Short answer: Shadow AI is staff using AI tools that haven't been approved, usually on personal accounts, often with company or client data. It's near-universal, it's a friction problem rather than a discipline problem, and the effective response is to make the approved path easier — not to issue a ban that pushes usage further out of sight.
Almost never out of disregard for policy. The pattern is consistent: someone has a task that AI makes dramatically faster, the company has no approved tool or a cumbersome one, so they use their own account. From their perspective they're being resourceful. Often they are.
The second driver is that AI features arrive inside tools already in use. A note-taking app adds a summarisation feature; a browser extension offers to draft replies. Nobody chose these, and nobody registered them.
A prohibition without a viable alternative doesn't stop the behaviour — it stops the reporting of it. Usage moves to personal devices, where you have no visibility, no logging, and no ability to train people on how to do it safely. You've converted a manageable risk into an invisible one.
Organisations that ban AI and don't provide alternatives consistently discover, when they eventually survey, that usage was widespread throughout.
1. Amnesty, then inventory. Ask openly what people are using, state clearly that nobody is in trouble, and mean it. The information is worth far more than the enforcement.
2. Provide a good approved tool. The most effective single measure. If the sanctioned option is at least as capable and easier to access than the unsanctioned one, shadow use largely evaporates. A business-tier subscription for the team costs less than the risk it removes.
3. Make the rules concrete. Not "use AI responsibly" but a specific list of what must never be entered and what's fine. People follow rules they can apply.
4. Create a route for new tools. A lightweight request process — name the tool, the use, the data involved — assessed within a week. Slow approval processes generate shadow AI on their own.
5. Train rather than police. Someone who understands why client data shouldn't go into a consumer tool makes better decisions in situations your policy didn't anticipate.
In our experience, effectively universal in businesses without a provided tool. Assume it's happening and plan accordingly.
Network-level monitoring raises its own data protection and employment law issues, and damages trust. Provision and training address the risk more effectively and more cheaply.
Assess whether it's a reportable breach, document the assessment, notify the client if your contract requires it, and fix the friction that caused it.
We find the tools nobody officially approved — that's usually where the risk sits. Start a free assessment.