← Back to Field Notes
Governance

Shadow AI in Microsoft 365: How MSPs Detect, Govern, and Reduce Risk

By Lemhi Team ·

Shadow AI in Microsoft 365: How MSPs Detect, Govern, and Reduce Risk

Shadow AI is any AI tool that employees use for work purposes without the organization’s approval, monitoring, or governance. In Microsoft 365 environments, shadow AI typically shows up as personal ChatGPT or Claude accounts pasted with company data, browser-based AI extensions, ungoverned Copilot agents, and consumer-grade summarizers running over confidential email. Shadow AI is the single largest source of unmanaged AI risk inside SMBs in 2026 — and it is the failure mode that AI Acceptable Use Policies, Continuous Scanners, and the VCAIO role exist to address.

How MSPs Detect and Govern Shadow AI in Microsoft 365

Shadow AI is the conversation your SMB clients are about to ask you about, whether or not they know the term yet. CoreView’s 2026 State of AI in Microsoft 365 report found that 70% of C-suites encourage AI use, but 53% of admin teams say AI is deploying faster than the safeguards. That gap is shadow AI in plain language. Microsoft now publishes shadow AI guidance on Microsoft Learn. New entrants like OpenClaw and Agent 365 are tooling against it specifically. The category is heating up.

For MSPs, shadow AI is both a risk surface and a revenue surface. It is a risk surface because the data exposure is real: confidential client information, financial detail, customer PII, and IP routinely end up pasted into consumer-grade chat windows. It is a revenue surface because shadow AI is the most concrete, most leadership-visible reason an SMB needs a TaaS practice. Nobody on the executive team has to be convinced shadow AI matters.

The MSP playbook is four steps.

  1. Inventory. Use observability (egress monitoring, SaaS sprawl detection, browser-extension audits, the Continuous Scanner against M365) to build a real picture of which AI tools are in use, by whom, and against which data sources. Self-report surveys are not enough — employees underreport.

  2. Categorize. Each tool falls into approved, conditional, or blocked. The categories are decided in the AI Council by the executive sponsor on the VCAIO’s recommendation. Document the rationale.

  3. Govern. Write the AUP to match the inventory. Update sensitivity labels and conditional access policies so that high-classification data cannot reach blocked tools. Train employees on the categories with concrete examples.

  4. Enforce continuously. Re-scan the environment every month. Surface AUP violations to the VCAIO. Bring high-volume violations to the Council. Refresh training when a new tool category emerges.

The mistake most MSPs make is treating shadow AI as a one-time discovery exercise. By the time the inventory report ships, a new wave of consumer AI features has already entered the environment. The Continuous Scanner exists because the inventory has to be a running process.

Why Shadow AI Is the SMB Risk Surface That Cannot Wait

For SMB leadership, shadow AI is the version of AI risk that does not require a technical briefing to understand. Your employees are using AI to do their jobs. Most of them are doing it through personal accounts. None of those accounts are governed by your IT team. Whatever your AI policy says, the actual behavior in your environment is happening one browser tab away from your data.

The exposures are concrete:

  • Confidential client data pasted into consumer chat windows. Once in, gone — depending on the vendor’s training and retention policy.

  • Regulated data (HIPAA, financial records, PII) processed by tools that have no compliance footprint.

  • IP and product plans summarized by an AI tool the company has no contract with.

  • Customer correspondence routed through summarization extensions that have access to entire inboxes.

The fix is not banning AI. Banning AI inside an SMB in 2026 is the same as banning email in 2002 — it doesn’t work, and it makes you uncompetitive. The fix is governing AI: an approved list, a real AUP, employee training, continuous monitoring, and a Council that revisits all four when the landscape shifts. IBM’s 2025 Cost of a Data Breach report found breaches involving shadow AI cost more on average than fully governed environments — the math favors the practice.

How Lemhi Powers Continuous Shadow AI Discovery for MSPs

Lemhi treats shadow AI as a continuous discipline, not a project deliverable.

  • The Continuous Scanner runs against client M365 environments throughout the engagement. Permissions, sensitivity labels, sharing risk, agent inventory, and shadow AI signals surface to the PSA ticket queue as findings, not as a one-time report.

  • Standardized AUP templates. First draft in Phase 1, revised in Phase 3 based on observed real-world usage. Reviewed in every Monthly AI Council. The AUP evolves with the environment.

  • AI Council shadow AI segment. The Council’s Measurement Review block surfaces shadow AI signals each month — what tools showed up, what data they touched, what owners need to act.

  • Coordination with the VCISO. Where shadow AI overlaps with security posture or data classification, the VCAIO and VCISO coordinate. The MSP delivers both motions without duplicating the work.

  • Engage-led discovery. Lemhi Engage’s Tenant Readiness check surfaces shadow AI signals during Phase 0, so the proposal the MSP brings to the SMB already names the problem in dollar terms.

Shadow AI is not solvable by tooling alone. It is solvable by the practice — a VCAIO who owns the AUP, a Council that makes the decisions, and a Continuous Scanner that keeps the inventory current. Lemhi is how MSPs deliver that practice at portfolio scale.

Related Field Notes

See the readiness score and use-case map in action.

You've read the notes. Now see the playbook and the platform behind them.

Book a Demo