Printify’s question that mattered most wasn't which AI tools were unapproved. It was what happened inside the ones that already had sign-off.
An employee could open Claude or ChatGPT, tools the company itself had rolled out, and paste a customer's Social Security number, a contract figure, a piece of proprietary code, and nothing would catch it.
The security team could say what tools existed. They couldn't say whether the data inside them was safe. Shadow AI made that gap worse, sitting in a place nobody could see at all.
The company had one policy for everyone: block what IT knew about. For a team that needed a tool, that policy got in the way.
For data leaving through a tool the company had already approved, it did nothing, because it was built to police which tools people opened, not what they typed once they were already inside one.