Stopping the Shadow AI Problem
The article discusses the risks of "shadow AI," where staff use public AI tools without IT oversight, potentially compromising sensitive data. It suggests using local AI models like eLLM to keep data secure while still providing AI assistance.
The problem nobody put on the risk register
Somewhere in your organisation right now, a member of staff is probably pasting a chunk of text into a public AI chatbot. Maybe it's a draft policy document. Maybe it's a spreadsheet of student data they want summarised. Maybe it's an email thread with a parent or a supplier that they want rewritten more diplomatically.
None of this is malicious. It's just someone trying to get their job done quickly, using a tool that happens to be free, familiar, and a browser tab away. But once that information leaves your building through a public AI service, you have no way of knowing where it goes, how long it's kept, or whether it ends up feeding someone else's model.
This is shadow AI: AI tools being used across an organisation without IT's knowledge, approval, or oversight. Unlike shadow IT before it, which was mostly about unsanctioned apps and file sharing, shadow AI comes with a sharper edge. The data going in is often sensitive by nature, and the tools doing the processing sit entirely outside your control.
For education and public sector organisations in particular, this isn't a hypothetical risk. Staff records, student data, safeguarding information, and internal correspondence all carry obligations around how they're stored and processed. A well meaning member of staff trying to save time can, without realising it, create a data protection problem that lands on IT's desk months later.
Why banning AI outright doesn't work
The instinctive response is to block access to public AI tools. In practice, this rarely holds. People find workarounds, use personal devices, or simply stop mentioning that they're using AI at all, which makes the problem harder to see, not easier. Staff have found these tools genuinely useful, and taking that away without offering an alternative tends to just push the behaviour further out of sight.
The more sustainable fix is to give people an AI assistant that does the same job, but keeps the data where it belongs.
How eLLM addresses this
eLLM, the Essington Local Language Model, is built around the idea that an organisation should be able to offer AI capability to staff without losing control of its own data.
Local models keep sensitive data in house.
Rather than sending queries out to a third party service, eLLM can run AI models directly on your own servers. Staff get the same conversational assistant experience, but the data never has to leave your infrastructure to get an answer.
Cloud models are available, but on your terms.
For organisations that also want access to larger cloud based models for more demanding tasks, eLLM supports this as an option rather than a default, with privacy controls and budget management so cloud use stays deliberate and visible rather than incidental.
Automatic routing keeps the right queries in the right place.
eLLM can direct straightforward questions to local models and reserve cloud models for the tasks that genuinely need them, so nothing goes further afield than necessary.
MCP connected tools stay governed.
Where staff want an AI assistant to interact with other systems, calendars, ticketing, document stores, and so on, this happens through a managed process with approvals and audit logs, rather than an unmonitored connection to a browser extension or third party plugin.
Query governance adds a further layer of oversight.
Administrators can configure eLLM to flag or block queries that raise a concern, giving IT and safeguarding teams visibility they simply don't have when staff are using public tools.
The outcome
Staff keep the AI assistance they've come to rely on for drafting, summarising, and answering everyday questions. IT gets back the thing that shadow AI took away: knowing where organisational data goes, and having a governed system in place instead of a patchwork of personal accounts on public services. It isn't about restricting what people can do. It's about giving them a way to do it that doesn't leave your organisation's data protection posture up to chance.
Learn more
The eLLM Knowledge Base covers the detail behind each of these features, including how local and cloud models work together, how MCP tools are approved and audited, and how query governance is configured.
person people found this useful.