
By Connor Whitehouse, Senior Technical Consultant
Most businesses worrying about AI are focused on the tools they know about. The bigger risk may be the ones they do not.
Shadow AI is the term used when staff use AI tools outside the organisation's approved processes. That might be somebody using ChatGPT to help write a report, or a team uploading a spreadsheet to an AI tool they have found online. Increasingly, though, it is less obvious than that. AI features are now built into software businesses have used for years, and employees may be using them without giving much thought to what sits behind them.
None of this usually comes from bad intentions. People are trying to solve a problem, save time or get through their workload. If a tool can summarise a document, analyse some data or draft an email in seconds, it is easy to see why somebody would use it.
The problem starts when the business has no visibility of what is being used or what information is being shared with it.
Why shadow AI keeps appearing
It is tempting to see shadow AI as something IT should be able to prevent. In reality, there are a few fairly simple reasons why it keeps appearing.
Speed is one of them. People have deadlines and immediate problems to solve. If a tool can turn a two-hour task into a ten-minute one, waiting weeks for somebody to decide whether it can be used is not particularly attractive.
Accessibility makes that even easier. Many AI tools need little more than a web browser and an email address. There is nothing to install, no significant cost and no reason for IT or procurement to become involved. Someone can start using a new tool in the time it takes to create an account.
Then there is awareness. Most employees do not think of themselves as introducing new technology into the business. They have found something useful and are using it to do their job. Questions about where information is processed, how long it is retained or whether it is used to train a model are unlikely to be the first things they think about.
Each of those behaviours is understandable. The difficulty is what happens when they are repeated across different teams and departments without anyone having the overall picture.
The risk is in the information
The conversation around shadow AI can become too focused on the tools themselves. What matters more is what people are putting into them.
There is a considerable difference between asking an AI tool to improve the wording of a generic paragraph and uploading a document containing customer, employee or commercially sensitive information. To the person using the tool, however, the action can feel much the same.
That is where existing policies can fall short. Most businesses already have rules covering data protection, information security and acceptable use. Those policies may never have been written with AI in mind.
Telling somebody not to share confidential information is one thing. Making sure they understand that pasting information into an AI prompt is still sharing it with another system is another.
The technology has changed much faster than the way many businesses talk to their staff about handling information.
Does blocking AI solve the problem?
The obvious response is to restrict access. If public AI tools create a risk, blocking them can seem like the simplest answer.
There will be situations where that is appropriate, particularly when highly sensitive information is involved. But as a general approach it has limitations.
Blocking one website does not remove the reason somebody wanted to use it in the first place. They still have the same workload and the same problem to solve. There are also now so many ways to access AI, including through existing business software and personal devices, that trying to prevent every possible use quickly becomes difficult.
A better starting point is to make it clear what people can use, what they can use it for and what information should never be entered into it.
That needs to be practical. If the approved process takes too long or there is no obvious person to ask, people are more likely to make the decision themselves.
Finding what is already there
Before introducing more controls, a business needs some idea of what is already being used.
That does not necessarily require a major discovery exercise. Speaking to teams about the tools they use, reviewing existing software for newly introduced AI features and looking at expense and procurement records can quickly start to build a picture.
The important part is not to treat the exercise as an attempt to catch people doing something wrong. If employees think admitting they use an AI tool will lead to it immediately being taken away, they have very little reason to tell you about it.
In some cases, the tools people have found will be unsuitable and should stop being used. In others, they may have found something genuinely valuable that the business could adopt properly.
Both are useful things to know.
Getting the balance right
Managing shadow AI is not about stopping people from experimenting. Some of the most useful applications of AI will be found by the people closest to the work, rather than through a formal technology project.
The aim is to give that experimentation some boundaries.
People need to know which tools are approved, what information can and cannot be shared, and where to go if they find something new they want to use. Somebody then needs to be able to review it without turning a simple request into a lengthy approval process.
There also needs to be an up-to-date view of the AI already in use. That includes standalone tools, but also AI capabilities being added to existing systems. Otherwise, the business can have a perfectly good process for approving new software while missing changes happening inside software it approved years ago.
Shadow AI is therefore rarely just a staff behaviour problem. If people have no clear guidance, no approved alternatives and no straightforward way to get a useful tool assessed, unofficial use is fairly predictable.
The first step is visibility. Find out what is being used, understand what information is going into it and decide which uses the business is comfortable with. From there, the rules become much easier to set.
For some businesses that can be managed internally. For others, bringing in independent technology leadership can provide the oversight needed to understand what is already in use and put the right controls around it. If that is a conversation worth having, the IT and digital transformation team can help.
This article has been prepared for information purposes only. Formal professional advice is strongly recommended before making decisions on the topics discussed in this release. No responsibility for any loss to any person acting, or not acting, as a result of this release can be accepted by us, or any person affiliated with us.
.jpg)
.png)



