Shadow AI: The Tools Your Team Isn't Telling You About

Shadow AI is the unapproved use of AI tools inside a business — often well-intentioned, frequently invisible, and usually driven by slow approval routes, fear of being told 'no', and AI features quietly appearing inside software you already use. This article explains why it happens, how to surface it through an amnesty, browser and single-sign-on review and expense-line checks, and how to turn each discovery into an assessment rather than a punishment. It then shows how to keep an AI tool register alive through a regular Operational Heartbeat review. This is general information for UK small and medium-sized businesses and is not legal advice.
A member of staff is behind on a proposal. They open a free AI chat tool in their browser, paste in a client's brief and last year's pricing, and ask for a first draft. Ninety seconds later they have something workable. It saved them an hour. They did not think to ask anyone, because asking felt like it would take longer than the task itself.
Multiply that small, sensible-feeling decision across every person in the business, every week, and you have shadow AI: artificial intelligence tools being used for work without anyone deciding they were suitable, checking what data goes into them, or recording that they exist.
The instinctive management reaction is to treat this as a discipline problem — people breaking the rules. That reaction usually makes things worse. Shadow AI is first and foremost a visibility problem. You cannot assess a tool you do not know about, cannot secure data you cannot see leaving, and cannot improve a workflow you have never been shown. The businesses that handle this well start by getting the tools into the open, not by getting people into trouble.
You cannot govern what you cannot see. Every hour spent making it safe for people to tell you what they are using buys you more control than an hour spent policing it.
The Quick Answer
Shadow AI is the use of AI tools for work without approval, oversight or a record. It is common, and in most small businesses it is already happening.
To bring it under control without breaking trust:
- Understand why it happens — usually slow approval, fear of 'no', or AI features appearing inside tools you already use
- Surface it with an amnesty: a genuine, time-boxed, no-blame invitation to declare tools in use
- Cross-check what people tell you against a browser and single-sign-on (SSO) review and an expense-line review
- Treat each discovery as an assessment — what data, whose data, which settings, what value — not a punishment
- Record everything in a living AI tool register with an owner, purpose, data, settings, approval status and review date
- Keep it current with a regular Operational Heartbeat review, because tools, settings and staff change
The goal is not zero AI use. It is AI use you can see, assess and stand behind.
Last checked: 4 August 2026. AI tools, their default settings, their terms and the regulatory guidance around them change frequently. Verify current settings and terms before relying on any specific behaviour, and treat this as general information rather than legal advice.
Why shadow AI happens
Shadow AI is rarely an act of rebellion. It is almost always the path of least resistance for someone trying to do their job well. If you understand the three main causes, you can fix the conditions rather than blame the people.
1. The approved route is too slow
If getting a tool approved means an email into a void, a wait of several weeks, and no clear answer, staff will conclude — reasonably — that the official process is not designed for the pace of their work. Free AI tools take seconds to open. A business process that takes a fortnight cannot compete with a workflow that takes ninety seconds, and people will quietly choose the ninety seconds.
2. People expect the answer to be 'no'
Where earlier requests have been refused without explanation, or where the culture treats any new tool as a threat, staff learn not to ask. Asking risks a 'no' that stops them working; not asking lets them get on. The result is that the most capable, motivated people — the ones most likely to experiment with AI — become the least likely to tell you they are doing it.
3. AI features are appearing on their own
This cause is newer and harder to spot. AI features are being added to software businesses already use and already pay for. Assistants and 'summarise', 'draft' and 'rewrite' buttons are appearing inside office suites, email clients, note-taking apps, customer-relationship systems, PDF readers and browsers. Microsoft, for example, has been embedding its Copilot assistant across Microsoft 365 apps. In many cases nobody chose to adopt an 'AI tool' at all — an update simply switched one on.
A significant amount of shadow AI is not something anyone downloaded. It arrived in an update to software you already trusted, which is exactly why it slips past a policy that only looks for new purchases.
Industry research suggests the scale is substantial. A 2024 study by software company Software AG, reported by SecurityWeek, suggested that around half of employees who use AI at work were using tools not provided by their employer — and that many would carry on even if such tools were banned. Figures like this vary by survey and should be read as indicative rather than precise, but the direction is consistent: unapproved use is widespread, and prohibition alone does not stop it.
