Shadow AI sounds like a technology problem, but it usually starts as an ordinary work problem. A person has too much admin, a deadline is close, and a public AI tool gives a useful answer in seconds. The behaviour feels harmless because the intention is good. Someone wants to summarise a client email, draft a reply, clean up notes, translate a document or compare options before a meeting.
The issue is that the information being pasted into the tool may be personal information, confidential business information, or both. In a South African context, that immediately raises POPIA questions. What information was shared? Was there a lawful basis for processing it in that way? Where did it go? Was it stored by the provider? Could it be transferred outside South Africa? Who approved that route?
I do not think the practical answer is to shame staff for using useful tools. In most cases, the team is trying to get work done. The failure is usually upstream: the organisation has not given people a clear alternative, a clear boundary, or a plain-language rule for what may not be put into public AI.
If your team has no AI rules, staff will create their own rules under pressure.
That is why the first step is not a grand AI strategy. It is a review of actual use. Which tools are being used? Which teams are using them? What kinds of information are being pasted, uploaded or generated? Are people using personal accounts, company accounts or browser extensions nobody has approved? Are they processing names, ID numbers, health details, financial records, contracts, internal strategy or customer complaints?
Once the real behaviour is visible, the organisation can make calmer decisions. Some use cases can stay in public tools if the data is non-sensitive and the terms are acceptable. Some should be moved into a controlled workflow. Some should be blocked until there is a better process. Some should run on local models, especially when the organisation needs tighter control over prompts, documents, logs and outputs.
POPIA-aware AI adoption is not only about privacy notices. It is about daily routing decisions. A staff member needs to know whether the information is safe to use, whether it must be anonymised, whether it needs approval, and whether it belongs in a local tool instead of a public one. If the answer depends on legal language nobody understands, the rule will not survive a busy Tuesday afternoon.
The review I prefer is direct: map the tools, map the data, map the decisions. Then write the findings in language a manager can use. The output should not be a thick policy that sits unread. It should identify the risky habits, the quick controls, the workflows that need rebuilding, and the few rules that staff can remember.
Shadow AI is already inside many organisations because AI is easy to reach. The response should be just as practical. Give people an approved way to use AI, a safe place for sensitive work, and a clear line around client data. That is where POPIA-aware implementation starts.