AI Tools Academy
0 / 117 (0%)

AI for managers

Shadow AI at work: what it is and what managers can do

About 14 minutesPractises: Data judgement, Human responsibility

Written by AI Tools AcademyChecked against the sources listed below on 27 September 2026

Helpful first: How to manage a team that uses AI · Privacy and safety

Nobody at Fernway set out to break a rule. Alex tried a tool that looked useful, and it kept running. That is what shadow AI usually looks like: ordinary people solving ordinary problems with tools their organisation doesn't know about.

This guide explains what shadow AI is, why it happens, and what a manager can do about it, including what to do when something sensitive has already gone into the wrong tool. Your organisation's policy and approved tools still take priority over anything here.

What shadow AI means

"Shadow AI" means AI tools used for work that the organisation hasn't approved, or doesn't know are being used. It borrows from the older term "shadow IT", which covers any unapproved software or service used for work.

It can look like:

  • a personal ChatGPT, Claude or Gemini account used to draft work emails
  • an AI note-taker or transcription bot joining meetings
  • a browser extension that rewrites or summarises whatever is on screen
  • a phone app used to photograph and summarise a document
  • an AI feature switched on inside software the team already uses, without anyone checking what it does with data

Not every organisation has shadow AI, and not every unapproved tool is a problem. Using a free chatbot to suggest a better word for "synergy" is very different from pasting in a customer's account history. The concern is the combination of an unapproved tool and work information.

Why it happens

In most cases people use unapproved AI tools for reasons a manager would recognise.

The tool is useful. Someone found that AI drafts a first version of a routine letter in seconds. They are trying to do their job well.

Approval is slow. If asking for a new tool means a form, a queue and a decision in three months, people who need help this week will find their own route.

There is no approved alternative. If the organisation hasn't provided any AI tool, the only options are personal accounts or nothing.

Nobody said it wasn't allowed. Many teams have no rules at all. People fill the gap with their own judgement, which may be good or may not.

People don't know it counts. An AI summary button inside an email app, or a note-taker that came bundled with video calling software, may not feel like "using AI" at all.

None of these makes the risk go away. They do tell you where to look for the fix.

Why a blanket ban can make things worse

The instinctive response is to ban everything. That can feel safe, and a short pause while you agree rules is reasonable. A permanent ban with no approved alternative has a known weakness: people who found the tools useful may carry on using them, on their phones or at home, and stop mentioning it.

Then you have the same risk with less visibility. Nobody asks whether it's OK to paste in a customer email, because asking would admit they were doing it. Nobody reports a slip. You lose the chance to teach good habits, and you find out about problems late, if at all.

Is it happening in your team?

Don't assume. Some teams have no unapproved use at all, and treating everyone as a suspect damages trust. Some signs that are worth a friendly question:

  • work that suddenly reads very differently in style or structure
  • unfamiliar bots or attendees in meeting invitations
  • people mentioning a tool by name that isn't on your approved list
  • requests to IT for browser extensions or app installs
  • staff asking "is it OK if I..." questions about AI, which tells you they're thinking about it

The simplest way to find out is to ask, in a way that makes an honest answer safe.

The "tell us what you use" approach

Some organisations run what is sometimes called an amnesty: a set period in which staff are invited to say which AI tools they use for work and what for, on the understanding that telling you is the goal and nobody gets into trouble for it. It works best when it is short, specific and followed by visible action.

Before you start, agree with HR exactly what you are promising. "No disciplinary action for past use disclosed during this period" is a clear promise. Only make it if you can keep it. If something disclosed turns out to need reporting as a data incident, you will still need to report it. Say that honestly up front: the incident gets handled, the person doesn't get blamed for telling you.

Show a sample message Priya sent to her team

Subject: Which AI tools are you using? (No trouble, genuinely)

Hi all,

AI tools are becoming part of how a lot of people work, and I'd rather we used them well than pretended they weren't there. Over the next two weeks, please let me know which AI tools you use for work, including personal accounts, apps, browser extensions and meeting note-takers, and roughly what you use them for.

Nobody is in trouble for anything they tell me. The point is to find out what's useful, get us proper approved tools where we can, and agree some sensible rules.

One exception to be upfront about: if you think customer or staff information may have gone into a tool it shouldn't, I'll need to pass that to our data protection contact so the company can check whether anything needs doing. That's about handling the information properly. It's not about blame, and telling me quickly is the right thing to do.

You can reply to me directly or use the anonymous form linked below if you prefer.

Thanks, Priya

Offer an anonymous route as well as a named one. Some people will only tell you what they use if their name isn't attached.

What to do with the answers

Sort what you hear into three groups:

  • Keep: tools and uses that fit your rules, or would with an approved account. Look at making them official.
  • Replace: useful uses in the wrong tool. Move them to an approved tool, or ask IT whether one can be approved.
  • Stop: uses that carry too much risk for the benefit, such as a note-taker recording customer calls without the customer knowing. Explain why and help the person find another way to get the same benefit.

Then tell the team what you found, in general terms, and what is changing. If people tell you what they use and hear nothing back, they won't tell you next time.

At Fernway, the answers included the note-taking bot, two people drafting emails in personal chatbot accounts, and one person using a phone app to summarise supplier price lists. Priya and Ravi removed the bot's calendar access, confirmed the team could use Microsoft 365 Copilot Chat with their work accounts, and wrote a one-line rule about meeting recording tools needing IT approval.