Why unseen AI use carries real risk
Shadow AI matters because the everyday tasks people use it for tend to involve exactly the information a business most needs to protect.
| What goes into the tool | Why it may matter |
|---|---|
| Customer emails and personal details | May be personal data, engaging UK GDPR and Data Protection Act 2018 obligations that the business is accountable for. |
| Contracts, bids and pricing | May be confidential or commercially sensitive, and may be covered by non-disclosure or client agreements. |
| Employee or applicant information | Special-category or sensitive personal data can attract heightened obligations. |
| Source code, designs or draft content | May raise intellectual-property, ownership and licensing questions. |
| Whatever setting the tool defaults to | Some consumer tools may use inputs to improve their models unless a setting is changed; defaults vary and change over time. |
The Information Commissioner's Office (ICO) has been clear that data-protection law continues to apply when organisations use AI, and has published guidance on AI and data protection alongside a consultation series on generative AI. None of that assessment can happen if the business does not know the tool is in use. That is the core reason to make visibility the first objective.
This article does not attempt to tell you whether any specific tool is lawful for any specific task — that depends on the data, the settings, the supplier's terms and your circumstances, and may warrant professional advice. The point here is narrower and more practical: you have to see it before you can judge it.
How to surface shadow AI
There are three complementary ways to bring shadow AI into the open. Used together they give a far more honest picture than any one on its own: one relies on people telling you, and two check independently of what people remember to mention.
The amnesty approach
An amnesty is a genuine, time-boxed invitation for everyone to declare the AI tools they are using for work, with an explicit promise that declaring in good faith will not lead to disciplinary action. The purpose is to reset the incentive: right now, the safest thing for an employee is to say nothing. An amnesty makes the safest thing to be honest.
- 1Announce a clear window — for example two weeks — and explain why: to build a complete picture, not to catch anyone out.
- 2Make declaring easy: a short form or shared list asking what the tool is, what it is used for, and what information tends to go into it.
- 3State plainly that good-faith declarations will not be punished, and mean it — the first punished disclosure will end all future honesty.
- 4Thank people for every declaration, including for tools you will later decide to withdraw.
- 5Follow up quickly with what happens next, so the amnesty feels like the start of support rather than the start of a crackdown.
An amnesty only works once if you break it. If someone is disciplined for honestly declaring a tool, the message travels the business faster than any policy, and future shadow AI will go deeper underground.
Browser and single-sign-on review
People forget things, and some AI use is so routine it no longer registers as 'using an AI tool'. Two technical checks fill the gaps in what an amnesty surfaces, and both should be done transparently and in line with your own monitoring and privacy policies:
- Browser extensions: AI writing assistants, summarisers and 'chat with any page' add-ons are commonly installed as browser extensions. Reviewing installed extensions on managed devices can reveal AI tools that never appeared on any invoice.
- Single sign-on (SSO) logs: where staff sign in to third-party services using a business Microsoft, Google or other identity, the identity provider's sign-in and application records can show which external AI services accounts have connected to.
- AI features inside existing software: check the admin controls of tools you already own. Office suites, collaboration platforms and CRMs increasingly have AI features that administrators can see, configure or restrict centrally.
Be open that you are doing this and why. A review carried out quietly, then used against someone, does the same damage as a broken amnesty. A review announced as 'we are building a complete list of the AI in the business so we can support it properly' reinforces the visibility-first message. Businesses should ensure any monitoring is proportionate and consistent with their employment and privacy obligations.
Expense-line review
Not all AI is free. Paid subscriptions frequently appear on company cards and personal-expense claims under names that do not obviously say 'AI'. A review of card statements, subscription lists and recent expense claims can surface paid tools — and it often reveals duplication, where several people separately pay for similar tools that could be consolidated into one properly assessed, better-value arrangement.
Look particularly for small recurring monthly charges, app-store subscriptions, and anything billed per user. These are the fingerprints of tools adopted by individuals rather than the business.
