Resources · 26 June 2026

Shadow AI: managing the unapproved AI tools your staff already use

By the Operating Bench Team · Last reviewed 26 June 2026

Shadow AI, sometimes called unsanctioned AI, is the AI your organisation is using without knowing it. Not the tools you chose and approved, but the chatbots, summarisers and writing aids your staff quietly opened in a browser tab to get through the day. Survey after survey finds the same thing: most people already use AI at work, and a large share do it without telling anyone. The tools are useful, which is exactly why a ban rarely sticks. The question is not whether your team uses AI. It is whether you know what they use, and on what.

Here is how to get a grip on it.

What shadow AI actually looks like

In a typical UK business, on a typical week:

None of this is malicious. It is people trying to do their jobs faster. But every one of those actions sends company or personal data to a third party you have not checked, under terms you have not read.

Why it is a problem

The risks are distinct, and they stack:

Why banning it does not work

The instinct is to forbid it. The trouble is that prohibition does not remove the demand, it removes the visibility. Tell people they may not use AI and the capable ones use it anyway, on personal accounts, on their phones, off the record. You are left with the same risk and less insight into it.

The better goal is not zero AI. It is no unmanaged AI. You bring the use into the open, give people a safe and approved way to do what they were going to do anyway, and make the rules clear enough that following them is easier than going around them.

A practical way to bring shadow AI into the light

  1. Find out what is already in use. Ask, without blame. A short, anonymous question to each team (“which AI tools do you use, and what for?”) usually reveals more than any audit. You cannot govern what you cannot see.
  2. Decide what is approved, and for what data. Pick a small set of tools you are comfortable with, ideally ones with business terms that do not train on your data, and say plainly which data may go into them. An approved-tools list does more to curb shadow AI than any warning.
  3. Give people a data ground rule they can remember. Most leaks come down to one question: is this safe to put into this tool? A simple data-classification guide (public, internal, confidential, personal) answers it in seconds.
  4. Make the safe path the easy path. If the approved tool is good enough and obviously allowed, most people will use it. Shadow AI thrives where the sanctioned option is worse than the unsanctioned one.
  5. Make owning up safe. People hide AI use because they fear the consequences of admitting it. A no-blame way to flag “I think I put the wrong thing into a tool” lets you contain a problem instead of discovering it months later.
  6. Write it down and keep it current. A short AI acceptable use policy, a named owner, and a risk register that lists shadow AI as a tracked risk turn all of the above from good intentions into something you can actually show.

Where a policy earns its keep

Every step above is a document. That is the point of an AI policy for your business: it is the approved-tools list, the data-classification guide, the staff one-pager and the risk register, written so the safe path is the obvious one. Done well, it does not slow your team down. It just means the AI they were always going to use is AI you can stand behind.

Our AI Safe-Use Pack ships with all of those pieces, including a risk register that already names unmanaged AI use as a tracked risk. If you would rather start smaller, the free AI Starter Kit gives you the ground rules and the data guide on a single page.

This article is general information, not legal advice. How UK GDPR and confidentiality obligations apply to your AI use should be considered with professional advice where it matters.

Frequently asked questions

What is shadow AI?
Shadow AI is staff using AI tools without approval or oversight, usually free chatbots opened in a browser tab. It is rarely malicious, just people trying to get work done faster, but it puts data and decisions outside any policy.
Why is shadow AI a risk for UK businesses?
You lose sight of what data is going where, whether a tool trains on your inputs, and whether the output is being checked. That creates data protection, confidentiality and quality risks you cannot manage because you cannot see them.
How do we manage shadow AI without banning AI outright?
Bans tend to push usage further underground. A workable approach names a short list of approved tools, sets clear rules for what may and may not go into them, and gives staff an easy way to request a new one. Our AI Safe-Use Pack includes the policy and an approved-tools matrix to do exactly this.

Sources & further reading

External links are provided for reference and open in a new tab. This article is general information, not legal advice.

Share this LinkedIn X

One email when it matters

A short note when the rules change or we publish something genuinely useful for UK organisations. No spam, unsubscribe in one click.