AI Rules for Staff: 9 Policies That Actually Prevent Shadow AI Problems
Updated August 22, 2026
On May 5, 2026, an employee at Community Bank, the banking subsidiary of CB Financial Services, ran a batch of non-public customer data through an AI tool that IT and compliance had never signed off on. Names, Social Security numbers, dates of birth, all of it. Six days later, CB Financial filed a Form 8-K with the SEC calling the incident material, and it turned out to be the first time a public company had made that kind of disclosure without a hacker, a ransomware gang, or a stolen password anywhere in the story. Just an employee looking for a shortcut.
Nobody broke in. Nothing about this fits the usual definition of “hacked.” An employee, almost certainly trying to save time, fed real customer records into an AI application that wasn’t vetted or covered by the bank’s data-handling policies, and that was enough on its own to trigger a federal disclosure requirement, an outside cybersecurity investigation, and calls to regulators. If your business still doesn’t have written AI rules for staff, this is the story that should finally move it off the someday list.
Shadow AI Is Already Inside Your Business
Community Bank just happens to be the one that got caught in public. Verizon’s 2026 Data Breach Investigations Report, the same annual study we cite across our security research, found that 45% of employees are now regular AI users on their corporate devices, up from just 15% a year earlier. Of those employees, 67% are reaching AI tools through personal, non-corporate accounts, which puts that activity completely outside whatever protections IT has in place. Shadow AI use is now the third most common non-malicious insider action in Verizon’s data loss prevention telemetry, a fourfold jump from the year before, and source code is the single most common thing employees paste into public AI tools, ahead of business records, internal documents, and everything else on the list.
None of this means your staff is reckless. It means AI got useful faster than most companies wrote policy for it. Most employees aren’t sneaking around; they’re reaching for whatever tool is already open on their phone, and if that happens to be a personal account instead of something IT approved, they don’t think twice about it.
9 Rules for Setting Up AI Guidelines Your Staff Will Actually Follow
Generic “use AI responsibly” guidance doesn’t stand a chance against a compliance deadline or a genuinely helpful chatbot at 4:45 on a Friday. The rules below are specific enough to change how people actually behave day to day, and light enough that nobody quietly ignores them.
1. Name the Tools Employees Are Allowed to Use
Publish an actual list, by name, of the AI tools your staff is allowed to use, and keep it updated as new ones get approved. A policy that just says “use AI responsibly” with nothing specific behind it pushes people toward whatever tool they already have open in a browser tab, which is exactly how shadow AI starts. You don’t need to sanction every tool on day one. Three or four approved options that cover drafting, research, and coding is enough to start with.
2. Draw a Hard Line on What Never Goes Into a Prompt
Spell it out. Social Security numbers, dates of birth, account numbers, health information, source code, anything under a client NDA: none of it gets typed, pasted, or uploaded into an AI tool, sanctioned or not. This is the one rule that would have stopped the Community Bank incident before it started, and it should be short enough to fit on an index card. A rule people have to go dig up to remember is a rule they’ll skip when they’re in a hurry.
3. Put One Person in Charge of Approving New Tools
Give one person, not a committee, ownership of a simple intake process. An employee finds a tool they want, sends a two-line request, and that person checks it against your data policies and approves or declines it within a few days. This is exactly the kind of governance question that’s easier to work through with an outside IT consulting partner than to figure out from scratch. If getting a new AI tool approved takes six weeks and a form nobody can find, people will just use it anyway without asking, which is the exact problem you’re trying to fix.
4. Require a Human to Review Anything That Leaves the Building
Anything AI-drafted that’s heading to a customer, a regulator, a vendor, or the public (an email, a contract, a financial summary, a piece of marketing copy) gets read by a person before it goes out. AI tools sound just as confident when they’re wrong as when they’re right, and an employee who trusts that first draft a little too much is exactly how a fabricated number ends up in front of a client.
5. Get Visibility Into What’s Actually Being Used
You can’t govern what you can’t see. If you’re already running Microsoft 365 with Purview Sensitivity Labels in place, Microsoft Purview’s Data Security Posture Management (DSPM) for AI extends that same protection into AI activity: it shows which AI tools employees are actually accessing, flags sensitive data going to unsanctioned platforms, and carries those existing labels into whatever gets pasted into a prompt. Given that most AI use is happening through personal accounts, per Verizon, a lot of companies have no idea what’s going on here until something like this is turned on.
