GreenLoop IT Solutions : Articles
Shadow AI: Personal Email vs. Company Email Accounts, and What GreenLoop Can Do About Each
Executive Summary
- What it is: Employees often have ChatGPT or Claude accounts that exist entirely outside your organization’s visibility — commonly called “shadow AI.” Not all of these accounts carry the same risk, and not all of them can be addressed the same way.
- The distinction that matters: An account tied to a personal email address is invisible to your organization. An account tied to a company email address is visible in principle, even if it was never brought under central management.
- What GreenLoop can do: We can identify accounts tied to your verified company email domain and map a realistic path to bring them under management or retire them. We cannot see accounts tied to personal email addresses, and we don’t perform account-level cleanup ourselves — that requires individual account access we don’t hold.
- Where this fits: This is part of the discovery work in our ChatGPT and Claude security assessment, and any cleanup path we identify is something your organization acts on — either directly, or with our help configuring the policies that prevent it from happening again.
Two Kinds of “Personal Account”
When we talk to clients about shadow AI, “personal account” often gets used as a catch-all, but there are really two distinct situations, and they need to be handled differently.
Accounts tied to a personal email address
These are the ones that create the most risk. An employee signs up for ChatGPT or Claude with a personal Gmail or similar personal address, entirely disconnected from your company’s identity systems. There’s no domain to verify, no admin console visibility, and nothing GreenLoop — or your own IT team — can see about what’s been shared through that account. If sensitive company data has gone through it, it’s effectively unrecoverable from a governance standpoint. The most practical proactive fix for most SMBs is policy and awareness: making it clear which AI tool is approved for company use, and giving employees an approved alternative so there’s no reason to reach for a personal account in the first place.
Accounts registered with a company email address
This is a meaningfully different problem. The account is tied to your domain, which means it can, at least in principle, be identified once you verify that domain with the vendor. It may still be sitting entirely outside your admin console — never provisioned through SSO, never added to a managed workspace — but it’s not invisible the way a personal-email account is. Both ChatGPT and Claude support, at least on their higher plan tiers, mechanisms for identifying these accounts and either migrating them into a managed workspace or having the employee export their data and close the account out.
What GreenLoop Can Do
- Discover. As part of a security assessment, we help identify which employees have accounts tied to your company email domain, using the vendor’s own domain-verification tooling.
- Map a path forward. For company-email accounts, we outline the realistic options — typically either migrating the account’s data into your new managed workspace, or having the employee export and close it — and sequence that alongside your rollout.
- Configure prevention going forward. As part of hardening, we set up domain verification, enforced single sign-on, and — where the plan supports it — enforced account migration, so new accounts can’t be created outside your managed workspace going forward.
What GreenLoop Doesn’t Do
- We don’t access, migrate, or delete individual employee accounts ourselves. That requires credentials and account-level access we don’t hold, and reasonably shouldn’t. The decision and the action belong to your organization and the employee.
- We can’t see accounts tied to a personal email address. There’s no domain to verify and no admin visibility into them — this is a genuine blind spot, and the fix is prevention through policy and an approved alternative, not retroactive cleanup.
A Practical Starting Point
If you suspect this is a meaningful issue in your organization, a straightforward first step is a short, clear policy: communicate which AI tool is company-approved, why, and where employees should direct questions about using AI with sensitive data. Combined with a managed workspace that’s actually pleasant to use, most of the incentive to reach for a personal account for legitimate work goes away on its own.
FAQ
If an employee has a ChatGPT or Claude account tied to their personal Gmail, is there anything we can do about data they’ve already shared?
Not directly. There’s no way for your organization or GreenLoop to access or audit that account. The realistic response is forward-looking: establish an approved company workspace and a clear policy so there’s no ongoing reason to use a personal account for work.
Our employees have accounts tied to their work email, but IT never set them up that way. Can we get those under control?
Yes, this is the more recoverable scenario. Once you verify your email domain with the AI vendor, both ChatGPT and Claude offer tools to identify matching accounts and either migrate them into a managed workspace or have the employee export and close them.
Does GreenLoop do the actual account migration for us?
We identify the accounts and map out the path, but the migration action itself is account-level and is handled by the employee (accepting an invite and choosing to migrate or export) or your organization, not by GreenLoop directly.
How does this fit into the broader assessment?
This is one part of the discovery work covered in our ChatGPT and Claude security assessment. See that article for the full picture of what an assessment covers and how plan selection, identity controls, and this account cleanup all fit together.