AI GOVERNANCE & COMPLIANCE · SERVICENOW AI CONTROL TOWER · IRM / GRC · ENTERPRISE SERVICE MANAGEMENT · PROCESS RE-ENGINEERING · EU AI ACT · ISO/IEC 42001 · UK GDPR & DPIAs · AI GOVERNANCE & COMPLIANCE · SERVICENOW AI CONTROL TOWER · IRM / GRC · ENTERPRISE SERVICE MANAGEMENT · PROCESS RE-ENGINEERING · EU AI ACT · ISO/IEC 42001 · UK GDPR & DPIAs ·
AI Governance / Shadow AI

Your team is already using AI. The question is whether you can see it.

Shadow AI is not rogue behaviour. It is what happens when people find genuinely useful tools and have no sanctioned route. The risk is not the tool: it is the invisibility. Client records, case files and company data leaving via a personal account, with no policy, no training and no oversight.

78%
of AI users bring their own AI tools to work (80% at small and medium-sized companies)
Microsoft & LinkedIn Work Trend Index, 2024
52%
of people who use AI at work are reluctant to admit to using it for their most important tasks
Microsoft & LinkedIn Work Trend Index, 2024
A familiar picture

Picture a fee-earner the night before a hearing

It is late. The sanctioned document system is slow and the AI assistant the firm provides is too basic for what they need. So they open a personal browser tab, paste the case summary into a well-known AI chatbot, and get what they need in seconds.

No malice. No recklessness. Just deadline pressure and a better tool one click away.

That is shadow AI. And that case summary just left the organisation.

Typical scenario
  • 01Deadline pressure at 10pm. No time for the slow sanctioned tool.
  • 02Personal device. Personal account. Case notes pasted in.
  • 03Excellent summary. Job done. Nobody knows it happened.
  • 04Client data now in a third-party model. No audit trail. No consent. No policy.
The gap

Board awareness is not governance

Most leadership teams now know that AI is being used. Many have a policy on paper. But awareness and policy are not the same as governance, and the 52% figure makes the gap plain: more than half of people using AI for their most important tasks will not tell you about it.

That means your policy, however well-written, is not reaching the moments that matter. The risk does not live in the boardroom. It lives with the person under deadline, on a personal device, with a tool that genuinely works.

Governance means knowing what is actually being used, and making the right route easy enough that people take it.

Awareness
"We know people are using AI tools."
Policy on paper
"We have a policy. It says don't use unsanctioned tools."
Governance
"We know what is being used, people have a good sanctioned route, and they are trained to use it safely."
Why bans backfire

A ban does not remove the demand. It removes the visibility.

Before the ban

Usage on work devices

At least it is in your network. You could in principle see it, log it, and set guardrails.

After the ban

Usage on personal phones

Zero visibility. Same data risk. Now outside your network, outside your policy, and outside your knowledge.

The proportionate response

Enable and govern

Give people a genuinely useful, sanctioned route. Pair it with clear training and rules. The risk goes down. The productivity goes up.

Legal exposure

What shadow AI actually exposes

No scare tactics, just the three frameworks that genuinely bite when data leaves via a personal AI account.

UK GDPR

Personal data leaving the organisation

When personal data is pasted into a public AI service through a personal account, it leaves the organisation with no data processing agreement, no lawful-basis assessment and no DPIA behind it. The organisation, as controller, carries that exposure, and a ban that is not enforced or monitored does little to change it.

Client confidentiality

Professional duties to clients

In legal, accountancy, healthcare and other professional services, client data carries confidentiality obligations that sit entirely separately from data protection law. Pasting client information into a third-party model without the client's knowledge is a breach of those duties, regardless of any AI policy.

Equality Act 2010

Where decisions touch people

When shadow AI is used to support decisions about people (shortlisting CVs, assessing performance, scoring applications), the Equality Act applies to the outcome regardless of the tool. If the model produces a biased result and you used it, the exposure is yours.

EU AI Act Article 4 is the training hook: it makes staff AI literacy a duty for organisations in scope of the Act, and the de facto benchmark for everyone else. Shadow AI puts that expectation in sharp relief.

The proportionate response

The enablement path

Four steps, in order. Each makes the next one more effective.

01

See it

Understand what AI tools your team is actually using, across every device and route. You cannot govern what you cannot see. This is the AI inventory.

02

Sanction it

Give people a genuinely useful, approved route. Not a worse option with a compliance badge on it. A tool people will actually choose over the personal account.

03

Train it

Staff AI-literacy training in plain English. What the tools do, where the risks live, what data must never go in. Proportionate to your sector. Aligned to EU AI Act Article 4.

04

Govern it

An acceptable-use policy people actually read, in plain English. Roles and accountability assigned. A register so you can show what you are using and why. Rules that travel with the person, not just the device.

Where we help

Two services built for this problem

Primary remedy

AI Use Policy Pack

A tailored governance starting framework for organisations using AI without a policy around it. A plain-English acceptable-use policy specific to your tools, a one-page staff quick-reference, a focused risk note, and a 30-minute handover call. Fixed price, in approximately one week.

  • A tailored acceptable-use policy in plain English, written around the tools your team actually uses
  • A one-page staff "AI Do's and Don'ts" quick-reference, designed to be understood at a glance
  • A short risk note tied to your specific AI use, each point honestly scoped as legal duty or best practice
  • A 30-minute handover call to walk you through the pack and how to roll it out
See the AI Use Policy Pack →
Discovery first

AI Controls and Security Assessment

If you need to understand the full scope of your AI estate first: what is being used, where, and what data it touches. A discovery and mapping exercise aligned to NCSC guidance, with a prioritised remediation roadmap.

  • Full discovery and mapping of your AI estate
  • Vulnerability and data-handling risk assessment
  • Prioritised remediation roadmap, NCSC-aligned
See the Controls Assessment →
Start free

Not sure where you stand?

Take the free 10-minute AI Readiness Scorecard. Answer a handful of questions about how your business uses AI. We will send a RAG-rated readiness score across our ten governance dimensions, with a plain-English recommended next step. No obligation, no sales pitch.