6. Actually Train Your Team on the Rules
A policy buried in the employee handbook that nobody reads doesn’t count as training. Sit your team down for fifteen minutes and walk through real examples: what’s fine to ask an AI tool, what isn’t, and why. A short session covering three or four actual scenarios sticks better than a five-page document nobody opens after the first read.
7. Give People a Low-Friction Way to Report a Mistake
Someone will eventually paste something they shouldn’t have. The only real question is whether you hear about it that day or from a regulator months later. Make reporting easy and blame-free: a Slack channel, an email address, whatever your team already uses. Treat every report as a chance to close a gap instead of a reason to write someone up. Community Bank’s own filing noted the bank moved to secure the data as soon as it was discovered. The businesses that come out ahead in situations like this are usually just the ones where problems get flagged quickly.
8. Anchor Your Rules to a Real Framework
You don’t have to build AI governance from scratch. NIST’s AI Risk Management Framework, the federal framework most enterprise AI policies reference, breaks AI risk into four functions: govern (who’s accountable), map (where AI is used and what data it touches), measure (how you’re tracking risk), and manage (what you actually do about what you find). You don’t need a compliance department to use it as a checklist. Even a two-page policy that hits all four of those areas holds up better than a pile of ad hoc rules.
9. Revisit the Rules Every Quarter
AI tools and their data-handling terms change faster than almost any other software category your business relies on. A policy written around one tool’s retention practices in early 2026 could be out of date by December. Put a recurring 15-minute review on the calendar (quarterly is plenty) to check that your approved tool list, your no-go data list, and your intake process still match how people are actually working.
The Bottom Line
Community Bank wasn’t breached by a sophisticated attacker. An employee tried to work faster and reached for a tool nobody had vetted, and that’s the AI risk most businesses are actually facing right now: not some hypothetical hacker, but well-meaning staff filling a policy gap with whatever’s fastest. Nine rules close that gap: name your tools, draw a hard line on sensitive data, put someone in charge of approvals, require human review, get real visibility into usage, actually train people, make it safe to report mistakes, anchor everything to a real framework, and revisit it regularly. None of that slows your team down or takes away a technology that’s genuinely making them more productive. It just gives it some guardrails.
Book a Free Consultation
Not sure where your AI policy stands, or whether you even have one? Let’s talk. Book a time on my calendar and we’ll go through what AI tools your team is already using, what’s exposed, and what a policy people will actually follow looks like for your business, as part of a broader cybersecurity program built around how your team actually works.
Frequently Asked Questions
Shadow AI is employees using AI tools, like ChatGPT, Gemini, or Copilot, without IT or compliance approval, often through personal accounts on work devices. It’s now the third most common non-malicious insider action tracked in Verizon’s 2026 DBIR, up fourfold from the year before.
In May 2026, an employee at Community Bank used an unauthorized AI tool to process non-public customer data, including names, Social Security numbers, and dates of birth. The bank’s parent company, CB Financial Services, disclosed it in an SEC Form 8-K on May 11, 2026, the first public disclosure of its kind triggered by internal AI misuse rather than an external cyberattack.
Not really. Banning AI tends to push usage further underground instead of stopping it. A short list of approved tools, a clear rule about what data can never go into a prompt, and a fast approval process for new tools cover most of the risk while still letting your team use AI productively.
Very common. Verizon’s 2026 DBIR found 45% of employees are now regular AI users on corporate devices, and 67% of that usage happens through personal, non-corporate accounts, outside any protections a company might have in place.
NIST’s AI Risk Management Framework is the most widely referenced starting point. It organizes AI governance into four functions (govern, map, measure, and manage) and works as a practical checklist even for businesses without a dedicated compliance team.
If you’re on Microsoft 365 with Purview Sensitivity Labels in place, Microsoft Purview’s Data Security Posture Management (DSPM) for AI shows which AI platforms are being accessed on company devices, flags sensitive data shared with unsanctioned tools, and extends your existing data protection labels into AI interactions.