Insights

How is shadow AI affecting my company?

For risk & security leadsVerified July 2026

Shadow AI is the use of AI tools your organisation never approved or provisioned. A marketing manager pastes the draft board deck into a personal ChatGPT account. A developer runs client code through a free coding assistant. An analyst uploads a customer list to get it summarised. None of it appears on an invoice, and all of it moves your data outside your control.

If you carry the financial and security risk for a mid-market company, this is already happening inside yours. Industry surveys through 2025 and 2026 put the share of employees using AI tools without IT approval at well over half. The tools are free, they sit one browser tab away, and they work, which is why the behaviour spreads faster than policy keeps up.

Why shadow AI is a financial risk

Think of it as three exposures sitting on top of each other.

The first is data leakage with a long tail. On most consumer AI plans, inputs can be retained and used to train future models unless the user has actively opted out. After the consumer-terms changes that swept the major providers in late 2025, retention on training-enabled consumer accounts can run for as long as five years. A single pasted contract or forecast is not a passing exposure. It can sit in a training-eligible store long after the person who pasted it has left.

The second is compliance and contractual breach. If you handle personal data under GDPR, or you have signed confidentiality clauses with your own customers, an employee routing that data through an ungoverned tool can put you in breach without a single system being hacked. A regulator will not accept "it was a personal account" as a defence.

The third is concentration risk that no one has priced. When a critical workflow quietly comes to depend on one person's personal AI account, you hold an operational dependency you cannot see, audit, or replace. It tends to surface at the worst possible moment, usually when that person leaves.

Taken together, shadow AI turns a productivity shortcut into a balance-sheet risk that no one has quantified.

How to detect it

You cannot govern what you cannot see, so start with the evidence you already hold.

Your firewall, secure web gateway, and DNS logs already record traffic to the main AI domains. Pull a list of those endpoints and query the last 90 days. Volume and frequency show you where usage actually sits, rather than where you assume it does.

Individual AI subscriptions bought on personal or company cards show up in expense claims and in SaaS-management tooling, so a rising count of £20-a-month line items tells you something. Check, too, which third-party AI apps your staff have authorised against your Google Workspace or Microsoft 365 tenant through OAuth, since surprising grants are common and easy to miss. Managed browsers and endpoint tooling can report installed extensions, which catches the assistants embedded where you would not think to look.

Then ask. An anonymous survey with no disciplinary edge almost always finds usage the logs miss. People will tell you what they use once they believe the goal is a better tool rather than a reprimand.

The output of this pass is a plain register: which tools, used by which teams, carrying which class of data.

What to do about it

Resist the instinct to ban outright. A blanket block pushes usage onto personal phones you cannot see at all, which leaves you worse off than before. The job is to redirect the demand rather than suppress it.

Give people a sanctioned alternative first. The most effective control by far is a governed AI tool good enough that the unapproved one loses its appeal. Detection without a real alternative only teaches people to hide it better.

Then triage by data sensitivity. Someone using a free tool to polish a public blog post barely registers. The same person pasting customer records or unreleased numbers is the one to address today. Rank the register by data class and work down from the top.

Write the policy in plain language and hold it to a page: which tools are approved, which categories of data must never go into any external AI tool, and how to request a new one. A policy people can keep in their heads gets followed. A forty-page one does not.

Finally, close the highest-risk gaps on purpose. Where sensitive data is involved, move the workflow onto a commercial or enterprise tier that excludes your inputs from training by contract, and record that you have done it.

How to safeguard the business

Detection and triage are the first pass. What follows is maintenance work that keeps the exposure low as the market moves.

Move sanctioned usage onto commercial and enterprise plans, where the major providers exclude your inputs from model training by default. That is a materially different legal position from the consumer tiers. The same plans bring the controls worth having: single sign-on so access follows employment, admin visibility over who is using what, configurable retention, and data-loss-prevention rules that stop classified data reaching an external tool at all. Keep the register current, because the tool market shifts from month to month, and teach your people the distinction that matters most, which is the one between a personal account and a governed one.

Shadow AI usually means your people found something useful before the organisation gave them a safe way to use it. The risk is real, and left alone it gets expensive. The remedy is a governed on-ramp to the same capability, so the shortcut stops being worth taking.

This is where an enablement partner earns its place: running the discovery, ranking the exposure, and standing up a governed alternative your teams will prefer. That is the work Firestarter does in its six-week accelerator.

Sources and verification. Data-retention and training-default claims reflect the published consumer and commercial terms of the major providers as of July 2026. These change often, so confirm the current terms on each provider's trust or privacy pages before you set policy.

  • Risk & security lead

    Does AI train on my business data?

    Whether an AI provider trains on your business data depends almost entirely on which plan you buy. A risk manager's guide to the safe tiers across Anthropic, OpenAI, Google, and Microsoft.

    Read the guide

  • Risk & security lead

    Which AI is right for my company?

    A cost and risk comparison of AI from Anthropic, OpenAI, Google, and Microsoft for business: API and per-seat pricing, plus which fits a manufacturing, financial services, or software company.

    Read the guide