Walk into any campus office right now and someone’s likely to be pasting text into ChatGPT — drafting an email, summarizing a policy, cleaning up a spreadsheet. A student advisor running retention-risk data through it. A recruiter using it for outreach. No approval. No training. It’s just happening.  

This is “shadow AI,” and it’s already the operating reality on most campuses today. A recent survey cited in Ed Tech Digest   found that 78% of education employees know of colleagues using unauthorized AI in their work. The practice is both a genuine security exposure and a signal of where many people want to innovate.

But herein lies the rub: Clamp down too hard on shadow AI and you lose potential innovation. Ignore it and you’ve got an ungoverned tool touching student data with nobody watching. So, what should we do?

Why Blanket Banning Shadow AI Backfires

The natural response from IT, enrollment/admission and compliance teams is to lock shadow AI down by blocking domains, sending a policy memo, or reminding everyone about FERPA. It feels like the responsible approach — after all, unmonitored data leaving your institution is a real risk — but it also feels like theater.

Staff who’ve found a tool that saves them two hours a day aren’t going to give it up because of a memo. More than likely, they’ll just stop mentioning it. Bans push the behavior underground, where there’s no visibility into what data is being pasted where, and no way to catch a mistake before it becomes a problem. A well-meaning advisor who feeds a student’s academic record into a consumer AI tool to “help write a note” has just created a data exposure nobody in IT knows about.

There’s a second cost, too: a reprimand communicates to your most motivated people that curiosity isn’t welcome. Staff looking for a better way to do their jobs are exactly who you want to keep engaged and motivated to continually seek new ways to innovate. They shouldn’t be shamed into silence, or, to stick with the metaphor, relegated to the shadows.

Provide Resources Rather Than Reprimands

Instead of stopping at “no,” ensure staff that everything they were doing in the shadows can be done in plain daylight, that is, with approved tooling. And then provide the resources to help them innovate safely. The good idea survives, employees can continue to do their jobs more efficiently, and the risk is mitigated.

That’s the real lesson in shadow AI: every time you have to reach for the stick, it’s worth asking what the carrot should have been in the first place.

6 Ways to Bring Shadow AI into the Light  

Meaningfully addressing shadow AI is more complex than writing the perfect policy and praying team members fall in line. It’s a delicate act of balancing a handful of concrete mechanisms working together — some in place before you open the AI door to broader use; some designed to catch good ideas as they emerge.

1. Build the strategy and guardrails before you open things up broadly.

Start with governance. Decide up front who owns data decisions, what’s off limits (anything touching a student ID, SSN, or other FERPA-protected data), and what the escalation path looks like. It doesn’t have to be perfect. Begin with a data-into-AI policy and mandated work accounts, then improve from there.

2. Stand up real sandboxes, not just permission slips.

Give people a contained space to experiment with safe, non-production data, so trial and error don’t carry real risk. Some institutions, like Harvard and the University of Oklahoma, have done this well, creating sandbox environments where students, faculty, and staff experiment and have a genuine voice in AI projects.

For example, instead of advisors pasting real student records into ChatGPT to draft outreach, an institution can stand up a sandboxed tool pre-loaded with a synthetic dataset — fake names, enrollment statuses, and balances built to look and behave like the real system. Advisors get room to experiment with drafting templates and testing tone for a missing-FAFSA reminder with zero exposure, since none of the data is real.

3. Give everyone a basic tier of access before anything has to go through a committee.

Let people try a sanctioned tool at a minimal level before making a formal case for it. A low-stakes way to test an idea lets staff find out for themselves whether it’s worth bringing forward — so the ideas that do reach committee are already vetted, and nobody feels blocked just for wanting to explore.

4. Create a real intake process…with real people.

A standing group of people genuinely invested in AI succeeding in their own corner of the institution does two things: gives staff a real path to resources for a good idea, and signals a fair, intentional process rather than access handed out based on who you know. Just as important, don’t let the committee become a bottleneck. The goal is a lightweight, trusted framework, not another approval gauntlet.

5. Showcase and celebrate what people build.

When someone outside the formal process builds something genuinely useful, invite them in to show it off. Celebrating and sharing good ideas shifts culture more than a policy memo, signaling that innovation is noticed and rewarded. Define a champion group – to help spur usage and safety.

6. Choose ongoing training over a one-time rollout.  

Access without training just relocates the risk. Capabilities shift fast enough that even long-time users still find real gaps when they revisit the basics. A standing commitment to refreshing knowledge for everyone, regardless of their level of experience, establishes a culture of continual learning.

Shadow AI Isn’t Really a Technology Problem

It’s a trust and infrastructure gap. Staff found a solution faster than the institution could build a safe way to offer it. Closing that gap quickly, with genuine curiosity about what people are actually trying to solve, does more for data security than any blocklist ever will. Best of all, it turns curiosity into an institutional advantage instead of a liability.

The campuses that get ahead of shadow AI won’t be the ones with the strictest policies — it will be those that notice where their people are already innovating and supply real sandboxes, defined access tiers, and a solid process.

If you need help establishing governance for AI on your campus, increasing your data security, or cleaning up your data ahead of broader AI adoption, the experts at SIG can help.

Written by: Ellen Daley and Ryan Millbern