Square One
← GROUNDWORK · PAPER 03 · MAY 2026

Shadow AI is a symptom, not a crime.

Your best people are already using AI in personal accounts, because it helps them do their jobs. The risk isn’t their initiative. It’s that none of that work can be stood behind.

Ask around your organisation and you will find it: the estimator who drafts tender responses in a personal ChatGPT account, the engineer who pastes a specification into Claude to check her reasoning, the coordinator who asks Copilot to tidy a client email. None of them is being reckless. They found a tool that removes blank pages and speeds up hard thinking, and they used it, the same instinct you hire for.

This is what “shadow AI” actually is. Not a security breach in progress. Not misconduct. It’s capable people routing around the fact that the organisation hasn’t given this kind of work an approved place to happen. Blaming them misreads the problem, and bans don’t work, because the tools are free, private and genuinely useful. Prohibition just pushes the work further out of sight.

Where the risk actually sits

The real exposure is quieter than the headlines suggest, and it has little to do with any particular model. When work happens in personal accounts, four things go missing at once:

Evidence. An output arrives with no record of what it was based on. If a client, an auditor or a court later asks “where did this figure come from?”, there is no answer, only a memory of a chat session that no longer exists.

Permissions. Your Microsoft 365 tenancy spent years encoding who may see what. A paste into a personal tool steps around all of it in one keystroke (commercial terms, client data, employee details), not maliciously, just invisibly.

Approval. Content flows into documents that carry your letterhead without anyone having consciously decided it should. The judgement step that makes work yours simply never happens.

Memory. Whatever was learned in that session (the good prompt, the correction, the refined reasoning) evaporates when the tab closes. The organisation pays for the work twice and keeps neither copy.

Why bans make it worse

A policy memo that says “don’t” changes none of the incentives that created the behaviour. The work is still due Friday. The tool still helps. The only thing a ban reliably achieves is honesty leaving the room: usage continues, but nobody mentions it, so the organisation loses even its rough picture of where AI is touching its work. The condition, ungoverned work, gets darker, not smaller.

The organisations handling this well have made the opposite move. They’ve concluded that if their people find AI useful, the answer is to give that work a governed place: AI over the organisation’s own evidence, inside its own permissions, behind a policy gate, approved providers, for approved tasks, at a known cost, logged. The better tool is the sanctioned one, so the shadow version simply stops being worth the friction.

You don’t fix shadow AI by policing people. You fix it by making the governed path the easiest one.

That is the test for any response to shadow AI: does it make the sanctioned way better than the workaround? A governed environment that answers from evidence people are entitled to see, keeps what it learns, and leaves a record anyone can stand behind isn’t a restriction on your staff’s initiative. It’s the first time that initiative has been allowed to compound, on the record, where it belongs.

THE FULL GUIDE
Shadow AI: the definitive guide →
GROUNDWORK · PAPER 03 · MAY 2026Talk to us →
SQUARE ONE IS A PRODUCT OF INHOUSE CX© 2026 INHOUSE CX