Field Notes

07

Shadow AI is the new shadow IT

Your team is already using AI. The only question is whether you know how, and right now most owners do not.

A decade ago this was shadow IT. Staff signed up for their own file-sharing and messaging tools because the official ones were slow or missing. IT departments lost track of where company data lived. Shadow AI is the same pattern with sharper edges. Your people are pasting customer emails, contracts, pricing, and half-finished strategy into free chatbots to get their work done faster. They are not being reckless. They are being resourceful. But it is happening in the dark.

Here is why owners miss it. AI use does not show up on an invoice. There is no licence to approve, no kit to order. Someone opens a browser tab and gets on with it. So the official position becomes “we are still working out our AI policy” while the unofficial reality is that half the team has been using it daily for months. The gap between the policy and the practice is where the risk sits.

And the risk is real, but it is not the one people panic about. The headline fear is data leaking into a model. That matters, especially with client confidentiality, and it is worth a clear rule. But the quieter risk is bigger. Nobody knows which decisions were shaped by a chatbot. A quote, a contract clause, a customer reply, a hiring note, all touched by a tool with no record of what it was asked or what it got wrong. The work looks normal. You just cannot trace how it was made.

I saw a services firm where a junior had been drafting all the client update emails through a free tool. The emails were fine, mostly. Then one went out with a confident, completely invented figure in it, because the tool had filled a gap and nobody checked. The client noticed before the firm did. The problem was not the tool. The problem was that its use was invisible, so no check existed around it.

The sharper way to think about this is to stop treating shadow AI as a thing to ban and start treating it as a thing to surface. You cannot ban it. You will just push it further into the dark and lose the chance to make it safe. People use it because it helps. Banning a thing that helps only teaches them to hide it better.

So bring it into the light. Ask the team, with no blame attached, what they are already using and for what. You will be surprised, usually pleasantly, and occasionally alarmed. Then put two simple things in place. A clear line on what must never go into an outside tool, in plain language, not legalese. And a habit of checking AI-assisted work before it leaves the building, especially anything with a number or a promise in it.

The practical takeaway. This week, ask your team one honest question. What AI tools are you using to get your job done. Promise no telling-off, because you need the truth more than you need to look in control. Whatever you learn, you are now ahead of where you were, which was assuming the answer was nothing. Shadow AI is not a future problem to plan for. It is a present reality to manage, and the first move is simply finding out what is already going on.