Skip to content
AI Metric

Chris

Shadow AI: your team is already using tools you have not approved

Somebody in your firm used a free chatbot for work this week. Probably several somebodies. The estimator tidying a clarification email, the office manager summarising a tender document, the site manager rewording a snag list before it goes to the client. This is shadow AI: useful tools adopted quietly, on personal accounts, without anyone approving the data that goes into them.

The instinct is to ban it. The evidence of every previous shadow IT wave, from personal Dropbox accounts to WhatsApp on site, says a ban does not stop the behaviour. It stops the visibility. The work still flows through the tool, but now nobody will admit it, so nobody can manage it.

The answer is a sanctioned route: approved tools, clear rules about what data goes where, and honest training. This post is the discovery and remediation playbook. The policy argument for that stance is made in controlled adoption, not blanket bans.

Why is your team doing this in the first place?

Because it works. The person pasting a client email into a chatbot is not being reckless; they are getting forty minutes of drafting done in five and going home on time. Shadow AI is a signal that your people have found genuine value before the business has. That is worth knowing, and it should shape the response: you are not stamping out misconduct, you are formalising something your best people already voted for.

It also tells you exactly where to aim an approved tool. The tasks people route around policy for are, by definition, the tasks worth automating properly.

What is the actual risk, without the scaremongering?

Not sci-fi. Contract law and data protection.

If an employee pastes personal data (a client contact's details, a subcontractor dispute, HR notes) into a free consumer chatbot, your firm has disclosed personal data to a third party processor with no processing agreement, no assessment, and in some cases terms that permit the provider to use the content for training. Under UK GDPR you remain the controller and the accountability sits with you. The ICO's guidance for organisations is clear that you need a lawful basis and appropriate safeguards before personal data leaves your control.

The second risk is plain confidentiality: tender pricing, rates, client terms. Not a GDPR matter, but exactly the sort of information leakage the NCSC small business guide tells firms to control deliberately rather than by accident.

Neither risk means the tools are unusable. Both mean the free-personal-account route is the wrong route.

How do you find out what is actually in use?

Not with forensics. With amnesty.

Announce that the firm is choosing approved AI tools, that nobody is in trouble, and that you want to know what people already use and for what. Run it as a short survey or a round of ten-minute conversations. You will learn more in a week than monitoring software would tell you in a year, and you will learn the part monitoring cannot show: which tasks the tools are being used for.

Two supporting checks are worth doing quietly: skim expense claims for AI subscriptions, and ask whoever manages your Microsoft 365 tenancy what third-party apps have been connected. But the amnesty is the main event. If people believe discovery leads to punishment, discovery ends. Permanently.

What does the sanctioned route look like?

Three tiers, matched to data sensitivity. Write them down on one page.

Data going inExamplesSanctioned route
Public or genericDrafting a job advert, explaining a regulation, rewording boilerplateApproved chatbot, business account, any tier
Commercially confidentialTender text, rates, programme detail, client correspondenceBusiness-tier account with training opt-out and data processing agreement in place
Personal or sensitive dataHR matters, disputes, health and safety incidents involving named peoplePrivate deployment only, or not at all

The middle tier is where most of the day-to-day work lives, and it is cheap to fix: business tiers of the mainstream tools contractually exclude your data from training and give you admin control. The top tier is the case for private AI rather than public chatbots, where the model runs under your control and the data never leaves it.

The one-page rule sheet matters more than the tooling. People follow rules they can remember at 4pm on a Thursday.

How do you make the sanctioned route stick?

By making it better than the shadow route, and by training people honestly.

Better means: the approved tool is paid for, faster to access than a personal login, and connected to the documents people actually work with. If the sanctioned route is worse than the free chatbot, the free chatbot wins, policy or not.

Honest training means telling people what the tools are genuinely good at, where they fail, and why the data rules exist, rather than an hour of compliance theatre. Sceptical teams respond to being levelled with; there is a whole approach to this in training sceptical construction teams. The rule of thumb: if your training session does not include the phrase "here is where it gets things wrong", it is not training, it is advertising.

Review the setup quarterly. New tools appear, people change roles, and shadow AI regrows wherever the sanctioned route falls behind.

This is work AI Metric does for firms regularly: discovery, the rule sheet, the tooling, and the training, usually inside a month. But most of it a director can start on Monday with a survey and a page of rules. The firms that get hurt by shadow AI are not the ones using it. They are the ones who do not know they are.

AI Metric is a construction-native AI consultancy. If your team is spending more time operating software than doing their job, get in touch or book a call.