Governance & Compliance
Sanctioned vs. unsanctioned AI
Sanctioned AI is the tooling an organization approved and contracts for; unsanctioned AI is everything else employees actually use. Governance lives in the gap.
Sanctioned AI has been through procurement: reviewed terms, an enterprise tier, a DPA, admin controls. Unsanctioned AI is the long tail in actual use — personal accounts of the same products, plus niche tools nobody registered. Most organizations discover the second list is longer than the first.
The distinction is account-level, not product-level: ChatGPT can be both, on the same laptop, in adjacent tabs. That is why URL blocking misfires and why discovery plus account-aware, prompt-level controls became the standard approach to closing the gap.
Where this shows up
Related terms
See it in your own organization.
Sanitized AI inventories the AI tools in use and redacts sensitive data from prompts before it leaves.