Decode & Grow

Shadow AI: The Tools Your Team Uses That You Don't Know About

Short answer: Shadow AI is staff using AI tools that haven't been approved, usually on personal accounts, often with company or client data. It's near-universal, it's a friction problem rather than a discipline problem, and the effective response is to make the approved path easier — not to issue a ban that pushes usage further out of sight.

Why it happens

Almost never out of disregard for policy. The pattern is consistent: someone has a task that AI makes dramatically faster, the company has no approved tool or a cumbersome one, so they use their own account. From their perspective they're being resourceful. Often they are.

The second driver is that AI features arrive inside tools already in use. A note-taking app adds a summarisation feature; a browser extension offers to draft replies. Nobody chose these, and nobody registered them.

What risk it actually creates

  • Data protection. Client personal data entering a consumer-tier tool with no DPA, potentially used for training, potentially transferred without a mechanism. This is the material risk.
  • Confidentiality. Client contracts frequently prohibit third-party processing without consent. An employee pasting a contract into a chatbot may breach it.
  • Compliance gaps. Your AI use register is incomplete, so your risk classification is wrong and your literacy training doesn't cover what's actually used.
  • Quality and consistency. Unreviewed output going to clients, with no standards applied.
  • Continuity. Work and prompts living in a personal account that leaves with the person.

Why bans don't work

A prohibition without a viable alternative doesn't stop the behaviour — it stops the reporting of it. Usage moves to personal devices, where you have no visibility, no logging, and no ability to train people on how to do it safely. You've converted a manageable risk into an invisible one.

Organisations that ban AI and don't provide alternatives consistently discover, when they eventually survey, that usage was widespread throughout.

What works instead

1. Amnesty, then inventory. Ask openly what people are using, state clearly that nobody is in trouble, and mean it. The information is worth far more than the enforcement.

2. Provide a good approved tool. The most effective single measure. If the sanctioned option is at least as capable and easier to access than the unsanctioned one, shadow use largely evaporates. A business-tier subscription for the team costs less than the risk it removes.

3. Make the rules concrete. Not "use AI responsibly" but a specific list of what must never be entered and what's fine. People follow rules they can apply.

4. Create a route for new tools. A lightweight request process — name the tool, the use, the data involved — assessed within a week. Slow approval processes generate shadow AI on their own.

5. Train rather than police. Someone who understands why client data shouldn't go into a consumer tool makes better decisions in situations your policy didn't anticipate.

How to find it

  • Ask directly, without consequences.
  • Review expense claims and card statements for subscriptions.
  • Audit connected third-party apps and browser extensions in your Google or Microsoft admin console.
  • Check AI features that shipped inside tools you already pay for, some enabled by default.
  • Include the question in one-to-ones as a routine item rather than an investigation.

Frequently asked questions

How common is this?

In our experience, effectively universal in businesses without a provided tool. Assume it's happening and plan accordingly.

Should we monitor employee AI use technically?

Network-level monitoring raises its own data protection and employment law issues, and damages trust. Provision and training address the risk more effectively and more cheaply.

What if someone has already put client data into a consumer tool?

Assess whether it's a reportable breach, document the assessment, notify the client if your contract requires it, and fix the friction that caused it.

We find the tools nobody officially approved — that's usually where the risk sits. Start a free assessment.

Compliance
Made on
Tilda