Shadow AI is the use of AI tools that the business has not approved, by staff trying to do their job well. It is rarely defiance; it is usually a gap between what people need to do their work and what the policy, or the procurement process, allows them to use.
The response that works is not prohibition. Prohibition moves the behavior out of sight, and unbudgeted, unassessed tool use is precisely the exposure that governance exists to reduce.
This guide covers how to find shadow AI, why it happens, and how to bring it under control without driving it underground. It is part of the Governance, Risk & Data pillar.
Shadow AI is a signal about the policy, more often than it is a signal about the staff.
Why it happens
Four causes, in order of frequency.
- The tool people need is not approved. The work requires a capability, and the approved list does not have it.
- The approval process is slow or invisible. Nobody knows how to request a tool, so they do not.
- The data rule is unknown or unclear. Staff do not realise the tool they are using handles data the policy restricts.
- The policy took too long to arrive. Use began before the policy existed, and it never stopped.
The evidence suggests how widespread the behavior is. In EOG’s synthesis of 2025–2026 research, 44% of small businesses reported having AI acceptable-use policies (GTIA, 2026) — which means most businesses are in some form of shadow-AI position, with staff using tools that no one has assessed.
How to find it
Finding shadow AI does not require surveillance, and surveillance is counter-productive: it produces concealment rather than information. Three approaches work better.
- Ask, anonymously. A short survey with a single question — “which AI tools do you use for work, and for what?” — produces more accurate information than monitoring, and it identifies the gap.
- Look at the invoices. Expense claims, card statements and software subscriptions frequently show tools nobody in leadership knows about.
- Ask at the point of the task. In workflow conversations, ask what people reach for. The answer is usually the tool they would not have requested.
The output is not a list of offenders. It is a list of unmet needs, which is a procurement and policy problem rather than a discipline one.
How to bring it under control
Five steps, in this order.
1. Close the gap. Where a tool is widely used and the data position is acceptable, approve it. Approval is cheaper than enforcement, and it converts a hidden risk into a governed one.
2. Provide an alternative where it is not. Where a tool cannot be approved, provide the approved option for the same task, so the work can still be done.
3. Restate the data rule, once, clearly. The prohibited categories, the default when uncertain, and the person to ask. Not a lecture — a short reminder with examples.
4. Make approval easy. A one-page request, a named approver, and a stated turnaround. The absence of a route is the most common cause of the behavior.
5. Repeat. Shadow AI reappears with each new tool, so the survey and the gap-closing are annual, not one-off.
The sequence matters. A data-rule restatement with no alternative and no approval route produces compliance in the meeting and the same behavior the following week.
What to do about past use
Where a tool has been used on data that the policy prohibits, the response is the same as any incident — and it should be handled without blame, or the next one will not be reported.
- Establish what was used and on what data.
- Assess the exposure against the tool’s retention and training terms.
- Act proportionately, from deleting content to notifying affected parties.
- Fix the cause, usually the missing approved alternative.
- Record it, so the position can be evidenced.
See When AI Goes Wrong and Data Security and Confidentiality in AI Tools.
A worked gap-closing
A firm runs the anonymous survey and finds four tools in use that nobody in leadership knew about. Three are note-taking tools on personal accounts; one is a general assistant used for drafting.
- The note-taking tools. Used for internal meetings only, but two of them are personal accounts with no data processing agreement. The gap: the business had no approved meeting-notes tool. Action: approve one business-tier tool with training disabled, and require internal meeting notes to move to it.
- The assistant. Widely used and broadly acceptable, but on personal accounts, which means company material is in services the firm has not assessed. Action: buy a small number of business-tier seats, and name them in the policy.
- The data rule. Two of the four users did not know that client documents were prohibited in personal accounts. Action: restate the rule with examples in the next team meeting, and add a one-page summary to the shared drive.
The survey produced no disciplinary action and closed most of the exposure. The following year, the same survey found one new tool — which is the expected result, and the reason the exercise repeats.
Common mistakes
- Prohibiting without providing an alternative. The behavior goes underground.
- Treating it as misconduct. Punishment produces concealment, and concealment produces bigger incidents.
- Surveillance. Monitoring produces less information than asking, and more distrust.
- A policy with no approval route. People cannot comply with a process they cannot find.
- A one-off response. Shadow AI returns with the next tool.
- No restatement of the data rule. Staff revert to the behavior they were never told about, and the second round of shadow AI is larger than the first.
Frequently asked questions
What is shadow AI?
The use of AI tools that a business has not approved for company work — usually by staff trying to complete a task the approved tools do not cover.
How do we find out if staff are using unapproved AI tools?
Ask anonymously rather than monitoring: a short survey identifying which tools are used and for what. Check expenses and subscriptions as corroboration.
Should we ban unapproved AI tools?
A ban without an alternative is usually unenforceable and drives use underground. Require approval before use on company work, prohibit the listed data categories in unapproved tools, and make approval easy.
Why do staff use unapproved AI tools?
Because the tool they need is not approved, the approval route is invisible or slow, the data rule is unclear, or the use began before any policy existed.
What do we do if a tool has been used on prohibited data?
Treat it as an incident: establish the facts, assess exposure against the tool’s retention and training terms, act proportionately, fix the cause and record it — without blame, so the next case is reported.
How often should we check for shadow AI?
Annually at minimum, and whenever a new capability becomes widely available. Each new generation of tools produces a new round of unapproved use, so the check is a recurring exercise rather than a one-off audit.
Does approving more tools create more risk?
Not compared with the alternative. An approved tool with a known data position is governable; an unapproved one on a personal account is not. Approval with conditions — approved for internal work, not for client data — is usually the right answer.
Is unapproved tool use a disciplinary matter?
Rarely, and treating it as one is counter-productive. The usual cause is a gap in the approved tools or in the approval route, and closing the gap is more effective than pursuing the individual.
Next step
Run the anonymous survey this month, approve what can be approved, provide alternatives for the rest, and restate the data rule once with examples. See Data Security and Confidentiality in AI Tools and Writing an AI Acceptable-Use Policy, or book an AI adoption call to run the review with you.
Sources
- GTIA (2026): 44% of small businesses have AI acceptable-use policies; 24% cite data security and compliance as a top AI barrier.
Figures are cited from their sources and dated. Where a source is a vendor study, the sample size is stated where published.