Turning discoveries into assessments, not punishments
Once tools are on the table, the temptation is to sort them into 'allowed' and 'banned' and move on. That wastes the most valuable thing an amnesty produces: a real map of how your business actually works. Each discovery deserves a short, consistent assessment, not a verdict on the person who declared it.
A workable assessment can be brief. For each tool, consider:
- 1Purpose — what real job is this doing, and how much time or value does it genuinely add?
- 2Data — what information goes into it, and does any of it include personal data, confidential material or client information covered by an agreement?
- 3People — who uses it, and who else could see the data as a result?
- 4Settings — what are the tool's current data, training and retention settings, and can they be changed to reduce risk?
- 5Supplier — what do the terms say about how inputs are used, stored and shared, and are those terms acceptable for this data?
- 6Alternative — is there an approved tool that already does this job, or that could with the right configuration?
- 7Decision — approve, approve with conditions, replace, or withdraw — with a named owner and a review date.
The National Cyber Security Centre (NCSC) has published guidance on the secure development and use of AI systems, and its broad principle applies neatly here: understand what a system does and what it touches before you rely on it. An assessment is simply that understanding, written down.
If the outcome of honesty is punishment, you will not get honesty again. Reserve consequences for genuine bad faith — deliberately hiding a tool after an amnesty, or ignoring an explicit instruction — not for the people who told you the truth.
Often the most useful discovery is a task, not a tool. Someone using AI to summarise long email threads has told you that summarising long email threads is a real pain point. Even if you withdraw their chosen tool, you now know a problem worth solving properly — which turns governance into something staff experience as help rather than obstruction.
A fictional example of an assessment, not a punishment
The following scenario is fictional and is included only to illustrate the approach.
During an amnesty, an account manager at a fictional ten-person agency declares that she has been using a free AI tool to rewrite client update emails, sometimes pasting in the client's previous correspondence to keep the tone consistent.
Rather than a warning, the manager runs the assessment. Purpose: real — clearer client emails, faster. Data: includes client correspondence, some of it personal data. Settings: the free tool's defaults are unclear and the terms are not reassuring for client data. Decision: withdraw the free tool for this task, and instead configure and approve a business account of an existing tool with acceptable terms, with a note that raw client correspondence should be generalised rather than pasted in full.
The account manager keeps her time saving, the business gains a defensible position, and the next person to find a useful tool knows it is safe to say so. That is the whole point of treating discovery as assessment.
Keeping the register alive
An amnesty and a review produce a snapshot. A snapshot goes out of date the moment staff join or leave, a supplier changes its terms, a tool adds a new feature, or an update switches on an assistant nobody asked for. The output of surfacing shadow AI should therefore be a living AI tool register — a single, maintained record of every AI tool in use.
A practical register records, for each tool: the owner, the purpose, the data that goes into it, its current settings, its approval status and its next review date. It does not need to be sophisticated. A shared spreadsheet that is actually kept up to date beats an elaborate system that no one maintains.
| Register field | Why it earns its place |
|---|---|
| Tool and supplier | So you can track terms changes and news about that specific provider. |
| Owner | A named person responsible for keeping this entry honest. |
| Purpose | The real job it does — the thing you would need to replace if it went away. |
| Data it handles | The single most important field for judging risk and obligations. |
| Settings | Data, training and retention settings, so you can spot when a default changes. |
| Approval status | Approved, conditional, under review, or withdrawn. |
| Review date | So the register cannot quietly rot. |
The Operational Heartbeat review cycle
A register only stays useful if something forces you to look at it again. That is the role of the Operational Heartbeat: a recurring, deliberately unglamorous review that keeps governance current rather than treating it as a one-off project. The cadence matters less than the fact that it actually happens — quarterly suits many small businesses, with a lighter monthly glance at anything flagged.
