Shadow AI: The Tools Your Staff Are Already Using That IT Has Never Heard Of
16 Sep 2026
Somewhere in your business right now, somebody is using an AI tool you have never approved. They are not being malicious. Quite the opposite. They found something that makes their job faster, it was free to sign up for and asking IT felt like a slow way to get to a probable no.
This is shadow AI, and it is one of the fastest growing security blind spots in businesses of every size. Industry surveys consistently show that a large share of employees use personal AI tools for work tasks, and a significant portion actively hide that use from their employer. Not because they are doing anything wrong, but because they do not want the tool taken away.
What shadow AI actually is
Shadow AI is any AI tool being used for work without the knowledge or approval of the business. Free chatbots, browser extensions, meeting transcription apps, image generators, AI note takers, personal subscriptions paid on a personal card. If it touches company information and IT does not know it exists, it is shadow AI.
Think of it like staff bringing their own power tools onto a building site. Each individual tool might be perfectly good. But nothing has been safety tested, nothing is on the insurance schedule and if something goes wrong, nobody even knew the tool was on site. The problem is not the tool. The problem is the invisibility.
Why your people are doing it
The honest answer is that the tools are genuinely useful and the free versions are genuinely free. A hard-pressed employee with a deadline does not see a data governance question. They see a faster way to draft a report, summarise a meeting or tidy up a spreadsheet.
There is also a generational shift underway. People entering the workforce now have used AI throughout their education. To them, working without it feels like being asked to work without a calculator. If the business does not provide a sanctioned option that is actually good, they will quietly supply their own.
Where the risk really sits
The core issue with free consumer AI tools is simple. If you are not paying for the product, your data often is the payment. Information typed or pasted into a free AI tool may be stored on servers outside the UK, used to train future models or retained indefinitely. Once it leaves your building, you cannot get it back and you cannot prove where it went.
For a business handling customer records, financial information or anything covered by UK GDPR, that creates real exposure. A well-meaning employee pasting a client list into a free chatbot to draft an email is, in regulatory terms, a data disclosure to an unknown third party. No audit trail. No contract. No recourse. And if that ever becomes a reportable breach, the 72-hour notification clock starts ticking whether you knew about the tool or not.
Why banning it outright fails
The instinctive response is to block everything. In our experience that is the single most reliable way to make the problem worse.
Block AI tools on the company network without offering an alternative and usage does not stop. It moves to personal phones sitting right beside the work keyboard, where you have no visibility at all. You have not reduced the risk. You have just blinded yourself to it. Prohibition without provision drives the behaviour underground, and underground is the one place you cannot manage it.
What sensible control looks like
The businesses getting this right are not choosing between banning AI and ignoring it. They are doing four things, in order, and each maps directly onto the Assess stage of how we approach every security challenge through our ARP® framework.
First, get visibility. You cannot govern what you cannot see. DNS level filtering shows you which AI services are actually being reached from your network, which is frequently an eye opener in itself. Most businesses we assess are running two to three times more AI tools than leadership believed.
Second, provide a sanctioned option worth using. A properly managed AI tool inside your own Microsoft tenant, with your data protections wrapped around it, gives staff the productivity without the leakage. If the approved tool is good, most of the incentive to go around it disappears.
Third, put a clear AI use policy in writing. Staff genuinely want to know where the line is. A short, plain English policy that says what is allowed, what is not and why protects the business and removes the guesswork. It also matters for UK GDPR accountability, because being able to show you had a policy and trained people on it is a very different conversation with the ICO than a shrug.
Fourth, keep watching. AI tools launch weekly. Governance here is not a one off project but a standing item, the same as patching or backups.
Start with two free steps
If shadow AI is not yet on your board agenda, two things will put you ahead of most businesses by Friday.
Download our free AI Tools Use Policy template. It is written for UK businesses in plain English, covers UK GDPR and data protection obligations and can be adapted to your organisation in an afternoon.
Then ask us about an AI Readiness Assessment. It gives you the full picture of what AI is actually in use across your business, where your data is going and what needs to change before you scale AI up rather than shut it down. Because the goal here is not to stop your people using AI. It is to let them use it without betting the business on a free chatbot's terms and conditions.
Call us on 028 8225 2445 or get in touch through our contact page.
Back Top
