We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / AI and new risks

AI and new risks

Shadow AI: Your Staff Are Already Pasting Client Data Into Chatbots. Here Is the Policy.

Shadow AI is already in your business: what the 2026 breach data says about unapproved chatbots, and the one-page AI acceptable use policy that fixes it.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

The transcript, the free tool and the engagement letter

A paralegal at a 40-person litigation firm has a 212-page deposition transcript and a partner who wants a summary by 4 p.m. The firm's document system does not summarise. Her personal phone has a free AI app that does. She uploads the PDF from her work laptop, gets a clean summary in ninety seconds, tidies it, and sends it to the partner, who says it is the best summary he has had all year.

Three weeks later the client's general counsel sends the partner a question. The client's engagement letter, signed in March, contains a clause the client's own IT department insisted on: no client material may be processed by third-party AI services without written approval. The general counsel is asking, routinely, whether the firm has complied. The partner says yes without checking.

The paralegal reads the email and goes quiet. She has used the app on eleven matters. The free tier's terms allow the provider to use uploaded content to improve its models. Nobody at the firm has ever mentioned AI in a meeting, a policy or a training session. The IT company that manages the laptops has no idea which AI sites staff visit, because nobody asked them to look.

The partner now has to decide whether to tell the client, and the firm's malpractice insurer, and the paralegal, none of which will be a short conversation.

What the heck does this mean

Shadow AI is any AI tool your staff use for work without the business approving it, paying for it or knowing it exists. The free chatbot on a personal phone. The browser extension that "summarises any page." The transcription app someone installed for a meeting. It is shadow IT with a faster learning curve and a bigger appetite for data.

A few terms, one line each.

Prompt: whatever you type or upload into the tool; the transcript was a prompt.

Training data: content the provider may keep to improve the model; free tiers usually claim this right, business tiers usually waive it.

Data loss prevention: software that stops documents leaving through the browser, email or upload; the control that would have blocked the PDF.

Acceptable use policy: the one-page rule that tells staff which tools are approved and what may never go into them.

Business associate agreement: in US healthcare, the contract that makes a vendor accountable for patient data; consumer AI tools do not sign one.

The problem is not that staff are lazy or reckless. The paralegal did excellent work faster. The problem is that the firm never decided what was allowed, so the decision was made at 3:10 p.m. by the person with the deadline.

The numbers that matter

Shadow AI was involved in 43% of the breaches studied in IBM's 2026 Cost of a Data Breach Report, adding USD 5.39 million to the average cost of those incidents. Almost half. That is not an edge case; it is the new normal.

Of the organisations breached in the same IBM 2026 study, 68% had no policy governing AI use at all. The paralegal's firm would have been one of them.

Verizon's 2026 Data Breach Investigations Report found that 45% of employees use AI on work devices, and 67% of those do it through personal accounts, outside any control the business has. Nearly half your staff, two-thirds of them invisible to you.

What to do this week

  1. Find out what is actually in use. Pull the web-filter or DNS logs for AI domains, ask each team lead which tools their people use, and put the answers in the software inventory beside every other application. (CIS 2 Inventory and Control of Software Assets)
  2. Pick one approved tool per job and pay for the business tier under the company's account, with training on your data switched off in the contract. People stop using the free one when the paid one is better and allowed. (CIS 2 Inventory and Control of Software Assets)
  3. Write the one-page policy: approved tools, forbidden data with examples, human review before anything leaves the building, who to ask. Have every employee and contractor sign it by Friday. (CIS 3 Data Protection)
  4. Turn on a data loss prevention rule that blocks document uploads to unapproved AI sites from managed devices, and log the attempts so you can see who needs a conversation rather than a warning. (CIS 3 Data Protection)
  5. Run a 20-minute training built around your own examples: the deposition, the patient list, the payroll file, the code. Show what a business-tier tool does with a document and what a free tier reserves the right to do. (CIS 14 Security Awareness and Skills Training)
  6. Check your own promises. Read the engagement letters, the BAAs and the client contracts for AI clauses, and make the policy at least as strict as the strictest one you have signed. (CIS 3 Data Protection)

Where AccuSights fits

Our assessment finds the AI tools already in use, the data they are touching and the contract clauses that make it a problem, and ranks the fixes so the policy lands on evidence rather than hope. The Cyber Hygiene Test takes three minutes for a first score, and 15 minutes with an engineer settles which tool to approve.

The read-only compliance agent shows where AI use and your regulators' data rules collide, mapped to PDPL, DoH or DHA. We have no access and do not remediate; you or your IT partner fix, we show you where.

Questions people ask

Is it a HIPAA violation to put patient information into a consumer AI chatbot? If the tool is a consumer version with no business associate agreement, pasting protected health information into it is a disclosure to a third party that has not agreed to HIPAA's terms, and that is a problem for the practice, not the vendor. Some enterprise AI services will sign a BAA and contractually keep your data out of training. Use one of those, under your own account, or keep patient details out of the prompt entirely.

Can I block AI tools on company devices? Yes, with web filtering on managed devices and a data loss prevention rule that stops uploads of documents to unapproved sites. Blocking alone pushes people to their phones, so pair it with an approved tool that does the job well. The 2026 DBIR figure that most AI use runs through personal accounts tells you what happens when the only policy is no.

What should an AI policy include? Four things on one page: which tools are approved and under whose account; which data may never go into any AI tool, with examples such as client names, patient details, card numbers and source code; the rule that a human checks any AI output before it goes to a client or a regulator; and who to ask when unsure. Add a line about logging and review so people know it is checked, and have everyone sign it.

The paralegal was not the risk. The empty space where a decision should have been was the risk. Fill it this week, on one page, and let your people use the good tools without guessing.

Questions people ask

Is it a HIPAA violation to put patient information into a consumer AI chatbot?

If the tool is a consumer version with no business associate agreement, pasting protected health information into it is a disclosure to a third party that has not agreed to HIPAA's terms, and that is a problem for the practice, not the vendor. Some enterprise AI services will sign a BAA and contractually keep your data out of training. Use one of those, under your own account, or keep patient details out of the prompt entirely.

Can I block AI tools on company devices?

Yes, with web filtering on managed devices and a data loss prevention rule that stops uploads of documents to unapproved sites. Blocking alone pushes people to their phones, so pair it with an approved tool that does the job well. The 2026 DBIR figure that most AI use runs through personal accounts tells you what happens when the only policy is no.

What should an AI policy include?

Four things on one page: which tools are approved and under whose account; which data may never go into any AI tool, with examples such as client names, patient details, card numbers and source code; the rule that a human checks any AI output before it goes to a client or a regulator; and who to ask when unsure. Add a line about logging and review so people know it is checked, and have everyone sign it.

Controls this post maps to

CIS 3 Data ProtectionCIS 2 Inventory and Control of Software AssetsCIS 14 Security Awareness and Skills Training

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.