Shadow AI: your team already started, the question is whether you know

Translucent silhouette of an office worker overlaid with glowing network connections and app icons drifting into the shadows, representing shadow AI use inside a business

Try this at your next staff meeting. Ask everyone to raise a hand if they used an AI tool this week. Most hands go up.

Now have them keep their hand up if you know which tool they used, and ask the ones that you don’t know which tools they used to put their hands down.

Then ask yourself if you know what they pasted into it and have the ones you know for certain put their hands down. When our team ran this exercise with a room of South Florida business owners, nearly every remaining hand came down.

That gap is shadow AI, and it has very little to do with the tools themselves or the people using them. It is the distance between what your team is doing with AI and what you actually know about it.

What shadow AI is

Shadow AI is the use of artificial intelligence tools at work without the knowledge or approval of whoever owns technology decisions at your company. That might be an IT provider, an office manager, or you.

It usually looks harmless. Someone pastes a client email into a chatbot to make it sound more polished. Someone drops a spreadsheet into a free web tool to summarize it. Someone installs a browser extension that promises to write meeting notes. Nobody is trying to cause a problem. They are trying to finish faster.

The term borrows from shadow IT, which has been around for years, but the two behave differently in ways that matter.

Shadow ITShadow AI
Usually a whole application, like a file sharing account nobody approvedOften a single browser tab, or a feature already built into software you pay for
Tends to leave traces: installs, invoices, new loginsFrequently leaves no trace at all
The risk is where data is storedThe risk is where data is sent, and what happens to it after
Discovered through software auditsRarely discovered until someone mentions it

That last row is the hard part, and it is why the usual software inventory does not help much here. You can audit installed software, but you cannot audit a copy and paste.

Why smart people do it anyway

Almost every business owner we talk to has the same first reaction, which is some version of “we should probably ban this.” We understand the instinct, and we have made the argument for it ourselves. It is also the response most likely to make the problem worse.

Consider what actually happens when a tool is banned but the pressure to move faster stays exactly the same. People do not stop using AI. They stop telling you about it. The activity moves from a work laptop to a personal phone, where you have no visibility at all and no ability to help.

A ban converts a manageable problem into an invisible one, which is the opposite of what you were trying to do.

There is also a fairness question worth sitting with. Most of the people using these tools are doing it to serve customers better or get home at a reasonable hour. When we look at how shadow AI shows up inside our clients’ businesses, it clusters around the roles carrying the most work: the person answering every customer email, the office manager reconciling three systems by hand, the salesperson writing proposals at nine at night. Punishing that instinct costs you more than the risk does.

What actually goes wrong

The risk conversation around AI tends to get abstract fast. Here is the concrete version, scaled to a company with twenty to two hundred employees rather than a bank.

Your data trains someone else’s model

Consumer AI accounts and business AI accounts are different legal agreements, and the difference is not cosmetic. On most consumer plans, what you type can be retained and used to improve the product. On business and enterprise plans from the major providers, it generally is not, and you get administrative controls over the account.

We break down the differences between free, business, and enterprise AI accounts in a separate guide. Same interface, same logo, very different contract. Most employees have no idea the distinction exists, because nothing in the product tells them and nobody has ever explained it.

Information leaves under someone’s personal login

When an employee uses a personal AI account for work, that account is not yours. If they leave the company, the history goes with them, along with whatever client information is sitting in it. You cannot revoke access to an account you never controlled, and you cannot produce those records if a client or a regulator asks what happened to their data.

Confidentiality obligations get broken quietly

If you have signed a nondisclosure agreement, or you handle health, legal, or financial records, or you have client contracts with confidentiality terms, pasting that material into an unapproved tool can put you in breach. Not eventually. At the moment it is pasted.

Nobody notices, which is precisely the problem: there is no alarm, no error message, and no record that anything unusual happened.

Confident, wrong answers reach customers

AI tools are built to produce fluent text. Fluent is not the same as accurate. A summary that quietly drops a contract exclusion, a figure that looks plausible and is not, a citation to a regulation that does not exist. These reach customers when nobody reviews the output before it goes out.

The tool itself is the product

The name-brand AI companies are not the whole picture. There is a long tail of cheap AI sites, browser add-ons, and app store downloads that wrap someone else’s model in a new interface. Some are legitimate. Some make their money from the data flowing through them, and their terms of service say so if you read far enough.

If a tool costs nine dollars a month and appears to do what a far more expensive product does, that difference is being paid for somehow, and it is worth knowing how.

How to find out what your team is actually using

Most published advice on this points you at a security platform that monitors network traffic and flags unapproved services. Those products are real and they work. They are also priced and scoped for organizations with a security team to run them, which most small and midsize businesses do not have.

Here is what works without buying anything.

Start by asking, and mean it. Send one message saying you are putting together a list of approved AI tools, you want to know what people already find useful, and nobody is in trouble. Then honor that. The first person who gets criticized for answering honestly is the last person who answers honestly.

Then check the expense reports. Personal subscriptions to AI tools show up on reimbursements more often than you would expect. Twenty dollars a month, charged under a product name nobody in accounting recognizes.

