Shadow AI: The AI Tools Your Team Is Already Using
Your staff are probably using AI tools you have never approved. Here is how to find out what is leaving your business, and what to do about it calmly.
Step 1. What Shadow AI Is, And Why It Happens
Shadow AI is any AI tool your staff use that you have never approved. It happens in almost every business, and it usually starts with good intentions.
Your staff are not being malicious. They are trying to work faster. Someone discovered that a free AI tool saves them an hour a day, so they use it. Nobody asked permission because nobody thought to ask. This is normal human behaviour, not a security failure.
The problem is what travels with that convenience. When a contract, a customer list, or a spreadsheet of payment details gets pasted into a free AI tool, that data has left your building. You may never get it back.
The guiding principle here is simple. You cannot manage what you do not know about. So the first job is not to ban anything. It is to find out what is actually happening.
Step 2. The Data That Must Never Go Into A Public AI Tool
Some information should never be typed into a public AI tool. Not as a rule to memorise, but as a clear line everyone can see.
- •Customer names with contact details
- •Payment card or bank details
- •Health information
- •Staff HR records
- •Contracts under negotiation
- •Passwords and API keys
- •Unpublished financial figures
- •Anything covered by a client confidentiality agreement
The reason is straightforward. Consumer AI tools may use what you paste to train future models. Once data is inside a model's training data it cannot be reliably removed, by you or by anyone else.
Write this list down and put it where staff can see it. A list on the wall is worth more than a policy in a drawer.
Step 3. How To Find Out What Is Actually Being Used
You do not need to spy on anyone. A few non-invasive checks will usually give you the full picture.
- 1.Ask your team in a non-punitive way. Explain that you want to make their tools safe, not ban them. People tell the truth when the truth is safe to tell.
- 2.Check your internet router or firewall logs for AI service domains, if you have access. Look for names such as ChatGPT, Claude, Gemini and Copilot.
- 3.Check your company card and expense records for AI subscriptions. A monthly charge of a few pounds is easy to miss and very revealing.
- 4.Look at the browser extensions installed on company machines. Extensions often have far more access than anyone realises.
The goal is to build a list, not to catch anyone. Approach it that way and people will help you.
Step 4. Write A One-Page AI Policy Staff Will Actually Follow
A policy only works if it is read. Keep it to one page and keep it plain. A simple structure looks like this.
- •Which AI tools are approved, named clearly
- •What data is never allowed in AI tools, copied from your list in Step 2
- •What to do if unsure. The answer is always ask first
- •That AI output must be checked by a human before it is used with a customer
Now the trap. A policy that bans everything gets ignored. Worse, it drives usage underground where you cannot see it at all. A policy that gives one clear approved path gets followed, because people want to do the right thing when the right thing is easy.
Step 5. Choose The Safer Option: Business AI Accounts
There is a real difference between a consumer free tier and a business or enterprise account. It is worth understanding before you choose.
Consumer free tiers often train on your data. Business or enterprise tiers usually do not, and they add admin controls, audit logs and data retention settings that a free account simply does not have.
When you set one up, look for a setting about improving or training the model. Turn it off. Then confirm it stayed off.
This is usually a paid upgrade. It is also often cheap compared to a data breach, an unhappy client, or a regulatory conversation you would rather not have.
Step 6. Turn Off The AI Features You Never Asked For
Modern operating systems and apps add AI features by default. Most people never switch them on because they were never asked.
- •On Windows, check the Copilot and Recall settings
- •On macOS, check Apple Intelligence
- •In Microsoft 365 and Google Workspace, check whether AI assistants are enabled and what they can reach
The principle is the same every time. Find the setting. Read what it can access. Switch it off if you did not ask for it.
Five minutes in each place is usually enough, and it removes a whole category of quiet data exposure.
Step 7. A Quarterly 15-Minute AI Hygiene Review
Shadow AI is not a problem you solve once. It is a habit you keep. Fifteen minutes a quarter is enough.
- 1.Ask the team what tools they are using now. It changes, so ask again.
- 2.Check that the approved tools are still the right ones for the work
- 3.Check for new AI features switched on by updates
- 4.Review whether any sensitive data has been shared, and how it happened
- 5.Update the policy if anything has changed
Put it in the calendar. This is a standing habit, not a one-off task, and it is far easier to maintain than to restart.
Tips
- •Shadow AI discovered is better than shadow AI hidden. You can only fix what you can see.
- •Always give staff one approved, good tool rather than banning everything. A ban just moves the problem somewhere darker.
- •The question "what data is in this?" takes two seconds and prevents most incidents.
- •If in doubt, the answer is a local model running on your own machine. Nothing leaves the building.
- •Train your team once, briefly, and they will self-police. People generally want to do the right thing.
- •The AI policy should fit on one page or it will not be read.
Need More Help?
StarCaller Academy offers 1-to-1 sessions to help you with any of these topics and more.