadow AI governance for MSPs: An action plan | Sherweb\" \/>\n<meta property=\"og:description\" content=\"Are your clients using unapproved AI tools? Follow this shadow AI governance playbook for MSPs, from audit to policy.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/\" \/>\n<meta property=\"og:site_name\" content=\"Sherweb\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Sherweb\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-21T12:27:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/wp-content\/uploads\/Hero_1200x480-1-6.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"480\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"The Sherweb Team\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@SherWeb\" \/>\n<meta name=\"twitter:site\" content=\"@SherWeb\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"The Sherweb Team\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/shadow-ai-governance-msps\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/shadow-ai-governance-msps\\\/\"},\"author\":{\"name\":\"The Sherweb Team\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#\\\/schema\\\/person\\\/42a19dccace310904575a5656cc20976\"},\"headline\":\"Shadow AI: What MSPs need to do when clients adopt AI tools without IT approval\",\"datePublished\":\"2026-09-21T12:27:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/shadow-ai-governance-msps\\\/\"},\"wordCount\":2403,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/shadow-ai-governance-msps\\\/#primaryimage\"},\"thumbnailUrl\":\"\\\/blog\\\/wp-content\\\/uploads\\\/Hero_1200x480-1-6.jpg\",\"keywords\":[\"AI\",\"Shadow AI\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/shadow-ai-governance-msps\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/shadow-ai-governance-msps\\\/\",\"url\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/shadow-ai-governance-msps\\\/\",\"name\":\"Shadow AI governance for MSPs: An action plan | Sherweb\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/shadow-ai-governance-msps\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/shadow-ai-governance-msps\\\/#primaryimage\"},\"thumbnailUrl\":\"\\\/blog\\\/wp-content\\\/uploads\\\/Hero_1200x480-1-6.jpg\",\"datePublished\":\"2026-09-21T12:27:39+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#\\\/schema\\\/person\\\/42a19dccace310904575a5656cc20976\"},\"description\":\"Are your clients using unapproved AI tools? Follow this shadow AI governance playbook for MSPs, from audit to policy.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/shadow-ai-governance-msps\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/shadow-ai-governance-msps\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/shadow-ai-governance-msps\\\/#primaryimage\",\"url\":\"\\\/blog\\\/wp-content\\\/uploads\\\/Hero_1200x480-1-6.jpg\",\"contentUrl\":\"\\\/blog\\\/wp-content\\\/uploads\\\/Hero_1200x480-1-6.jpg\",\"width\":1200,\"height\":480,\"caption\":\"Shadow AI governance for MSPs: An action plan\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/shadow-ai-governance-msps\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/category\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Shadow AI: What MSPs need to do when clients adopt AI tools without IT approval\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/\",\"name\":\"Sherweb\",\"description\":\"More than a cloud marketplace\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#\\\/schema\\\/person\\\/42a19dccace310904575a5656cc20976\",\"name\":\"The Sherweb Team\",\"url\":\"https:\\\/\\\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\\\/blog\\\/author\\\/the-sherweb-team\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Shadow AI governance for MSPs: An action plan | Sherweb","description":"Are your clients using unapproved AI tools? Follow this shadow AI governance playbook for MSPs, from audit to policy.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/","og_locale":"en_US","og_type":"article","og_title":"Shadow AI governance for MSPs: An action plan | Sherweb","og_description":"Are your clients using unapproved AI tools? Follow this shadow AI governance playbook for MSPs, from audit to policy.","og_url":"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/","og_site_name":"Sherweb","article_publisher":"https:\/\/www.facebook.com\/Sherweb","article_published_time":"2026-09-21T12:27:39+00:00","og_image":[{"width":1200,"height":480,"url":"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/wp-content\/uploads\/Hero_1200x480-1-6.jpg","type":"image\/jpeg"}],"author":"The Sherweb Team","twitter_card":"summary_large_image","twitter_creator":"@SherWeb","twitter_site":"@SherWeb","twitter_misc":{"Written by":"The Sherweb Team","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/#article","isPartOf":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/"},"author":{"name":"The Sherweb Team","@id":"https:\/\/www.sherweb.com\/blog\/#\/schema\/person\/42a19dccace310904575a5656cc20976"},"headline":"Shadow AI: What MSPs need to do when clients adopt AI tools without IT approval","datePublished":"2026-09-21T12:27:39+00:00","mainEntityOfPage":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/"},"wordCount":2403,"commentCount":0,"image":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/#primaryimage"},"thumbnailUrl":"\/blog\/wp-content\/uploads\/Hero_1200x480-1-6.jpg","keywords":["AI","Shadow AI"],"articleSection":["Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/","url":"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/","name":"Shadow AI governance for MSPs: An action plan | Sherweb","isPartOf":{"@id":"https:\/\/www.sherweb.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/#primaryimage"},"image":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/#primaryimage"},"thumbnailUrl":"\/blog\/wp-content\/uploads\/Hero_1200x480-1-6.jpg","datePublished":"2026-09-21T12:27:39+00:00","author":{"@id":"https:\/\/www.sherweb.com\/blog\/#\/schema\/person\/42a19dccace310904575a5656cc20976"},"description":"Are your clients using unapproved AI tools? Follow this shadow AI governance playbook for MSPs, from audit to policy.","breadcrumb":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/#primaryimage","url":"\/blog\/wp-content\/uploads\/Hero_1200x480-1-6.jpg","contentUrl":"\/blog\/wp-content\/uploads\/Hero_1200x480-1-6.jpg","width":1200,"height":480,"caption":"Shadow AI governance for MSPs: An action plan"},{"@type":"BreadcrumbList","@id":"https:\/\/www.sherweb.com\/blog\/security\/shadow-ai-governance-msps\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.sherweb.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.sherweb.com\/blog\/category\/security\/"},{"@type":"ListItem","position":3,"name":"Shadow AI: What MSPs need to do when clients adopt AI tools without IT approval"}]},{"@type":"WebSite","@id":"https:\/\/www.sherweb.com\/blog\/#website","url":"https:\/\/www.sherweb.com\/blog\/","name":"Sherweb","description":"More than a cloud marketplace","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.sherweb.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.sherweb.com\/blog\/#\/schema\/person\/42a19dccace310904575a5656cc20976","name":"The Sherweb Team","url":"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/author\/the-sherweb-team\/"}]}},"tag_names":["AI","Shadow AI"],"_links":{"self":[{"href":"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/wp-json\/wp\/v2\/posts\/26074","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/wp-json\/wp\/v2\/users\/177"}],"replies":[{"embeddable":true,"href":"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/wp-json\/wp\/v2\/comments?post=26074"}],"version-history":[{"count":1,"href":"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/wp-json\/wp\/v2\/posts\/26074\/revisions"}],"predecessor-version":[{"id":26076,"href":"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/wp-json\/wp\/v2\/posts\/26074\/revisions\/26076"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/wp-json\/wp\/v2\/media\/26075"}],"wp:attachment":[{"href":"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/wp-json\/wp\/v2\/media?parent=26074"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/wp-json\/wp\/v2\/categories?post=26074"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/r-swca2-app15-sherwebblogprd-c5f5cbg9dbf0btgy.canadacentral-01.azurewebsites.net\/blog\/wp-json\/wp\/v2\/tags?post=26074"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}