There is a conversation we now have in almost every assessment, and it goes the same way every time. We ask whether staff are using AI tools. The owner says no, or not really, or only for small things. We look. They are, extensively, and some of what has gone into those tools should not have.
To be clear about what we mean, because the phrase “shadow AI” sounds more sinister than the reality. Someone in accounting pasted a client list into a free chatbot to fix the column formatting, because doing it by hand would have taken forty minutes. Someone in sales fed a signed contract into a summariser to pull out the renewal dates. Someone drafted a difficult client email by describing the situation, including the client’s name and the amount in dispute. Nobody did anything malicious. Every one of them was trying to do their job well with a tool that is one browser tab away, free, and asks no questions.
Why this is different from ordinary shadow IT
Businesses have dealt with unsanctioned software for twenty years, and the usual risks are known: an unmanaged app, a licence problem, data in a place backups do not reach. Bad, but bounded, and generally recoverable once found.
This is not bounded in the same way. Content put into a free consumer AI service can be retained, can be used to improve the service, and is outside your control from the moment it leaves the browser. There is no recall. And the exposure is not covered by your confidentiality obligations, your privacy policy, or your insurance, because none of those contemplated the data going there. For a law firm that may implicate privilege. For an accounting practice it is a confidentiality breach under professional obligations. For a clinic, patient information in a public tool is a privacy breach under PHIPA regardless of intent. In each case it is reportable, and in each case it was created by an ordinary person having a productive afternoon.
Banning it does not work, and makes things worse
The reflex is a policy that prohibits AI tools entirely. We understand the appeal and we advise against it, because we have watched what happens next. The tools do not stop being useful, so people do not stop using them. They stop mentioning it. The activity moves to personal phones and home computers, where you have no visibility at all, and the person who might have flagged a mistake now has a reason not to.
A prohibition also puts you in the position of asking your staff to work slower than the market. That is not a position leadership can hold for long, and it should not want to. The productivity is real. The problem was never that people want to use these tools. It is that nobody told them which one, for what, with what.
What actually works
Start by finding out what is true. Not to discipline anybody, and it is worth saying that out loud before you start, because an assessment conducted as an investigation returns nothing useful. You want an honest picture of which tools are in use, for what tasks, and what categories of information have already gone out.
Then write a policy that says yes to something. The failure mode of AI policies is that they are entirely prohibitions, so they get ignored within a fortnight. A policy that works names the sanctioned tool, names the tasks it is approved for, and is specific about the categories that never go into anything unsanctioned: client identifiers, financial detail, health information, credentials, anything under an NDA. Specific beats comprehensive. People can follow three clear rules and cannot follow two pages.
Then give them somewhere legitimate to go. This is the part most businesses skip and it is the part that decides whether any of the rest holds. AI deployed inside your own environment, with your data boundaries, your access controls, and logging that shows what it touched, does the same job as the free tool without the exposure. Once that exists, the policy is no longer asking anyone to give up productivity, which is the only version of the conversation that survives contact with a busy quarter.
We treat this as security work, because that is what it is. It sits alongside everything else we do to keep data where it belongs, and it is part of how we deploy AI. The businesses handling this well are not the ones with the strictest rules. They are the ones that gave people a sanctioned option before the unsanctioned one became a habit.