Resources · 26 June 2026
Shadow AI: managing the unapproved AI tools your staff already use
By the Operating Bench Team · Last reviewed 26 June 2026
Shadow AI, sometimes called unsanctioned AI, is the AI your organisation is using without knowing it. Not the tools you chose and approved, but the chatbots, summarisers and writing aids your staff quietly opened in a browser tab to get through the day. Survey after survey finds the same thing: most people already use AI at work, and a large share do it without telling anyone. The tools are useful, which is exactly why a ban rarely sticks. The question is not whether your team uses AI. It is whether you know what they use, and on what.
Here is how to get a grip on it.
What shadow AI actually looks like
In a typical UK business, on a typical week:
- Someone pastes a client email thread into a free chatbot to draft a reply.
- A manager drops a spreadsheet of staff data into an AI tool to “summarise the trends”.
- An AI notetaker silently joins video calls and stores the transcripts somewhere offshore.
- Marketing runs copy through three different AI writers, none approved, each with its own terms.
- A developer pastes a chunk of internal code into a chatbot to debug it.
None of this is malicious. It is people trying to do their jobs faster. But every one of those actions sends company or personal data to a third party you have not checked, under terms you have not read.
Why it is a problem
The risks are distinct, and they stack:
- Data leakage. Free consumer AI tools may use what you type to improve their models. Paste a client list, a contract or staff details, and you may have disclosed personal or confidential data to a third party with no lawful basis and no data processing agreement. Under UK GDPR that is your problem, not the tool’s.
- Confidentiality and IP. Client confidentiality, trade secrets and your own intellectual property can walk out of the door one prompt at a time.
- Accuracy and accountability. AI output can be wrong with great confidence. If no one knows a decision leaned on an unchecked AI answer, no one checks it.
- No record. When use is invisible, you cannot show a regulator, client or auditor what happened, which tools were involved, or what you did about it. “We did not know our staff were doing that” is not a defence anyone wants to rely on.
Why banning it does not work
The instinct is to forbid it. The trouble is that prohibition does not remove the demand, it removes the visibility. Tell people they may not use AI and the capable ones use it anyway, on personal accounts, on their phones, off the record. You are left with the same risk and less insight into it.
The better goal is not zero AI. It is no unmanaged AI. You bring the use into the open, give people a safe and approved way to do what they were going to do anyway, and make the rules clear enough that following them is easier than going around them.
A practical way to bring shadow AI into the light
- Find out what is already in use. Ask, without blame. A short, anonymous question to each team (“which AI tools do you use, and what for?”) usually reveals more than any audit. You cannot govern what you cannot see.
- Decide what is approved, and for what data. Pick a small set of tools you are comfortable with, ideally ones with business terms that do not train on your data, and say plainly which data may go into them. An approved-tools list does more to curb shadow AI than any warning.
- Give people a data ground rule they can remember. Most leaks come down to one question: is this safe to put into this tool? A simple data-classification guide (public, internal, confidential, personal) answers it in seconds.
- Make the safe path the easy path. If the approved tool is good enough and obviously allowed, most people will use it. Shadow AI thrives where the sanctioned option is worse than the unsanctioned one.
- Make owning up safe. People hide AI use because they fear the consequences of admitting it. A no-blame way to flag “I think I put the wrong thing into a tool” lets you contain a problem instead of discovering it months later.
- Write it down and keep it current. A short AI acceptable use policy, a named owner, and a risk register that lists shadow AI as a tracked risk turn all of the above from good intentions into something you can actually show.
Where a policy earns its keep
Every step above is a document. That is the point of an AI policy for your business: it is the approved-tools list, the data-classification guide, the staff one-pager and the risk register, written so the safe path is the obvious one. Done well, it does not slow your team down. It just means the AI they were always going to use is AI you can stand behind.
Our AI Safe-Use Pack ships with all of those pieces, including a risk register that already names unmanaged AI use as a tracked risk. If you would rather start smaller, the free AI Starter Kit gives you the ground rules and the data guide on a single page.
This article is general information, not legal advice. How UK GDPR and confidentiality obligations apply to your AI use should be considered with professional advice where it matters.