Shadow AI: what to do about the tools nobody approved

Somebody in the business is pasting client material into a chatbot this week. Not out of malice, and probably not in defiance of a rule, because in most small companies no rule exists.
The global study run by the University of Melbourne with KPMG, covering more than 48,000 people across 47 countries, found that 57 percent of employees hide their use of AI and present AI-generated work as their own. The same research put the share who have had any AI training at 47 percent, and the share who say their workplace has a policy or guidance on generative AI at 40 percent. Those three numbers explain each other. People use the tools, nobody told them how, so they keep quiet.
Shadow AI is the name for that gap. It matters more in a 30 person company than in a bank, because the bank has a security team and the 30 person company has a founder who assumed nothing was happening.
What counts as shadow AI
The obvious version is a personal chatbot account used for work. An employee drafts a client email, summarises a contract, or cleans up a spreadsheet in a tool the company has never seen.
The second version is browser extensions. Meeting recorders, summarisers, writing assistants, all installed in two clicks, many of them reading whatever page is open.
The third version is quieter and the most common one now. AI features arrive switched on inside software the company already pays for. A CRM adds summarisation, a helpdesk adds suggested replies, a document tool adds drafting. Nobody made a purchase decision, so nobody reviewed anything, and the data flows under an agreement signed years ago.
The fourth is new and worth watching. Agent-style tools ask for access to email, calendar, files, or a browser session, then act on their own. That is a different risk category from a chatbot window, because it involves standing permissions rather than one conversation.
Why this became normal so fast
Adoption ran ahead of management. The U.S. Chamber of Commerce puts the share of small businesses using generative AI at 58 percent, up from 40 percent a year earlier. Down at worker level, the Chamber Foundation’s first Main Street AI Monitor, an Ipsos survey of just over a thousand people working at US small businesses in May 2026, found about half using AI, and among those users 64 percent said their main application is personal productivity: drafting, summarising, brainstorming.
That is the shape of the problem. The use is individual, it is small, and it produces a visible time saving for the person doing it. No procurement process exists for a habit. A marketing coordinator who cuts an hour off a draft will not file a request and wait two weeks, and the coverage in the business press keeps arriving at the same conclusion, that employees adopted these tools before employers noticed.
What the real exposure looks like
Data leaving the company is the first one. The UK’s National Cyber Security Centre, in its guidance on AI and cyber security, makes a point worth repeating to staff in plain words: queries sent to a public AI service are visible to the provider and may be used to improve it. Paid business tiers usually change that default, which is precisely why the tier matters more than the brand. The same guidance is blunt about prompt injection, which cannot be fully engineered away because these models do not enforce a boundary between instructions and data, and about moving carefully with agent-style tools that can take action.
Client contracts are the second, and the one that catches professional services firms. Plenty of agency and consulting agreements include confidentiality clauses that say nothing about AI and still prohibit disclosing client material to third parties. A chatbot is a third party. Nobody has to hack anything for that to become a breach of contract.
Accuracy is the third, and it costs more often than the other two. Work goes out with a fabricated citation, a wrong number, or a summary that inverts the meaning of a clause, and the person who pasted it in did not check because the output read fluently. Hidden use makes this worse, since nobody reviews what nobody admits to producing.
Then there is the version that shows up later. A regulated business, an acquirer’s due diligence, or a large customer’s security questionnaire asks which AI systems process their data. Answering honestly means knowing, and most companies do not.
Ownership belongs on the list too, quietly. Work produced with heavy AI assistance sits on uncertain ground in copyright terms in several jurisdictions, which rarely matters for an internal summary and matters a great deal for a logo, a jingle, or a piece of code a client expects to own outright. Agencies selling deliverables should know which of their outputs fall in that second group.
What is overstated
Not every worry deserves equal weight. Two get repeated more than the evidence supports.
The first is the blanket claim that anything typed into an AI tool trains the model and reappears elsewhere. Business and enterprise tiers from the major providers are excluded from training by default under their own terms, and consumer tiers usually carry a setting for it. What is true, and what people should understand, is that the company’s data now sits with another vendor under that vendor’s terms, which is a supplier risk question rather than a science fiction one.
The second is that employees using AI are cutting corners. The productivity data says most of the use is drafting and summarising, which is the same category of help a template or a colleague provides. Treating it as misconduct is how companies end up with the worst outcome, which is heavy use that nobody will discuss.
Why bans on shadow AI do not work
A prohibition with no approved alternative changes behaviour in one way only. People stop using the company laptop for it and switch to a phone, where there is no logging, no data loss prevention, and no chance of noticing anything.
The Melbourne research points the same direction. When training and guidance are missing, concealment goes up. The fix is not tighter language in the handbook; it is giving people somewhere legitimate to do the work.
A practical week
Ask before you audit. Send one message to every team asking which AI tools they use for work, including the ones inside existing software, and say plainly that nobody is in trouble. Underreporting is guaranteed if the framing is disciplinary.
Check the software you already buy. Read the recent release notes for the systems holding customer or employee data, and look at which AI features are switched on by default.
Look at expenses. Personal AI subscriptions get reimbursed all the time, and a card statement is a decent inventory.
Pick one or two approved tools and pay for the business tier. This is the step that does most of the work, because it moves usage onto an account the company controls, with training excluded and administration available.
Write the rules on one page. What can go in, what cannot, what has to be checked by a person, and what has to be disclosed. A written AI policy is the thing every later question depends on, from a client questionnaire to an insurance renewal.
Say what disclosure means. Most disputes about hidden use come from an unstated expectation. Decide whether AI-assisted drafting needs flagging internally, to clients, or not at all, then say so once and consistently.
The one-page policy, roughly
- The approved tools, and the account type people must use
- Categories of data that must never be entered anywhere, listed as examples rather than principles
- Which client contracts restrict third-party disclosure, and who checks before AI touches that work
- Who reviews AI-assisted output before it leaves the company, and for which types of work
- Disclosure expectations internally and externally
- Rules for agent-style tools, especially anything requesting access to email, files, or a browser session
- Who to ask about a tool that is not on the list, with a named person and a short answer time
- A review date, because this list goes stale in months
Most of this fits on a single page and takes an afternoon to write. The reason it rarely gets written is that it feels like admitting the company has a problem, when the truthful version is that the company has employees who found a faster way to work and were never told where the edges are.
Companies that get this right end up with less exposure and better information. They know what is being used, they pay for the tier that protects them, and they hear about the useful tools from the people who found them first.






