Shadow AI: What It Is and What to Do About It
Your team is already using AI tools you have not approved. That is information, not just a risk, and the useful response is triage rather than a ban.
Shadow AI is the use of AI tools inside an organisation without approval, review or visibility from whoever is meant to be making those decisions. It is the AI-shaped version of shadow IT, and in most small businesses it is not an edge case. It is the default state, and the people doing it are usually your most motivated staff.
How common it actually is
Surveys put the numbers uncomfortably high. A report from UpGuard, covered by Cybersecurity Dive, found more than 80% of workers using unapproved AI tools, including nearly 90% of security professionals, with less than 20% saying they use only company-approved tools. The same report found 70% of respondents were aware of colleagues sharing sensitive data with AI tools inappropriately. Those figures come from surveys of larger organisations with formal policies to violate, which makes the small-business picture more rather than less likely to look this way.
The detail worth sitting with is the security professionals number. The people best equipped to explain the risk are using the tools anyway, which tells you the behaviour is driven by usefulness rather than ignorance. Policies written on the assumption that people just do not understand the danger will fail for that reason.
What it looks like in a small business
A salesperson pasting a prospect's requirements document into a chatbot to draft a proposal.
A bookkeeper photographing an invoice and asking a model to extract the line items.
A developer using a personal account for a coding assistant because the company one was never set up.
Someone running a customer list through a tool to segment it, on a free tier, on a personal login.
A manager summarising a performance review conversation with a note-taking assistant that joined the call.
None of these people think of themselves as doing anything unusual. Each is solving a real problem faster, which is exactly why the behaviour spreads without discussion.
Why banning shadow AI does not work
Three reasons, and the third is the one that matters.
Enforcement is close to impossible. Most of these tools are a browser tab on a personal account, invisible to whatever software you use to manage company devices.
The productivity gain is real. A ban asks people to work more slowly for a reason they can see is about liability rather than quality, which is a losing argument to make repeatedly.
A ban destroys your visibility. Before it, people mention what they use. After it, they stop mentioning anything, and you lose the only reliable source of information you had.
Shadow AI is a signal. It tells you which tasks your team finds tedious enough to route around process for, and that list is a genuinely useful input into deciding which tasks to automate with AI first.
Finding out what is actually in use
You do not need monitoring software, and installing some is a good way to guarantee nobody tells you anything ever again. Three approaches work better.
Method | How it works | What it misses |
|---|---|---|
Ask, with amnesty | Say plainly that you want to know what people use, that nobody is in trouble, and that the goal is to pay for the good ones. Ask in a group setting so the first honest answer makes the second one easier. | Tools people are embarrassed about, and anything used so casually they forget it counts. |
Check expenses | Personal subscriptions submitted as expenses, or small recurring charges on a company card, name the tools directly. | Everything on a free tier, which is most of it. |
Watch the output | Documents that arrive suddenly better formatted, or a colleague producing four times their usual volume of first drafts, are direct evidence. | Anything where the tool assists thinking rather than producing text. |
Triage in three questions
For every tool you find, three questions decide what happens next.
What data goes into it? Public marketing copy and internal brainstorming are one category. Customer records, employee data, client files and credentials are another. Only the second category is urgent.
Does it train on that data? A ten-minute check settles it, and the method is in how to check if an AI tool trains on your data. A tool that trains on inputs and receives customer records is the one genuine emergency in most of these audits.
Is it doing something valuable? If yes, the correct outcome is usually to buy the business tier and make it official rather than to stop it. You get the data controls, the person keeps the productivity, and the behaviour comes back into the light.
Most tools you find will be harmless and useful, a few will be harmless and pointless, and one or two will be genuinely alarming. Spending equal attention on all three is how these reviews turn into theatre.
A policy people will actually follow
Short, specific, and about data rather than tools. A usable version fits on one page and says four things: which categories of data may never go into any external tool, which tools are approved and paid for, how to request a new one and roughly how long that takes, and who to tell when something goes wrong, with an explicit promise that reporting a mistake is not a disciplinary matter.
A list of banned tool names dates within a month and teaches nobody anything. A rule that customer records and credentials never leave approved systems survives every new product launch, because it describes the thing you actually care about.
The other half of the work is making the approved path fast enough that nobody needs to route around it, which is mostly a question of adoption rather than policy. Getting your team to use AI covers that side, and the wider set of AI risks puts shadow AI next to the other things worth worrying about. If it has already happened, see what to do if it already happened for the response steps.
FAQ
Is shadow AI illegal?
Using an AI tool is not illegal in itself. Putting personal data into one without a lawful basis can breach data protection law, and putting client data into one can breach a contract you signed. The exposure comes from the data, not the tool.
How do I stop employees pasting customer data into AI tools?
Give them an approved tool that does the same job with the data controls in place, and make the rule about data categories rather than tool names. Instructions people can apply without checking a list are the ones that survive contact with a deadline.
Should I audit shadow AI before writing a policy?
Yes. A policy written before you know what is in use will ban things nobody does and permit things everyone does. The audit takes an afternoon and makes the policy specific enough to be worth reading.
How did this land?
About the author

Senior Editor, AI & Product
Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.


