Your employees may already be using AI at work.
They may use ChatGPT to rewrite an email, Claude to analyse a document, an AI meeting assistant to record a discussion or another AI tool to prepare reports, presentations or summaries.
The company may never have approved any of them.
IT may not know they are being used. Compliance may not know what information is being uploaded. Management may not know which AI tools have access to company data.
Nothing may have gone wrong yet.
But there is already a name for the problem:
Shadow AI.
And cybersecurity authorities are starting to pay attention.
What Is Shadow AI?
The NCSC describes Shadow AI as AI technology being used outside an organisation’s approved systems and processes. It is essentially a new form of shadow IT.
This can be as simple as an employee opening a personal AI account and using it to perform a work task.
The employee may not be trying to bypass company security.
They may simply be trying to work faster.
But the moment company or customer information is entered into an AI service that the organisation has never assessed or approved, the organisation may lose visibility over where that information is going and how it is being handled.
Research cited by the NCSC found that 71% of employees reported using AI tools that had not been approved by their employer.
That suggests Shadow AI is not a hypothetical future problem.
It may already be inside the workplace.
We Already Know Employees Are Using AI
We previously discussed this in “Everyone at Work Uses ChatGPT. So What’s the Problem?”
Employees are already using generative AI to draft, research, summarise, translate, analyse and communicate.
Shadow AI takes that discussion one step further.
Does the company know what AI they are using?
And, more importantly:
Does the company know what information employees are giving it?
Those are very different questions.
A company may officially say that it has not “adopted AI” while dozens of employees are already using AI services individually.
From a governance perspective, AI has entered the organisation whether management formally adopted it or not.
Why Does Shadow AI Happen?
It is tempting to treat Shadow AI as employee misconduct.
But that may be too simplistic.
The NCSC points out that organisational policies and guidance have not always developed at the same speed as employees’ adoption of AI.
Imagine an employee who spends two hours summarising documents every week.
They discover that an AI tool can do it in two minutes.
There is no company AI policy.
Nobody has told them which AI tools are approved.
There is no internal alternative.
Nobody has explained what information can or cannot be uploaded.
So they use the tool that works.
Multiply that across marketing, HR, finance, sales, legal, procurement and management and Shadow AI can spread throughout an organisation without any formal decision ever being made to introduce AI.
This is why Shadow AI is not only a technology problem.
It can also reveal a governance gap.
Canada Is Talking About Shadow AI Too
The UK is not alone.
Canadian Centre for Cyber Security has also expressly addressed Shadow AI in its Top 10 Artificial Intelligence Security Actions. (Canadian Centre for Cyber Security)
Its recommendations go beyond simply warning employees to be careful.
Canadian organisations are advised to identify sanctioned and unsanctioned AI models operating on their networks, implement policies and processes to govern Shadow AI, establish internal acceptable-use policies and maintain allow and deny lists for AI solutions.
The Canadian guidance also recommends controls relating to personal information in prompts, data loss prevention, access controls, retention, vendor transparency, audit rights and restrictions on the use of organisational data for model training.
The message from both countries is therefore moving in a similar direction:
Know what AI is being used. Know what information is entering it. Put controls around it.
That is important.
Because it moves the discussion away from simply asking whether an individual employee made a mistake.
It raises another question:
What did the organisation put in place to manage the risk?
“We Never Approved ChatGPT” Is Not an AI Governance Framework
Suppose an employee uploads a confidential document into an unapproved AI service.
The immediate response may be:
“Why did the employee do that?”
That may be a valid question.
But there are others.
Did the organisation tell employees which AI tools were approved?
Did it explain what information could not be uploaded?
Was there an AI acceptable-use policy?
Were employees trained?
Was there a process for approving new AI tools?
Was anyone responsible for monitoring AI use?
Could an employee report an accidental disclosure without fearing that the safest option was to keep quiet?
If none of these existed, the problem may not stop with the employee.
There may also be an organisational governance failure.
As we discussed in “Governance and Compliance: Most SMEs Are Already Doing It (They Just Don’t Know It),” AI governance does not necessarily require an enormous compliance department.
For many businesses, it begins with knowing what technology is being used, deciding who is responsible and setting basic rules around acceptable use.
What Is the Cybersecurity Risk?
Shadow AI creates an unusual cybersecurity problem because an attacker does not necessarily have to break into the organisation for information to leave it.
An employee may voluntarily transfer information outside the organisation by entering it into an external AI service.
That information could include customer data, contracts, employee information, internal emails, financial information, source code, business strategies, intellectual property or confidential documents.
The NCSC warns that Shadow AI can increase the risks of data breaches, intellectual property loss and regulatory failures.
It also warns that organisations may lose visibility and control over information transferred into consumer AI services because information could be stored, retained or used outside established security and governance arrangements, depending on the service and privacy controls involved.