Next, look at what is already turned on. A good deal of AI use is not shadow at all. It is built into software you already pay for and got switched on by default in an update, across Microsoft 365, your CRM, your phone system, and your meeting software. Ask your IT provider which AI features are currently active in your existing tools, starting with your Microsoft 365 plan. The answer is often longer than expected.

Finally, watch for the meeting note takers. We flag these specifically with our clients, because they join calls as participants and produce transcripts that live somewhere you may not have chosen. They are also the AI tool most likely to get installed by one employee without a conversation.

You will not get a perfect inventory from any of this, and you do not need one. The goal is to replace a blank page with a rough map.

Six ground rules that fit on one page

Once you know roughly what is happening, the fix is smaller than most people expect. It is not a governance program. It is a page.

  1. Assume they already started. The question was never whether your team uses AI, it is whether you know. Having no standard has not prevented anything, it has only made the activity invisible.
  2. Write the policy, and keep it to one page. Not a legal document. Which tools are approved, what never gets pasted into them, and who to ask. If it does not fit on one page, nobody reads it.
  3. Move people to business accounts and turn data sharing off. This is the highest-value change on the list, and it is a checkbox and a credit card rather than a project.
  4. Publish a never list. Customer personal information, payroll and HR records, anything under an NDA, passwords and access keys, unreleased financials, and regulated data. Write it down so people do not have to guess.
  5. No mystery AI sites. If your IT provider did not give it to your team, company information does not go into it. We cover how to spot the difference in our guide to AI connectors and data brokers.
  6. A person signs off. Nothing goes to a customer, a regulator, or a bank without a human name attached to it. AI drafts. A person owns the result.

Notice what is not on that list. There is no approval workflow, no committee, and no software purchase. Six rules, most of which you can put in place this week.

What to do if something already went out

Sooner or later someone will tell you they pasted something they should not have, or you will realize it yourself while reading this. The reaction in that first conversation determines whether anyone ever tells you again, so it is worth deciding in advance how you want to handle it.

Start by finding out what was shared and where it went, without making the person defend themselves. You need three facts: what the information was, which tool received it, and whether the account was a company account or a personal one. That last answer changes almost everything about what comes next.

If it went into a company business account with data sharing turned off, you are usually in reasonable shape, and the work is deleting the conversation and moving on. If it went into a personal account, ask the employee to delete the chat history and the data associated with it, then check whether the provider offers a way to confirm removal. Most of the major providers do, though the process is buried in account settings.

Then ask the harder question, which is whether the information triggers an obligation you owe someone else. Client contracts, nondisclosure agreements, and regulations covering health, legal, and financial data can all carry notification requirements, and those requirements do not care that the disclosure was accidental. This is the point to call your attorney rather than guess, and if you work with an IT provider, loop them in at the same time so the technical and legal timelines line up.

Finally, write down what happened and what you changed because of it. Not for a file nobody reads, but because the second occurrence of the same mistake is a pattern worth fixing at the source rather than a person worth blaming.

Common questions

What is an example of shadow AI?

An employee pasting a customer’s email into a free chatbot to draft a reply. A manager uploading a payroll spreadsheet to a web tool to summarize it. A salesperson using a personal AI subscription to write proposals. An automatic meeting note taker joining calls that nobody approved. All four are ordinary, and none of them will show up in a software audit.

Is using ChatGPT at work shadow AI?

It depends on the account, not the tool. If your company provided a business account and set the rules, that is sanctioned use. If an employee signed up personally and is pasting work information into it, that is shadow AI, even though it is the same product.

Should we just block AI tools on the company network?

Blocking is a reasonable control for specific tools you have evaluated and rejected. As a blanket policy it tends to push the activity onto personal phones and personal accounts, where you have no visibility and no way to help. Most businesses get a better outcome from approving a small number of tools and being clear about the boundaries.

How risky is this for a small business, really?

It depends almost entirely on what your team handles. If you work with health records, legal files, financial data, or anything under contract confidentiality terms, the exposure is real and the rules probably already apply to you. If you do not, the more likely problem is inaccurate work reaching a customer. Both are worth an hour of your attention. Neither is worth panic.

Who should own the AI policy?

Someone with a name. The most common failure we see is a policy that exists as a document with no person attached, so questions have nowhere to go and the policy quietly stops being followed. Pick a person, put their contact information on the page, and give them permission to say “let me find out.”

Where to start

Pick one meeting this week and ask the three questions from the top of this article. Do not prepare a presentation and do not frame it as an audit. Just ask, write down what you hear, and thank whoever answers first, because they are taking the biggest risk in the room.

Then write the page. Approved tools, the never list, who to ask. An hour of work, and it converts a problem you cannot see into one you can manage.

We put together a one-page AI acceptable use policy template you can fill in and hand out, built from the same six rules above. It is free, it is editable, and it fits on one page on purpose.

If you would rather talk it through first, our team is happy to walk through what your business already has turned on and what is worth changing. No obligation, and you may well find you are in better shape than you think.