Managed AI Control: from shadow AI to proven control

Managed AI Control: from shadow AI to proven control

In almost every organisation, AI is being used without IT's knowledge. Employees use AI tools like ChatGPT, Claude, Copilot or Gemini to write text, process documents or answer customer queries – often sharing company data that isn’t meant for those tools. This raises concern among auditors, insurers and customers. With Managed AI Control, Cheops maps out that AI usage, translates it into an AI policy, and enforces that policy technically, step by step, from warning to blocking.

What is shadow AI and the risks it entails?

Hundreds of new AI applications are being created every month. An employee discovers a useful tool and sets up a free account. Or a team chooses an application that is better suited to their work than the official one. This use starts without any discussion with IT, and quickly grows under the organisation’s radar.

It is also happening on a large scale. According to the European Digital Barometer, 47% of Belgian managers use AI without their colleagues or leadership knowing. And as many as 18% are using tools or software that haven’t been approved by the company.   describes this as a growing shadow AI problem.

The risk lies mainly in the information employees share. A contract being summarised, an email containing customer information, a prompt with personal data – in every case, company information is leaving the organisation through a channel it has no control over. One law firm, for example, specifically asked Cheops to prevent confidential client information from ending up in unapproved AI tools.

International research underlines the importance of control too. Research by Boston Consulting Group, which included roughly 300 cybersecurity leaders, shows a clear link between stronger AI governance and monitoring, and less reported impact from AI-related security incidents. Fewer than 20% of the organisations surveyed currently monitor shadow AI. These figures strengthen the argument for regular follow-up as AI use evolves within an organisation.

How do you gain control over AI use in your organisation?

Managed AI Control moves through three phases that build on one another.

  • AI Insight identifies actual usage: which tools employees are using and what kind of sensitive information is being shared. The service starts with a detect-only period: Cheops measures usage without intervening, so the policy is grounded in real practice rather than a theoretical framework.
  • AI Policy translates those insights into a concrete policy document: which tools are allowed, under which conditions, and which risks justify a block. Cheops provides the facts, but the decisions rest with the organisation.
  • AI Governance turns the policy into technical rules and also enforces them. When a policy violation occurs, the system actively intervenes, from warning the user and protecting sensitive data to blocking applications when necessary.

How can you control AI use without blocking everything?

Governance within Managed AI Control is based on several levels, each matched to the risk posed by a given tool or situation.

  • Detect: usage is logged and reported, without any intervention.
  • Protect: when a risky tool is used, the employee receives a notification with the relevant guidelines. If someone shares sensitive data – such as an IP address or an account number – the system filters that information out of the prompt before it reaches the tool. The response still comes back as normal, but without the sensitive information ever being shared with the AI tool.
  • Block: tools the organisation doesn’t trust, or the sharing of highly sensitive data, are actively blocked.

This structure means organisations don’t have to choose between allowing everything and banning everything. “We still want to give people the freedom to use AI. We don’t just block things, but we do make sure sensitive data isn’t shared,” says Thomas Collier, Technology Innovation Manager at Cheops.

An HR team using an approved AI solution for personnel files, for example, is subject to different rules than an employee entering the same data into a public tool. The policy makes that distinction.

Why does AI governance call for regular follow-up?

Cheops delivers Managed AI Control not as a one-off project, but as a continuous service. On a regular basis, the organisation receives an AI Usage Report, a Policy Violation Report, and an AI Compliance Report that documents progress over time and can serve as evidence for auditors and insurers. Cheops discusses these results with the client and refines the policy where needed – for example, when use of a new tool increases significantly.

“The policy has to keep up with what’s happening in the workplace,” says Collier. “It shouldn’t become a static document that still looks exactly the same a few months down the line.”

The protection itself doesn’t wait for that review. Sensitive data is filtered or blocked immediately, regardless of when the next report is due. The quarterly review is there to fine-tune the policy, not to activate the baseline protection.

Why does AI control call for ongoing expertise?

AI is an emerging and rapidly evolving technology. New tools are constantly popping up, and existing applications keep adding new capabilities. This makes managing it complex too: organisations need to continuously track AI use and proactively adapt their policy and technical controls to new developments and risks.

Cheops tracks these developments across multiple clients simultaneously and keeps the platform up to date. Cheops then translates that expertise into the right technical rules for your organisation. That’s the difference between a managed service and a licence that an organisation has to manage and monitor all on its own.

The organisation remains the owner of policy decisions and determines what is allowed and which risks are acceptable. Following up on individual violations through HR, and the internal communication around that, remain the client’s responsibility.

How does AI governance fit within a broader AI strategy?

Managed AI Control is part of Cheops’s wider AI offering. Where the AI Empowerment Journey guides organisations through the strategic introduction, implementation and sustainable embedding of AI, Managed AI Control focuses specifically on keeping day-to-day AI use visible, under control and secure.

Want to know which AI tools are being used under the radar in your organisation?

Our experts are happy to help you identify them.

Contact us

Need more insights?

You want to stay current on how Cheops assists companies with their growth strategy? Our newsletters provide you with practical tips and tricks.