Skip to content
Lambert Consulting

Artificial Intelligence: A Cross-Functional Offering

Results first. Infrastructure second.

An assistant for your documents, end-of-line verification, a platform for multiple services. Where artificial intelligence is applied is determined by your data, not by a catalog.

See all solutions
4Comparing Architectures, Criterion by Criterion
2 fieldsSoftware and hardware under one roof
All Use CasesUse cases first, technology last

Our first department

This is what needs to work every morning.

Your servers, your workstations, your phone systems, and your identities. The foundation that no one notices as long as it holds, but that everyone notices the day it fails.

View the department
Multi-siteNational and international projects
3Branches in French-speaking Switzerland
View our client projectsCase Studies and References
Let us know how you're doingGetting a quote is free

How We Work

A piece of advice, not a sales pitch.

Our approach is consultative: we tell you what we think, even when it’s not in our best interest. That’s what makes projects succeed.

About Us
1995First project, using Microsoft SMS
Family-orientedOn a human scale and sustainable

Our Branches

Vaud, headquarters9 Avenue des Baumettes, 1020 Renens+41 21 806 37 15
Valais134 Oscar-Bider Street, 1950 Sion+41 27 552 00 22
FribourgChemin de Montmoirin 18a, 1618 Châtel-Saint-Denis+41 26 322 59 05
Monday through Friday8:00 a.m. – 6:00 p.m.
Contact UsFirst 30-minute consultation, with no obligation

Shadow AI: Managing the Use of AI That Your Employees Have Already Adopted

In most organizations, the question is not whether employees are using AI tools that management did not select, but to what extent and with what data. The term “shadow AI” refers to this parallel use: a consumer-grade assistant opened in a browser, a contract excerpt pasted in to be rephrased, or a table of figures submitted for a summary.

Publication Date
5 minReading time
Artificial IntelligenceBlog Feature

The issue is handled poorly because it is almost always addressed through prohibition—which doesn't work—rather than through regulation, which is possible.

Measure Before You Decide

Microsoft Purview offers data security posture management capabilities for AI. It covers Microsoft assistants, but also—and this is what interests us here— third-party AI applications used on company workstations.

Two technical prerequisites are required for this visibility on third-party sites: installing the browser extension Microsoft Purview and integrating the devices with Purview. Without these two elements, the feature works for Microsoft tools but remains unable to detect anything else.

Once in place, it provides information that management can use immediately:

  • visits to third-party generative AI sites, in a category separate from that of Microsoft assistants;
  • sensitive information sent to these sites, detected by the same types of data as your existing rules;
  • activity by user, by application, and by category, viewable in an activity explorer;
  • preconfigured strategies that can be activated with a single click to start collecting this information.

Microsoft has published a list of supported third-party AI sites, which includes the leading consumer-facing assistants on the market.

It takes at least twenty-four hours for these strategies to produce actionable results.

What the measurement generally reveals

The exercise rarely yields the expected result, and that is what makes it useful. Two observations keep coming up.

The first is that the practice is more widespread than estimated, but also more routine: rewriting emails, translation, formatting, and assistance with writing. These are activities that do not involve sensitive data and do not warrant any emergency measures.

The second point is that the few instances of truly problematic use are concentrated among a small number of people, often in the most exposed roles—management, legal, human resources, and finance. These are precisely the people we instinctively assume to be the most cautious.

An organization that has these two findings can establish a proportionate rule. An organization that does not have them will issue a blanket ban that no one will enforce.

Three successive steps: measure performance for four to six weeks, offer an internal alternative, and provide guidance through a one-page rule.
Order matters: a rule written before the fact never reflects actual practices.

Decisions that take effect immediately

Offer an alternative before imposing a ban. Microsoft 365Copilot Chat is included with an Microsoft 365 , and exchanges are covered by your organization’s contractual terms. An employee who has access to an acceptable internal tool is much less likely to look for one elsewhere.

Write the rule on one page. What should not be submitted to any external assistant, what can be submitted, and who to contact if in doubt. A longer document will not be read.

Apply your existing data protection rules to AI tools. The types of sensitive information defined for email and file sharing can be reused as-is.

Address the issue through training rather than disciplinary action. In the vast majority of the cases identified, the employee simply did not know that the tool was saving the information he or she entered.

Note: Purview also allows you to monitor ChatGPT Enterprise workspaces to detect sensitive information shared within them. A company whose teams are already using this tool under a contract can therefore integrate it into its monitoring efforts rather than treating it as unauthorized use.

Our Reading

A blanket ban remains the most common response—and it is the least effective. It has three negative consequences: usage shifts to personal phones, where you can no longer monitor activity; employees who had found a real way to improve their work lose that benefit without compensation; and management believes the problem has been solved, when in fact it has merely been hidden from view.

Our recommendation is to first collect data over a period of four to six weeks, and then draft a policy that takes into account the findings of that data. Doing it the other way around results in a document that is out of touch with actual practices—one that no one follows and that no one dares to enforce.

One methodological point is crucial to the success of this exercise: announce that you’re tracking usage. An organization that discovers after the fact that its visits to AI sites have been tracked loses more trust than it gains in visibility. Explain that you’re tracking usage, explain why, and make it clear that the goal is to establish a useful policy rather than to punish anyone. As a bonus, you’ll see a spontaneous decline in the most questionable behaviors.

We must also acknowledge a limitation of these tools. They can only monitor traffic passing through managed devices and browsers equipped with the extension. An employee using their personal phone remains out of reach, and no technical solution will change that. This is yet another reason to address the issue through policies and alternatives, rather than through monitoring alone.

What to Do

  1. Inform the teams about the measure before implementing it, explaining its purpose.
  2. Set up the two technical prerequisites; without them, you will have no visibility into third-party tools.
  3. Let it run for four to six weeks before drawing any conclusions.
  4. Take advantage of the offer included with your subscription as an internal alternative, before any restrictions take effect.
  5. Write a one-page guideline based on the findings of the assessment.
  6. Address individual cases through explanation, reserving disciplinary action for deliberate behavior.
  7. Review the policy every six months: tools change faster than internal policies.

The technical implementation of this transparency is the responsibility of your administrators and does not present any particular difficulties. What requires more care is how to announce the measure and translate the results into acceptable rules. Lambert Consulting provides support during this stage, focusing on the issue of the applicable framework for data submitted to an assistant, which addresses most of the questions that teams subsequently raise. The reorganization of internal access rights is part of the same governance initiative.

Microsoft Sources

After reading

What an article Can't Know

An article describes what applies to everyone. What varies from one organization to another is the inventory: which applications, which accounts, and which pieces of equipment are actually involved in your organization. The inventory determines the scope of the effort, and it cannot be summarized on a single page.

You'll be speaking directly with the engineers who will be doing the work, not with a middleman. We'll respond within 24 business hours.

If the topic has changed

Check what is still true

Announced dates are sometimes postponed, products are renamed, and conditions change. The blog tracks these topics over time: when a rule changes, a new post announces it.

Search for a topic in the blog