Introduction
Over the last year, we’ve spoken to a lot of businesses about AI. Interestingly, very few of those conversations start with someone saying, “We’re rolling out AI.”
More often, they start with comments like: “A few people have been using ChatGPT.” “Someone mentioned they’re using AI to help write emails.” “We’ve already got a couple of Copilot licences that people have started using.”
That’s because for most businesses, AI has already found its way in before the business has thought about how it’s being used, what information is being shared, or whether employees have any guidance to follow.
This is known as ‘Shadow AI’. In this article, we’ll look at why it happens, the problems it can create and what businesses can do to bring AI use into the open for their teams.
The Short Answer Is…
Shadow AI happens when employees start using AI tools before the business has decided how AI should be used. That’s becoming increasingly common because AI is easy to access and often built into software people already use every day. Rather than trying to ban it, most organisations are better off understanding what’s already happening and putting sensible guardrails in place.
What is Shadow AI?
Shadow AI is the use of AI tools within a business without formal approval or oversight. That could mean using a personal ChatGPT account for work, trying a new AI note-taking tool without checking it with IT, or putting company information into a platform that hasn’t been reviewed.
The term ‘shadow’ can make it sound secretive or deliberately underhand, but that usually isn’t the case. Most employees aren’t trying to get around company rules; they’re just trying to work more efficiently and may not realise the consequences.
Why Shadow AI happens
Most business technology is introduced from the top down: a new system is chosen, approved and rolled out, with somebody responsible for managing how it is used. AI is different to other tech in that it’s being adopted primarily from the bottom up.
It’s easy for employees to try tools for themselves, often using free accounts and without needing support from IT. If something helps them write an email, summarise a document or get through a repetitive task more quickly, it can easily become a regular part of their working day.
AI is also being added to tools people already use. Someone might receive an AI-generated summary at the top of a Google search, use an AI feature that has appeared within an existing app, or accept a suggested response without thinking of any of those actions as ‘using AI’.
In contrast, some employees may know it’s AI but choose not to mention it, especially if there’s been no communication around AI usage. They might be unsure whether it is allowed, or worry that using it will be viewed as cutting corners rather than finding a more efficient way to work.
So by the time leadership begins discussing an AI strategy, the business may already have months of AI use to understand.
What problems can Shadow AI create?
When AI tools are being used without oversight, businesses lose visibility of which platforms people are using and what information is being shared in them.
Cybersecurity and data protection
One of the biggest concerns is sensitive information ending up in tools that haven’t been approved by the business.
An employee might paste customer information into an AI tool to help draft a response. Someone else might upload meeting notes to generate a summary. Another employee may use AI to analyse information from a spreadsheet.
The problem is that once that information has been entered into an external platform, it has left the systems and controls your business has put in place to protect it. Depending on the tool, employees may have little understanding of how that information is stored, who can access it, how long it is retained for or whether it could be used to improve future AI models.
Compliance
Most organisations work within customer contracts, industry standards or regulatory requirements that dictate how information should be handled. Your employees using AI tools you don’t know about is especially problematic because you may be falling into non-compliance without even realising. Ultimately, it’s hard to assess the risks of a tool if you don’t know it’s being used in the first place.
Inaccurate outputs
AI can be extremely useful, but it’s not always accurate. Anyone who has spent time using AI will have come across examples where it misunderstood a question, missed important context or confidently presented incorrect information as fact.
If employees are using AI to support reports, proposals or customer communications, someone still needs to review the output and apply their own judgement.
Inconsistent ways of working
Over time, teams can end up using different AI platforms, following different processes and producing work to different standards. It also becomes harder to introduce an approved company-wide AI tool if employees are being asked to give up something they’ve already relied on for months.
Why Banning AI Doesn’t Work
Once businesses realise Shadow AI exists, there can be a temptation to shut it down completely. But removing access to a tool doesn’t remove the reason employees started using it, particularly if there’s no approved alternative or explanation of what should happen next.
This approach can also drive the behaviour further underground. Employees become less likely to mention the tools they’re using, which further reduces visibility rather than improving it.
The organisations seeing the greatest value from AI aren’t the ones preventing its use. They’re the ones creating a safer way for employees to use it.
A Better Approach to AI
Most SMEs don’t need a 50-page AI policy, but they do need some basic ground rules.
That should include:
- Which AI tools are approved for work use
- What information should never be entered into an AI platform
- When AI-generated outputs should be reviewed by a person
- Who is responsible for reviewing new AI tools
- How AI usage will be monitored over time
The goal isn’t to remove flexibility or AI usage altogether. It’s to give employees enough guidance that they can use AI confidently without creating unnecessary risk.
In many cases, simply having a conversation with employees is a good place to start. Ask people whether they’re already using AI. Ask which tools they’re using and what they’re using them for. You may discover that adoption is far wider than expected.
How Microsoft 365 Copilot and AI readiness fit into the picture
As mentioned, one of the challenges with Shadow AI is that businesses often have very little visibility or control over the tools employees are using.
Microsoft 365 Copilot approaches things differently because it operates within the Microsoft 365 environment that your organisation already owns and manages. So instead of uploading information into a separate platform, employees can access AI capabilities through tools many people already use every day, including Outlook, Teams, Word and Excel.
Operating within Microsoft 365 doesn’t remove the need to prepare the environment first. Copilot can bring existing issues with permissions, governance and information management to the surface. Could confidential HR information be surfaced to the wrong person? Are board meeting summaries only available to the people who should see them? Are documents stored in the right places, with appropriate permissions?
Once those foundations are understood, it’s much easier to decide how AI should fit into the business.
In conclusion…
A few years ago, businesses worried about employees signing up for software that IT knew nothing about. Shadow AI feels like the next version of that same challenge.
The difference is that AI isn’t arriving as a completely separate piece of technology. It’s appearing in search engines, business applications and productivity tools that people already use every day. In some cases, people may not even realise an AI feature has become part of how they work which makes it difficult to spot and even harder to govern.
Before thinking about what AI should look like in your business, it’s worth understanding what it already looks like today. You might find that the conversation is much bigger, and much further along, than you realised.
Do You Know How AI Is Already Being Used in Your Business?
Book An AI Readiness Review
Our AI Readiness Review is designed to help you identify your AI opportunities, understand what’s already happening within your organisation and build a realistic plan based on the way your business works today.
FAQs
What is Shadow AI?
Shadow AI is the use of AI tools within a business without formal approval or oversight. This could include employees using ChatGPT, AI note-taking tools or other AI platforms that haven’t been approved by the organisation.
Why is Shadow AI becoming more common?
AI is easy to access, often free to use and increasingly built into software people already use every day. As a result, AI adoption is frequently happening from the bottom up rather than through an official company rollout.
What risks does Shadow AI create?
Shadow AI can create cybersecurity, data protection and compliance risks if employees enter sensitive business information into unapproved tools. It can also lead to inaccurate outputs and inconsistent ways of working across teams.
Should businesses ban AI?
In most cases, no. Banning AI doesn’t address the reasons employees started using it in the first place and may simply push usage further underground. Most organisations benefit more from providing approved tools and clear guidance on how AI should be used.
How can organisations manage Shadow AI?
A good starting point is understanding what employees are already using. Businesses should then establish guidance around approved tools, information handling, human review of outputs and responsibility for assessing new AI solutions.
How does Microsoft 365 Copilot help reduce Shadow AI risks?
Microsoft 365 Copilot operates within your existing Microsoft 365 environment, giving organisations more visibility and control than a collection of independently adopted AI tools. However, businesses still need appropriate governance, permissions and information management practices in place first.