CHECKLIST
Shadow AI reduction checklist
Reducing shadow AI does not work through punishment — it works by opening an easier, declared alternative. These items are the transition map.
Eight items that move usage into the register: blameless inventory, past amnesty declaration, opening the gate to two departments, migrating the top three cases, declaring what is recorded, enabling a new-tool request channel, measuring the shift via register, and widening in waves.
THE CHECKLIST
Shadow AI reduction checklist
Eight items moving usage from personal accounts into the register — every item an action with a clear verification criterion.
Tick this list with the security team and transformation leadership — the gaps are the agenda of the next shadow-AI meeting.
This page prints cleanly — suitable as a baseline for tracking the shadow-AI reduction program.
EVALUATION QUESTIONS
Asked in every review.
How do we actually measure the shadow shrinking?
Two indicators from your register: gate usage growth per department and declining exception requests for external tools — plus a recurring blameless survey.
What do we do with employees who refuse to transition?
Start with understanding: is the gate genuinely harder? Is their use case uncovered? Refusal is information before it is a problem.
Eight items. One a week.
Print the list and start with item one this week — then bring your progress after eight weeks: we read the register with you and suggest the next wave.