Picture a fee-earner the night before a hearing
It is late. The sanctioned document system is slow and the AI assistant the firm provides is too basic for what they need. So they open a personal browser tab, paste the case summary into a well-known AI chatbot, and get what they need in seconds.
No malice. No recklessness. Just deadline pressure and a better tool one click away.
That is shadow AI. And that case summary just left the organisation.
- 01Deadline pressure at 10pm. No time for the slow sanctioned tool.
- 02Personal device. Personal account. Case notes pasted in.
- 03Excellent summary. Job done. Nobody knows it happened.
- 04Client data now in a third-party model. No audit trail. No consent. No policy.
Board awareness is not governance
Most leadership teams now know that AI is being used. Many have a policy on paper. But awareness and policy are not the same as governance, and the 52% figure makes the gap plain: more than half of people using AI for their most important tasks will not tell you about it.
That means your policy, however well-written, is not reaching the moments that matter. The risk does not live in the boardroom. It lives with the person under deadline, on a personal device, with a tool that genuinely works.
Governance means knowing what is actually being used, and making the right route easy enough that people take it.
A ban does not remove the demand. It removes the visibility.
Usage on work devices
At least it is in your network. You could in principle see it, log it, and set guardrails.
Usage on personal phones
Zero visibility. Same data risk. Now outside your network, outside your policy, and outside your knowledge.
Enable and govern
Give people a genuinely useful, sanctioned route. Pair it with clear training and rules. The risk goes down. The productivity goes up.
What shadow AI actually exposes
No scare tactics, just the three frameworks that genuinely bite when data leaves via a personal AI account.
Personal data leaving the organisation
When personal data is pasted into a public AI service through a personal account, it leaves the organisation with no data processing agreement, no lawful-basis assessment and no DPIA behind it. The organisation, as controller, carries that exposure, and a ban that is not enforced or monitored does little to change it.
Professional duties to clients
In legal, accountancy, healthcare and other professional services, client data carries confidentiality obligations that sit entirely separately from data protection law. Pasting client information into a third-party model without the client's knowledge is a breach of those duties, regardless of any AI policy.
Where decisions touch people
When shadow AI is used to support decisions about people (shortlisting CVs, assessing performance, scoring applications), the Equality Act applies to the outcome regardless of the tool. If the model produces a biased result and you used it, the exposure is yours.
EU AI Act Article 4 is the training hook: it makes staff AI literacy a duty for organisations in scope of the Act, and the de facto benchmark for everyone else. Shadow AI puts that expectation in sharp relief.
The enablement path
Four steps, in order. Each makes the next one more effective.
See it
Understand what AI tools your team is actually using, across every device and route. You cannot govern what you cannot see. This is the AI inventory.
Sanction it
Give people a genuinely useful, approved route. Not a worse option with a compliance badge on it. A tool people will actually choose over the personal account.
Train it
Staff AI-literacy training in plain English. What the tools do, where the risks live, what data must never go in. Proportionate to your sector. Aligned to EU AI Act Article 4.
Govern it
An acceptable-use policy people actually read, in plain English. Roles and accountability assigned. A register so you can show what you are using and why. Rules that travel with the person, not just the device.
Two services built for this problem
AI Use Policy Pack
A tailored governance starting framework for organisations using AI without a policy around it. A plain-English acceptable-use policy specific to your tools, a one-page staff quick-reference, a focused risk note, and a 30-minute handover call. Fixed price, in approximately one week.
- ✓A tailored acceptable-use policy in plain English, written around the tools your team actually uses
- ✓A one-page staff "AI Do's and Don'ts" quick-reference, designed to be understood at a glance
- ✓A short risk note tied to your specific AI use, each point honestly scoped as legal duty or best practice
- ✓A 30-minute handover call to walk you through the pack and how to roll it out
AI Controls and Security Assessment
If you need to understand the full scope of your AI estate first: what is being used, where, and what data it touches. A discovery and mapping exercise aligned to NCSC guidance, with a prioritised remediation roadmap.
- ✓Full discovery and mapping of your AI estate
- ✓Vulnerability and data-handling risk assessment
- ✓Prioritised remediation roadmap, NCSC-aligned