What is shadow AI and how do you spot it?
Shadow AI is staff using AI tools the business has not approved. Spot it by asking openly, checking expenses and noticing changes in how work gets done.
Why shadow AI happens
Shadow AI is rarely a discipline problem. It usually means staff have found a faster way to do their work and the business has not yet offered an approved option. They draft emails in a personal chatbot account, summarise meeting notes with a free browser extension or use an AI feature switched on by default in software they already have.
That tells you something useful: there is real demand, and your people have already worked out where AI saves them time. The problem is that the work happens on tools nobody has checked, under terms nobody has read, with data nobody can track.
The real risks
Data leaving the business: Client or personal information may go into tools with unknown storage and training terms. This is the risk most likely to cause real harm.
Unchecked output: AI-generated content can reach clients without review, carrying errors you only discover later. The business still answers for those mistakes, as explained in who is liable when AI gets something wrong.
Lost knowledge: Useful workflows sit in individual accounts, so the business cannot share or improve them, and loses them when someone leaves.
Inconsistent quality: Different people use different tools in different ways. That makes client work harder to standardise and check.
How to spot it
Ask openly: Run a short, anonymous survey asking which AI tools people use and what for, and make clear the purpose is to learn, not to punish. This usually tells you more than any technical check.
Check spending: Look at expense claims and company card statements for software subscriptions. Small recurring charges are a common sign.
Review extensions and apps: Ask your IT provider which browser extensions and applications are installed on company devices. Look for AI writing, transcription and summarising tools.
Check features in existing software: Tools you already pay for may now include AI features. Find out which are switched on and what they do with your data.
Watch for changes in work: Noticeably faster turnaround, a shift in writing style or unusually polished first drafts can all point to AI use. Treat these as prompts for a conversation, not evidence of wrongdoing.
What to do once you find it
Banning it rarely works. A ban drives use underground, where you have even less visibility, and frustrates the people most keen to improve how they work.
Keep discovery no-blame: Thank people for being honest. If the first person to admit using a tool gets disciplined, nobody else will speak up.
Provide approved alternatives: Offer tools that are at least as easy to use as the workarounds, with business terms you have checked.
Write simple rules: Capture approved tools and data rules in a short AI acceptable use policy. People need to know where the lines are.
Turn users into champions: The people already using AI well are your best source of practical use cases. Involve them in choosing and rolling out the approved tools.
Data protection and confidentiality duties still apply to anything staff have entered into these tools. If you find that sensitive client or personal data has been shared, take advice on your own situation before deciding what to do next.
More questions
