Shadow AI: What UK Businesses Need to Know and Do

Illustration of practical fractional leadership playbooks and guides
Shadow AI in UK businesses — illustration of an IT director reviewing unapproved AI tool alerts on a security dashboard

TL;DR

Shadow AI is the use of AI tools at work that the business has not approved, secured or even noticed, such as staff pasting customer data into a free chatbot. It is already widespread in UK firms and creates real data protection, security and quality risks. Banning it rarely works; the practical answer is to find out what is being used, provide approved tools that meet the need, and set a short, clear policy owned by a senior leader.

Last updated: 5 October 2026

Shadow AI is probably happening in your business today. Microsoft research found that 71% of UK employees have used unapproved consumer AI tools at work, and 51% still do so every week. Most are not being reckless. They are trying to write a proposal faster, summarise a contract or tidy a spreadsheet, and the free tool on their phone is quicker than waiting for IT.

The problem is what goes into those tools. Customer names, pricing, board papers, HR cases and source code are all being pasted into services the business has no contract with, no visibility of and no control over. For an MD or IT director, that is a governance gap that sits squarely with the board.

This guide explains what shadow AI is, why it matters, and a proportionate way for a scale-up to bring it under control without killing the productivity gains staff are clearly finding.

What is shadow AI?

Shadow AI is the AI equivalent of shadow IT: technology used for work without the knowledge or approval of the people responsible for security and data. It covers consumer chatbots used on personal accounts, AI features quietly switched on inside existing software, browser extensions that read every page, and staff connecting AI tools to company email or file storage.

What makes shadow AI different from older shadow IT is the data flow. A spreadsheet stored in a personal cloud account is a risk; a prompt that sends a customer list to an AI service may be retained, used for training or reviewed by the provider, depending on its terms. Once it has gone, you cannot get it back.

The legal position is clear. The Information Commissioner's Office has said that data protection law applies to the processing of personal data whether it is intentional or incidental, and that common practice does not mean people's expectations are being met. If staff put personal data into an unapproved AI tool, your business is still the controller.

The risks of shadow AI for UK businesses

The risks are practical rather than theoretical:

  • Data leakage — confidential customer, financial or HR information shared with providers you have no contract with.
  • UK GDPR exposure — personal data processed without a lawful basis, transparency or a data processing agreement.
  • Security weaknesses — AI browser extensions and integrations with broad access to email, files and systems.
  • Inaccurate output — AI-written advice, figures or contract wording used without checking, creating liability.
  • Intellectual property — your own know-how or code fed into third-party models, and unclear ownership of what comes back.
  • Client contract breaches — many clients now restrict how suppliers use AI on their data.
  • Lost value — good ideas stay with individuals instead of becoming shared, approved ways of working.

How to bring shadow AI under control

Start by finding out what is really happening, without blame. A short anonymous staff survey asking which AI tools people use and for what usually produces more honest answers than a network scan alone. Combine it with what your IT team or provider can see: sign-ins to AI services, browser extensions and AI features enabled in existing software.

Then meet the need properly. If people are using chatbots to draft documents, give them an approved business tool with proper data terms, such as an enterprise AI assistant tied to your existing Microsoft or Google licences. Publish a one-page policy that says what can and cannot be shared, which tools are approved and who to ask. Make checking AI output mandatory for anything sent to clients.

The National Cyber Security Centre's guidance for boards on AI and cyber security is a good, non-technical starting point for the leadership conversation. If you trade with the EU, our EU AI Act guide for UK SMEs explains the extra obligations, and our board guide to cyber risk assessment shows where AI fits into your wider risk register.

Picture a 150-person professional services firm that discovers, through a quick survey, that most of its fee-earners use free chatbots to summarise client documents. Rather than banning them, it rolls out an approved assistant within its existing licences, blocks the riskiest browser extensions, publishes a one-page policy and runs a 45-minute briefing. Within a month, usage has moved to the approved tool and the firm can answer client due-diligence questions about AI with confidence.

Who should own shadow AI, and how to choose help

Shadow AI is not just an IT problem, because the decisions involved are about risk appetite, client commitments and how the business wants to work. It needs a senior owner who can bring IT, HR, legal and operations together and report to the board. In larger firms that is a CIO, CISO or data and AI director; in many scale-ups, nobody holds that role.

When choosing help, look for experience of both AI adoption and information security, a proportionate approach rather than a list of bans, familiarity with UK GDPR and your sector's client requirements, and a fixed scope with no long-term tie-in. Our AI consultancy service and the fractional CISOs on our bench can run a shadow AI review and put the policy and approved tools in place in weeks.

Frequently asked questions

Is shadow AI illegal?
Using an unapproved AI tool is not illegal in itself, but what goes into it can be. Sharing personal data without a lawful basis, transparency or a contract with the provider can breach UK GDPR, and sharing client information can breach confidentiality terms. The business, not just the employee, carries that risk.
Should we just ban AI tools at work?
Outright bans rarely work, because staff use AI on personal devices and the productivity benefits are real. A better approach is to approve suitable tools, set clear rules on what data can be used, and make it easy to request new tools. That reduces risk while keeping the gains.
How do we find out what AI tools staff are using?
Combine an anonymous survey with technical evidence. Ask staff which tools they use and why, then check sign-ins to AI services, browser extensions and AI features switched on in existing software. Framing it as a fact-finding exercise rather than an investigation gets far more honest answers.
What should an AI acceptable use policy include?
Keep it to one or two pages: the approved tools, what data must never be entered (personal, client-confidential and commercially sensitive information), the requirement to check AI output before use, how to request a new tool, and who to contact with questions. Review it every six months as tools change.
Who in the business should be responsible for shadow AI?
A named senior leader, usually the IT director, CIO or CISO, supported by HR and whoever owns data protection. If you do not have that role in-house, a part-time technology or security leader can own the policy, approved tools and board reporting for a few days a month.

Ready to bring shadow AI under control?

Leadership Services gives UK scale-ups access to a bench of 500+ senior directors, including CIOs, CISOs and data and AI leaders who can run a shadow AI review and put sensible controls in place quickly. Engagements start from £1,795 per month, begin within one week and have no long-term tie-ins — get in touch and we will respond the same working day.

Want to talk through this for your business?

A 15-minute discovery call is often more valuable than any article we could write.