Practical governance that people will follow

Governance means the rules and routines that decide which tools are used and how. For a team, it doesn't need to be elaborate.

Keep a short list of approved tools, with the account type for each (work or personal) and what each is approved for. Put it somewhere everyone can find it.

Make asking easy and quick. A named person, a short form and a promised response time. "Ravi will reply within a week" does more than a policy that says "all software requires approval".

Check AI features in software you already use. Many products now include AI features. Ask IT which ones are switched on, and what they do with your information.

Name an owner for the list and the rules, and review them at a set interval.

Say what's allowed, as well as what isn't. A list of approved uses gives people a safe route. A list of bans alone gives them only a boundary to test.

Approved alternatives

The strongest way to reduce shadow AI is to offer something better. If your organisation uses Microsoft 365, staff signed in with work accounts may already have Copilot Chat, which applies enterprise data protection under your organisation's Microsoft 365 terms. OpenAI states that it does not use content from ChatGPT Business or Enterprise workspaces to train its models by default. Google Workspace and Anthropic offer business versions with separate terms too.

These business versions are not automatically safe for everything. They still need rules about what goes in, and someone still needs to check what comes out. They do give you a tool you can see, set up and support.

If there is no budget for an approved tool, say so, and give clear guidance on what can be done with free tools and what can't. The AI-Safe Desk course explains the difference between consumer, business and internal tools in plain English.

Awareness and training

People make better choices when they understand why a rule exists. A short session covering these points goes a long way:

  • what happens to text pasted into a consumer AI tool
  • which information is fine, which needs an approved tool, and which never goes in
  • how to spot an AI feature inside another app
  • who to ask, and what to do after a mistake

The Can I put this in ChatGPT? tool is a quick way for staff to check a specific case, and the free privacy and safety lesson covers the basics.

If someone has already pasted something sensitive

This is the moment that tests whether your team trusts you. If someone tells you they pasted customer details, staff information or anything confidential into an unapproved tool, how you respond decides whether the next person tells you at all.

Step 1: Thank them and stay calm

Say thank you for telling you. The fact that they reported it is the behaviour you want. Deal with how it happened later, and separately.

Step 2: Get the facts while they're fresh

Write down what information went in (as precisely as possible, without copying it again), which tool, which account (personal or work, free or paid), roughly when, and whether any settings such as chat history or training were on. Ask whether the output was used or sent anywhere.

Step 3: Tell your data protection contact

Report it to your data protection officer, information governance lead or whoever your organisation names for data incidents, straight away. They decide whether it counts as a personal data breach and whether it needs reporting. The ICO says an organisation must report a notifiable breach to the ICO without undue delay, and no later than 72 hours after the organisation becomes aware of it. That clock is one reason speed matters. Whether a particular incident is notifiable is their decision, not yours.

Step 4: Follow their instructions on the chat itself

Don't rush to delete things before you've spoken to them. They may want details first. Deleting a chat may not remove every copy the provider holds, so deleting it is not the end of the matter.

Step 5: Fix the cause

Once the immediate issue is handled, ask why it happened. Was there no approved tool? Was the rule unclear? Did the person not realise the information was sensitive? Fix that, and share the lesson with the team without naming anyone.

Show a good and a poor manager response

Grace Lynch, Fernway's Finance Assistant, tells Dan Okafor that she pasted a list of overdue customer accounts, including contact names and amounts, into a personal chatbot to get a chaser email drafted.

A poor response: "You did what? You know we don't do that. I'll have to report this." Grace leaves the conversation embarrassed. The next time something similar happens, she is less likely to say anything.

A good response: "Thanks for telling me straight away, that's exactly the right thing to do. Can you tell me which tool and which account it was, roughly when, and whether the chat history setting was on? Don't delete anything yet. I'm going to pass this to our data protection contact now so they can look at it. Later this week let's look at how you can get the chaser drafted in Copilot with your work account, without the customer details."

The second response gets the facts, starts the clock on the right process, and gives Grace a better way to do the job next time.

Mistakes to avoid

Treating a report as a confession. People who report problems are protecting the organisation. Treat them that way.

Assuming a business tool makes any input fine. An approved tool changes what happens to the data. It doesn't change whether the information should be shared for that purpose.

Announcing rules with no approved option. "Don't use AI" without an alternative leaves people choosing between their workload and your rules.

Forgetting the AI you already own. Features inside existing software can be the largest source of unnoticed AI use.

This guide is not legal advice. Your organisation's policy, data protection officer or legal adviser decides what applies in your situation.

Questions people ask

Is using a personal AI account for work against the law?
Not in itself. The risk depends on what information goes in and what the tool does with it. Putting personal data into a tool your organisation hasn't approved can create data protection problems. Your data protection officer or adviser decides what applies in your case.
If we offer an amnesty, can we still take action later?
Be clear about this before you start. An amnesty that is followed by disciplinary action will not be trusted twice. If your organisation cannot promise no action in any circumstances, say exactly what the amnesty covers and agree the wording with HR first.
Someone pasted customer data into a personal chatbot and then deleted the chat. Is that the end of it?
Not necessarily. Deleting a chat may not remove every copy the provider holds, and your organisation may still need to assess the incident. Report it to your data protection contact with the details and let them decide the next steps.

Sources and further reading

This page explains good practice in plain English. It is not legal advice. Your organisation's policy and approved tools take priority.

Rolling this out to a team?

We run practical, remote training for teams on safe, useful AI at work, using fictional practice data so nobody has to use real information to learn.

Discuss team training