The explosion of shadow AI exposes SMEs to data leaks. MSPs have a role to play with their clients in implementing effective governance and appropriate controls.
Within French SMEs, as everywhere else across the world, the AI revolution is underway: employees use ChatGPT to write commercial offers, Claude to analyze customer data, Gemini to prepare internal presentations… All this, naturally, without talking to their CIO. So, without formal authorization or any data governance policy.
This phenomenon has a name: Shadow AI. And unlike the Shadow IT of the 2010s, its implications are on a completely different scale. Because AI does not just host data: it absorbs it, processes it, learns it, uses it and can thus disclose potentially confidential information.
A massive blind spot, documented and yet underestimated
The figures are clear. In the USA, according to IBM, 80% of American office workers use AI in their work, but only 22% of them rely exclusively on tools provided by their employers. According to a Microsoft France / YouGov study from January 2026, carried out among 657 executives and managers, 61% of corporate AI users use their personal accounts at least once a week — outside of any IT framework. They are not interns: they are decision-makers, salespeople, lawyers, accountants.
Globally, 38% of employees admit to having shared sensitive professional information with AI tools without their employer’s permission (CybSafe / NCA, 2024). Contracts, HR data, financial forecasts, customer databases are all data disclosed without anyone in the organization being informed.
France presents a notable particularity. According to Okta’s global AI Agents at Work 2026 study, it has the lowest rate of Shadow AI globally, where 52% of employees worldwide admit to using unapproved AI tools. Should we be happy about it? Not necessarily. This result reflects more generally a more cautious adoption of AI in business than a truly more mature governance. Because according to the Impact AI Responsible AI Observatory (2025), only 9% of French employees can refer to an ethical charter or a dedicated contact regarding AI within their company. Discretion is not compliance.
The three blind spots of AI governance
The rise of ‘Shadow AI’ generates both governance and security problems for which 3 main blind spots seem to emerge:
- Managing personal accounts. When an employee accesses an AI tool through a personal account — not through a federated corporate account — no conditional access controls apply, no DLP policy can intercept exchanges, and the shared data can be fed into the vendor’s training models. It’s a data exfiltration that doesn’t trigger any alerts.
- Identity management. Indeed, effective AI governance solutions rely on integration with existing IAM (Identity and Access Management): they make it possible to know who is using what, to force SSO authentication on approved tools, and to block non-compliant access at the proxy or endpoint level. Without this layer, any usage policy remains declarative.
- The uncontrolled proliferation of tools. The most mature AI organizations already use more than 300 GenAI tools according to Gartner (2026). For an SME, the reality is more modest — but just as opaque: dozens of browser extensions, APIs connected to business tools, AI agents integrated into third-party SaaS, whose data flows no one has mapped.
AI governance: moving from declaration of intent to real visibility
The outright ban showed its limits very quickly. Amazon, JP Morgan and several major European banks attempted to block access to ChatGPT and other consumer tools — only to find that their employees continued to access them via their personal devices or connections outside the corporate network. The fundamental problem is that generative AI services use captured data to continue learning, with a real risk of disclosure to third parties — a reality that banning alone does not solve.
In France, the situation remains, for the moment, still contrasting. According to the Salesforce 2025 study, 58% of French employees using generative AI at work do so without a framework defined by their employer, and almost half use tools that their company has explicitly prohibited. At the same time, only 9% of French employees can refer to an ethical charter or a dedicated contact regarding AI within their company (Impact AI, 2025). In the absence of a framework, it is a gray area which grows silently.
The operational response cannot be based on prohibition, nor on awareness raising alone. It requires a control architecture: continuous discovery of GenAI tools active in the environment, inspection of prompts to intercept sensitive data before transmission, and enforcement of policies at the identity level — not just the network. It is on this condition that AI governance ceases to be declarative and becomes real.
What this means in practice for MSPs
Shadow AI isn’t an awareness problem — it’s an architecture problem. To answer this, IT service providers must think in terms of data flow, not just usage policy. For this, three building blocks are essential to constructing their response:
- The first brick is application discovery: it must make it possible to continuously identify which GenAI tools are active in the customer environment — browser extensions, third-party APIs integrated into SaaS, AI agents embedded in business tools. Without inventory, any policy remains blind.
- The second concerns the inspection of prompts: they must be able to analyze the content of exchanges with public models in order to detect the transmission of sensitive data – personal data (PII), financial data, intellectual property – before it leaves the company perimeter. This is the DLP layer applied to AI interactions.
- Finally, controlling access at the identity level constitutes the third brick: forcing authentication via SSO on approved tools, blocking access to public models via personal accounts at the proxy or endpoint level, and applying conditional access policies according to the user profile.
For French SMEs, the IT service provider is often the only actor able to implement this governance in an operational and proportionate manner. MSPs who integrate Shadow AI monitoring into their offering are not doing additional cybersecurity: they are providing a concrete – and immediate – response to a growing concern that their clients are beginning to perceive – often too late – about monitoring company workflows.
Those who have structured their response in advance in 2026 will therefore naturally be better positioned than those who wait for the first customer incident to react.