This changes the traditional cybersecurity conversation.
A company can have strong passwords, antivirus software, firewalls and access controls.
But those measures alone do not answer the question:
What happens when an authorised employee copies protected information into an unapproved AI system?
Cybersecurity and AI governance increasingly overlap.
Shadow AI Is Becoming More Powerful
There is another reason this issue deserves attention.
AI is moving beyond simple chatbots.
AI agents can potentially interact with files, applications, databases and other systems and perform tasks with increasing levels of autonomy.
The NCSC warns that AI agents may contain security vulnerabilities and that successful exploitation could give an attacker access to the same data, services and privileges available to the agent.
The consequences of unmanaged AI therefore become more significant as AI receives greater access to business systems.
A chatbot used to rewrite an email is one level of risk.
An unapproved AI agent connected to company systems is another.
And AI Can Still Be Wrong
Cybersecurity is not the only concern.
In “AI Sounds Smart. That Doesn’t Mean It’s Right,” we discussed another fundamental problem: convincing AI output is not necessarily accurate AI output.
Now combine that problem with Shadow AI.
An employee uses an AI tool that nobody approved.
The organisation does not know the tool is being used.
The employee relies on its output.
The output is wrong.
It then influences a report, customer communication, contract, business recommendation or management decision.
Who is responsible?
That brings us back to another issue we previously explored in “Everyone Talks About AI Productivity. Almost Nobody Talks About AI Accountability.“
AI can improve productivity.
But accountability does not automatically transfer from the human to the machine.
Should Companies Just Ban AI?
Not necessarily.
The NCSC expressly says it is not recommending that individuals stop using AI.
For organisations, it says the objective should be to reduce Shadow AI risk rather than assume it can be completely eliminated.
That distinction matters.
If employees are using AI because it solves a genuine business problem, simply banning it may not remove the need.
It may only make employees less willing to disclose that they are using it.
A company could then move from having visible AI use to invisible AI use.
That may be worse.
The better approach is to understand why employees want particular tools, assess whether appropriate alternatives can be approved and create an environment where employees can discuss AI use openly.
From Shadow AI to Managed AI
So what should a business actually do?
It does not necessarily need a hundred-page AI manual.
It needs visibility and basic controls.
The organisation should know which AI tools employees are using and why. It should decide which tools are approved, what information may be entered into them, what information is prohibited, when human review is required and who has authority to approve new AI services.
It should also consider what happens when something goes wrong.
If an employee accidentally uploads confidential information, who should they tell?
If a department wants a new AI tool, who assesses it?
If an AI vendor changes its terms or data practices, who reviews them?
If AI-generated content causes an error, who remains accountable?
These are not purely IT questions.
They involve management, cybersecurity, privacy, compliance, HR, legal and operational responsibility.
This is why our earlier discussions on ChatGPT compliance risk, AI workplace communication policies and governance practical guidance for SMEs ultimately lead to the same point.
AI governance is becoming part of ordinary business governance.
You Cannot Manage AI You Do Not Know Exists
Perhaps the most important sentence in the NCSC’s Shadow AI warning is also the simplest:
“You cannot manage what you do not know.”
That captures the problem perfectly.
The biggest AI risk inside an organisation may not be the expensive AI system management formally approved.
It may be the free AI account an employee opened six months ago and now uses every day.
Governments and cybersecurity authorities are beginning to recognise that reality.
The UK’s NCSC is warning organisations about Shadow AI.
Canada’s Cyber Centre is recommending specific controls to govern it.
The EU’s cybersecurity agency ENISA is separately increasing its focus on AI cybersecurity and the security and privacy challenges created by AI technologies. (European Union Agency for Cybersecurity)
The direction is becoming increasingly clear.
Businesses do not need to stop using AI.
But ignoring how AI is being used is no longer a sensible governance strategy.
Does Your Business Know What AI Its Employees Are Using?
If the answer is no, the first step does not have to be complicated.
Find out.
Then establish reasonable rules around what is approved, what information can be shared, when human review is required and who is responsible.
LexMesos Solutions supports SMEs with practical AI governance and compliance frameworks designed around real workplace use rather than unnecessarily complicated systems.
Our AI Governance & Compliance Toolkit provides businesses with a practical starting point for putting internal AI controls in place.
Because the problem with Shadow AI is not simply that employees are using AI.
It is that the organisation may have no idea what is happening in the shadows.
Keywords: Shadow AI, workplace AI, AI cybersecurity, AI governance, AI compliance, unapproved AI tools, ChatGPT at work, employee AI use, data security, confidential information, AI risk management, Shadow IT, generative AI, AI acceptable use policy, SME cybersecurity, workplace compliance
This article is for general informational purposes only and does not constitute legal advice.
10 September 2026

