ARTICLES

Shadow AI: Is Your Team Already Using It Without You Knowing?

Abstract geometric graphic with the Teasl wordmark representing shadow AI and workplace AI governance

It's a Tuesday afternoon. The marketing lead at a small accountancy practice has a client newsletter due by end of day. She knows what needs to go in it, she just doesn't have time to write it from scratch. So she opens ChatGPT, pastes in some notes, and has a decent draft in ten minutes.

She hasn't told anyone. She isn't trying to get away with anything. She's just trying to get through her afternoon.

Now think about how many people in your business are probably doing some version of this right now.

Most small business owners assume AI adoption is something they'll get round to, when they've found the right tool, run a session for the team, written some guidance. What they often haven't clocked is that their team has usually already started without them.

Surveys keep finding the same thing: a large share of employees use AI tools at work on their own initiative, often without telling anyone, and a fair number say they'd keep it that way even if asked. This isn't people trying to cut corners. They're trying to get their work done, and AI helps. The issue is that they're doing it without any shared sense of what's sensible, what's risky, and what actually produces good results.

What counts as "shadow AI" in a small business?

Shadow AI just means AI tools being used outside any agreed approach, the same idea as someone using their personal Dropbox because the work system is too slow.

For a small business, that matters because of what's involved. Client information. Financial figures. Things that, if they ended up somewhere they shouldn't, would be your problem to sort out and your reputation on the line.

If someone pastes a client brief or a set of figures into a tool the business hasn't thought about, the real question isn't whether it saved time. It's where that information went, and who's responsible if it causes a problem.

Under UK GDPR, the business is responsible for how personal data gets handled, including by tools staff are using on their own. "I didn't know they were doing that" doesn't help much with the ICO.

Why banning it usually backfires

The instinctive response, once an owner realises this is happening, is often to lock it down. Block the tools. Send an email saying AI isn't to be used.

It rarely works the way people hope.

The marketing lead still has a newsletter to write. She'll just do it on her phone at lunchtime instead, somewhere nobody can see what she's doing or step in if something goes wrong. The time saving stays. The risk doesn't go away, it just gets harder to see, because now it's happening somewhere you can't support it or step in if something goes wrong.

The people doing this aren't the problem. They've spotted something useful and started using it, which is exactly the instinct you'd want in a team. What they're missing is guidance and a bit of training, the things that would make it safe as well as useful.

So the better question isn't how to stop it. It's how to get ahead of it.

What getting ahead of it actually involves

This doesn't take a big project. A few things make the real difference.

Start by finding out what's already happening. A short conversation with your team will usually tell you more than you'd expect, who's using what, and for which jobs.

From there, write something short. A page, maybe two, covering what's fine, what needs a bit of care, and what's off-limits. A clear page people will actually read beats a long policy nobody opens.

And then build the capability properly. There's a real difference between "you're allowed to use AI" and showing people how to use something like Claude well, in a way that protects client information, keeps the quality up, and doesn't lead to people trusting the output more than they should.

Why this is worth getting right

It's easy to read all this as a warning, and the risks are real. But the more useful way to think about it isn't "how do we manage the danger", it's "how do we make sure our people get the benefit of this properly".

A team that's had a bit of training, has clear guidance, and uses AI consistently will get through more work, with more reliable quality, and free up time for the things that actually need a person's judgement. That's worth having, and it's available to any small business willing to put a bit of structure around it.

Where to start

If you're not sure where your business stands, ask yourself one question: do you actually know how your team is using AI right now?

If the honest answer is "not really", that's fine, it's just information. It tells you the problem isn't a missing policy or a tool you haven't bought yet. It's that nobody's had a proper look at what's already happening. Once you have that picture, the guidance and the training tend to follow naturally, and that's really what good AI training is for.