Shadow AI is any AI tool your staff use for work that the business has not chosen, paid for or checked. In a small firm it usually means personal ChatGPT accounts, meeting note-takers and browser add-ons. You can find most of it in one afternoon by checking five places: your admin console, card statements, browsers, calendars and a no-blame staff question.
What does shadow AI mean for a small business?
Shadow AI means work data going into AI tools that sit outside the business’s accounts, contracts and settings. The risk sits in what the business cannot do: it cannot see what went in, cannot get it back and cannot switch it off when someone leaves.
In a 12-person firm this looks ordinary. A practice manager pastes a client complaint into a free chatbot to soften the reply. A bookkeeper uploads a supplier spreadsheet for a summary. A salesperson lets a note-taking bot join every call.
None of these people are being reckless. They found a faster way to do their job, and nobody gave them an approved one.
How common is shadow AI in UK workplaces?
Shadow AI is the normal state of a UK workplace. Microsoft’s October 2025 survey of 2,003 UK employees found 71% have used unapproved consumer AI tools at work, and 51% still do so every week.
The same Microsoft research gives the reasons. 41% said it is what they already use at home, and 28% said their employer offers no approved option. Only 32% were concerned about the privacy of company or customer data they put in.
The pattern is global too. Microsoft and LinkedIn’s 2024 Work Trend Index found 78% of AI users bring their own AI tools to work. The sensible starting assumption for any owner is that it is already happening.
Why does it matter where the data goes?
Shadow AI matters because the same chatbot handles your data differently depending on whose account it runs under. A personal account follows consumer terms. A business account follows the contract your firm signed.
OpenAI’s own help centre is clear on this. For its services for individuals, OpenAI says it may use your content to train its models unless the user turns off “Improve the model for everyone”. Most staff never open that setting.
On business plans the default flips. OpenAI’s business data page states it does not train on data from ChatGPT Business, Enterprise or the API by default. The tool looks identical on screen. The data terms behind it are different.
That is why banning “ChatGPT” misses the point. The question for an owner is which account, holding which data. Our guide on keeping company data out of model training covers the vendor terms in more depth.
Where do you look for shadow AI in an afternoon?
You find shadow AI by checking five places in order, starting with the ones that need no conversation. Each check takes 15 to 45 minutes in a firm of 5-20 people.
| Where to look | What it shows | How to check it |
|---|---|---|
| 1. Google Workspace or Microsoft 365 admin console | AI apps staff have signed into with a work account and allowed to read email, files or calendars | Google: Security, then API controls, then Manage third-party app access. Microsoft: Entra, then Enterprise applications, then Permissions |
| 2. Company card and expense claims | Paid AI subscriptions bought on a work card or claimed back | Search the last 6 months of statements for OpenAI, Anthropic, Otter, Fireflies, Grammarly, Jasper and “AI” |
| 3. Browsers on work machines | AI extensions that read every page a person opens, including client portals | Open the extensions page in each browser on shared and personal work devices |
| 4. Calendars and meeting invites | Note-taking bots that join calls and record clients | Look for extra attendees with names like “Notetaker”, “Otter” or “Fireflies” in the last month of external meetings |
| 5. A no-blame staff question | Free personal accounts that leave no trace in any system | Ask everyone one question in writing and promise no consequences for the answer |
The admin console check is the most revealing. Google’s admin help explains how to see and control which apps access your Google Workspace data, including which data each app can reach. Microsoft documents the same review for permissions granted to enterprise applications in Entra.
Treat the staff question as the most important of the five. Free personal accounts show up nowhere else. A good wording is: “Which AI tools have you used for work in the last three months, and what did you put into them?”
What should you do with each tool you find?
Every shadow AI tool you find should go through the same three-question rule, so the decision is about data and use rather than the brand name. Run each tool through these questions in order.
- Does it touch client, staff or financial data? If no, keep it and add it to your approved list. A tool rewording a social post on a personal account is low risk.
- If yes, is there a business version with no-training terms by default? If there is, move that person onto a business account the firm owns and pays for. Then close or clean the personal account.
- If there is no business version, or nobody can say what the tool does with data, stop using it for that job. Then give the person an approved tool that does the same job within a week. A ban with no replacement sends the habit straight back underground.
Record the outcome on one page: tool, who uses it, what data goes in, and keep, move or stop. That page is the start of an AI inventory, and it is the first thing anyone helping you with AI governance will ask to see.
Most small firms end the afternoon with three to eight tools on the page. Usually one or two need moving to a business account. Rarely is anything a crisis.
How do you stop shadow AI coming back?
Shadow AI comes back whenever the approved route is slower than the unapproved one. The fix is making the approved tool easier to reach than the personal one, then writing the rules down.
Three things keep it in check. First, give staff a business account for the AI tool most of them already use. Second, write a one-page AI use policy that names approved tools and the data that never goes into any AI tool. Third, repeat the five-place check every quarter, which takes about an hour once the first sweep is done.
A business that sets up its approved AI properly, with its own context and rules loaded in, removes most of the reason to wander. That is what The Business Brain is built to give a small team.
Is shadow AI a governance problem or a design problem?
Shadow AI is a sign that the business never decided how AI should fit its work, so staff decided for it. Policies help, but they only hold when the approved setup is designed around the jobs people actually do.
This is the diagnose-first view Bedrock AI takes. Map which jobs staff are already using AI for, and you have a free list of where AI already earns its place in your firm. The shadow tools show you where demand already exists.
The next step in a small firm is to turn that list into one deliberate setup. That means the right accounts, data rules and owner for each tool. Our piece on AI governance for small businesses sets out why that design work comes before any policy.
FAQ
Is shadow AI illegal for a UK small business? Shadow AI is not illegal in itself. The risk is that staff put personal data into a tool the business has no agreement with. Under UK GDPR the business remains responsible for that client or staff data, so unapproved tools create exposure the owner cannot see.
Should a small business ban ChatGPT to stop shadow AI? A ban on its own rarely works, because staff who find a tool useful keep using it on their phones. A better route is a business ChatGPT, Claude or Copilot account the firm controls, plus a clear rule about which data never goes into any AI tool.
How often should you check for shadow AI? A firm of 5-20 staff should run the full five-place check once, then repeat it every quarter. After the first sweep, the quarterly check takes about an hour, because you only look for tools added since the last one.
What is the difference between shadow AI and shadow IT? Shadow IT is any unapproved software or device used for work. Shadow AI is the AI part of it, and it carries an extra risk. What staff type in can be stored and, on some consumer accounts, used to train the provider’s models.
Get ahead with AI by getting The Business Brain | Would rather talk it through? Book a free 15-minute call