Shadow AI is the use of AI tools, models or services for work purposes without your business reviewing, approving or putting a data agreement around them. It is not a hypothetical risk on a future roadmap. It is almost certainly happening in your business today, through staff pasting emails, documents and spreadsheets into free chatbots because it is faster than the approved way of doing things.

The term borrows from shadow IT, the long-standing problem of employees using unapproved software or cloud storage. Shadow AI is the same instinct applied to AI tools, and it spreads faster because there is nothing to install. Opening a browser tab is enough.
It also tends to arrive through the most trusted parts of a business, not the riskiest ones. Think of a finance manager under deadline pressure, a solicitor drafting a first pass at a letter, or a recruiter shortening a job description. These are competent, careful people reaching for the quickest tool available, not staff cutting corners on purpose.
Table of Contents
How is shadow AI different from ordinary shadow IT?
The overlap is real, but the risk profile is not identical. An unapproved app or cloud drive holds data where you put it. An AI tool can retain what gets submitted, and depending on the provider’s terms, may use it to train future versions of the model. That is a meaningfully different kind of exposure.
| Factor | Shadow IT | Shadow AI |
|---|---|---|
| What it covers | Unapproved apps, software, cloud storage | Unapproved AI tools and models |
| Data handling | Stored where placed | May be retained or used for training |
| Barrier to use | Install, sign-up or admin rights | Open a browser tab |
| Business visibility | Some tooling exists to detect it | Very little in most UK businesses |
If you want the fuller picture on the older problem, we cover it in our guide to what shadow IT actually costs a business. Shadow AI deserves its own treatment because the risks and the fixes are not quite the same.
How many staff are actually doing this?
More than most owners guess. The NCSC cites Microsoft research finding that 71% of UK employees have used an AI tool their employer never sanctioned. A 2026 survey of 1,250 office professionals by PagerDuty found 66% had used AI tools despite believing their employer’s policy prohibited it. Almost nine in ten (88%) had shared some form of work information with a public AI tool.
What they shared is the part that should concern any UK business owner:
- 43% shared emails or business correspondence.
- 34% entered customer data.
- 31% shared financial information or confidential company documents.
Generative AI adoption among enterprise staff rose from 74% to 96% between 2023 and 2024, per IBM. Governance has not kept pace with that growth in most organisations, which is exactly how shadow AI became the norm rather than the exception.
What are the real consequences?
Data leaves your control permanently. Free AI tools often retain submitted content. Client data, source code or internal figures fed into a public model cannot reliably be recalled once submitted.
You inherit regulatory liability, even for someone else’s mistake. Under UK GDPR, your business stays accountable for personal data. That holds true even when an individual employee, not the company, chose the unapproved tool. The ICO can fine the most serious breaches up to £17.5 million or 4% of global annual turnover, whichever figure is higher.
Contracts and confidentiality duties can break quietly. Many client agreements specify how and where their data may be processed. A well-meaning employee pasting a client brief into a chatbot can breach that clause without anyone realising until an audit or a client asks the question directly.
Samsung’s 2023 experience remains the clearest cautionary tale. Forbes reported that engineers pasted confidential source code and meeting notes into ChatGPT three separate times in one month, which led the company to ban the tool outright. Every incident came from someone trying to solve a genuine work problem, not from malice.
A practical checklist for getting control of shadow AI
Banning AI tools outright tends to backfire. Staff simply move to personal devices, where visibility disappears entirely. A steadier approach, in line with NCSC guidance, works through five steps:
- Find out what is actually in use. Talk to team leads directly rather than relying on assumptions. Most businesses underestimate the true number.
- Offer an approved alternative. Give staff an enterprise AI tool covered by a proper data processing agreement so there is no need to reach for a free public one.
- Put a short policy in writing. Cover what can and cannot go into an AI tool, and who approves new ones. Long policies get ignored; short ones get read.
- Train on the actual risk, not the rule. Most staff who leak data through AI tools do not know their input can be retained or reused. A concrete example does more than a compliance memo.
- Test the systems that connect to it. If your business runs an AI chatbot or an internal assistant wired into a large language model, get it properly tested. So do not assume the vendor’s defaults are safe on their own. Our guide to AI and LLM penetration testing sets out what that testing should cover.
Three-quarters of CISOs surveyed by IBM now say insider activity, including staff misusing tools with no bad intent, worries them more than external attackers. Shadow AI is a large part of why that shift happened.
Frequently asked questions
What exactly counts as shadow AI?
Any AI tool, model or service used for work tasks that your business has not reviewed, approved or covered under a data processing agreement. Common examples are free chatbots, AI browser extensions and personal AI accounts used for company work.
Is shadow AI just a large-enterprise problem?
No. Smaller UK businesses often have less visibility and fewer formal controls, which makes the risk higher, while carrying identical exposure under UK GDPR regardless of company size.
Does using an approved AI tool still count as shadow AI?
No. Once a tool has gone through your review process and sits under a proper data processing agreement, it is no longer shadow AI. The risk lies specifically in the unapproved, unreviewed use.
What’s the fastest way to reduce the risk this month?
Start with an honest conversation about what tools staff already use, then offer one approved alternative for the most common task, usually summarising or drafting text. It closes the biggest gap without waiting for a full policy rewrite.
Can a penetration test actually help with shadow AI?
Not directly for staff behaviour, but it matters where your business has built its own AI-connected systems. Testing shows whether an attacker could actually exploit those systems, rather than assuming the controls work because they exist on paper.
Shadow AI will not disappear because a policy says it should. It recedes when staff have a safer option, a clear rule and a reason to trust that IT understands what they actually need. Get those three things right and the risk drops fast. If your business has built or bought anything that connects to an AI model, that is worth checking with a proper penetration test rather than assumed safe. Get in touch for a conversation about what a scoped review would look like.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.