At each review, work through the register and confirm, at minimum:
- Approved tools and their owners are still correct
- Who is using each tool, and whether their access rights are still appropriate
- What personal data and confidential information is entering each tool
- Whether training and retention settings are still as recorded
- Whether supplier terms or subprocessors have changed
- Any incidents, output errors or complaints since the last review
- Business value: which tools are unused, duplicated or up for renewal
- Corrective actions outstanding, and the next review date
Crucially, the review should also reopen the amnesty in miniature: a standing, low-friction way for anyone to add a new tool to the register between reviews without fear. Shadow AI returns the moment declaring becomes hard or frightening again, so the easy, safe route in has to stay permanently open.
A register that is written once and never revisited is not governance — it is a museum exhibit. The Operational Heartbeat is what keeps it describing the business you actually have today.
Bringing it together
Shadow AI is not a sign that your people are careless. It is a sign that they are trying to work well with tools that are now everywhere and easy to reach. The businesses that come out of this in a strong position are the ones that make it safe and quick to be honest, assess what turns up calmly, write it down, and keep looking. Treat visibility as the goal and discipline as the rare exception, and you turn a hidden risk into a clear, manageable picture — and often into a genuinely better set of tools than you had before.
Next steps and resources
To capture what your amnesty and reviews surface, use a structured register you can keep alive:
Download the AI Tool Register template →
To set out clearly what staff can and cannot do with AI — so the approved route is obvious and the amnesty has somewhere to point people — see our guide to setting AI rules for your staff:
Setting AI Rules for Your Staff →
For the wider framework this article sits within — assessing tools, protecting data, keeping humans in the loop and running the review cycle — visit the AI Governance hub:
AI Governance Knowledge Centre →
Sources and further reading
The following sources were reviewed on 4 August 2026. Regulatory guidance and AI tools change frequently, so verify current positions before relying on them. This article is general information for UK businesses and is not legal advice.
ICO — Guidance on AI and data protection →
ICO — Response to the consultation series on generative AI →
NCSC — Guidelines for secure AI system development →
Data Protection Act 2018 (legislation.gov.uk) →
SecurityWeek — The Shadow AI Surge: Study Finds 50% of Workers Use Unapproved AI Tools →
Plain-English Takeaway
Shadow AI is unapproved AI use inside your business, and it is almost always a symptom of a system that made the approved route too slow or too frightening. Surface it with an amnesty, a browser and single-sign-on review and an expense-line check rather than a hunt for culprits. Turn each discovery into a short assessment — what data, whose data, which settings, what value — and record it in a living AI tool register that you revisit on a regular Operational Heartbeat cycle. This is general guidance, not legal advice; where personal data, contracts or regulated activity are involved, consider taking professional advice.
Related Articles
Good IT Support Isn’t Just Fixing Problems
Good IT support is largely invisible. The best providers catch problems before your staff know they exist. Here is what a proactive IT provider should be monitoring every day.
Read articleAI Recruitment Tools: What the ICO Found When It Looked
In November 2024 the Information Commissioner's Office published the results of a set of consensual audits into the providers and developers of AI tools used for sourcing, screening and scoring job candidates. It made almost 300 recommendations, and the audited organisations accepted or partially accepted every one of them. The findings read like a ready-made due-diligence list: tools that let recruiters filter out people with protected characteristics, tools that guessed gender and ethnicity from a name, tools that hoovered up far more personal data than they needed and kept it indefinitely. For a UK SME thinking about buying one of these tools, that report is a free head start — the regulator has already told you where the problems tend to hide. This article summarises what was found, where employment law meets training data, and the questions worth putting to any vendor before you sign.
Read articleWhat the Air Canada Chatbot Case Means for Your Website
In 2024, a small-claims tribunal in British Columbia decided that Air Canada was responsible for wrong information its website chatbot gave a grieving customer — and rejected the airline's argument that the chatbot was somehow a separate entity accountable for its own words. The case is not binding in the United Kingdom, and it turned on Canadian law, so it should not be treated as a UK precedent. But the principle behind it travels well: a customer is generally entitled to rely on what your systems tell them, whether the words come from a static web page, a member of staff or an automated assistant. For a UK small business adding a chatbot to its website, the useful question is not "did the chatbot say it?" but "would we stand behind this if a person had said it?". This article explains the case, sets it beside UK consumer-protection framing, and turns it into practical constraints for customer-facing bots.
Read article