Square One
GUIDE · SHADOW AI

Shadow AI: what it is, the risks, and how to fix it

Shadow AI is your staff using AI tools such as ChatGPT, Claude and Copilot in personal or unsanctioned accounts to do their jobs, outside the organisation’s governance, evidence and permissions. It is not a discipline problem. It is a signal that capable people have found AI useful and the organisation has not yet given them a governed place to use it. The fix is not a ban; it is a better path.

IN SHORT
  • Shadow AI is work done through AI accounts the organisation does not control, own, or see.
  • It happens because the tools are genuinely useful and the sanctioned alternative is slower, worse, or absent. The behaviour is rational, not reckless.
  • The risk is not that AI was used. It is that four things go missing: evidence, permissions, approval, and memory.
  • Bans backfire: they push the same behaviour further out of sight and remove your last chance to see it.
  • The durable fix is to make the governed path the easiest one, so the shortcut stops being worth taking.

What shadow AI is

Shadow AI borrows its name from “shadow IT”, the long-standing pattern of staff adopting software the IT department never sanctioned: a personal Dropbox for files that would not fit through email, a Trello board a team spun up on their own. Shadow AI is the same instinct applied to a new class of tool. An estimator pastes a scope of works into ChatGPT to draft a first-pass proposal. A coordinator asks Claude to summarise a long email chain. A manager uses Copilot in a personal account to rewrite a board paper. None of it appears in any register. None of it was approved. Most of it is invisible to leadership.

The defining feature is not the tool but the boundary it crosses. When AI is used inside a governed environment, the organisation can see what evidence the output rested on, whether the person was entitled to that evidence, who approved the result, and what happened afterwards. Shadow AI removes all of that. The work still gets done, often well, but it is done in a place the organisation cannot reach, cannot check, and cannot defend.

It is worth being precise: shadow AI is not any use of AI. It is ungoverned use. The same estimator drafting the same proposal inside a sanctioned, permission-aware environment is not doing shadow AI. The tool is not the issue. The absence of governance around it is.

Why it happens (rational, not reckless)

It is tempting to read shadow AI as a workforce cutting corners. That reading is both wrong and unhelpful, because it points at the wrong fix. People reach for personal AI accounts for straightforward reasons:

  • the tool genuinely makes a hard task faster or a blank page less daunting
  • the organisation has offered no sanctioned alternative, or a worse one
  • the sanctioned tool is slower, more locked down, or does not reach the material they actually need
  • getting something approved feels like more work than doing the task itself
  • everyone around them is already doing it, so it reads as normal

Notice that every one of these is a rational response to the incentives in front of the person. Your most motivated, most capable staff are usually the ones furthest out in front, precisely because they are trying to do good work quickly. Punishing that instinct treats a symptom as a crime. The honest read is the more uncomfortable one: shadow AI is what happens when demand for a capability outruns the organisation’s supply of a governed way to meet it. The people are not the problem. The gap is.

The real risks: four things that go missing

The danger of shadow AI is not abstract, and it is not mainly about the AI being wrong. It is about what the ungoverned setting strips away. Four things go missing, and each one is a real exposure.

  1. Evidence. Output from a personal chatbot has no defensible source. It reads as confident and finished, but nobody can say what any particular sentence rests on. When a client, an auditor, an insurer or a court asks “what is this based on?”, there is no answer, only a plausible-looking document and a browser tab that has since been cleared.
  2. Permissions. When someone pastes company material into a personal account, the organisation’s access controls stop applying. Commercially sensitive or confidential information leaves the perimeter and lands in a tool governed by someone else’s terms. Worse, the material a person pastes may reach further than their own entitlement, quietly mixing things they were never meant to combine.
  3. Approval. Shadow AI produces work that skips the deliberate human check that should stand between a draft and a decision. A generated figure or clause can flow straight into a proposal, a report or an email with no one having consciously signed off on it, because there was no gate for it to pass through.
  4. Memory. Work done in a personal account is work the organisation never keeps. The reasoning, the sources, the version history, the fact that the task was done at all, none of it becomes organisational memory. It leaves with the browser session, and it leaves with the person when they resign.

Put together, these describe an organisation quietly producing work it cannot trace, cannot bound, cannot vouch for, and cannot retain. The volume matters too. A chatbot can generate in minutes what once took days, which means ungoverned work now accumulates at machine speed. The risk is not one bad answer. It is the steady build-up of output nobody can stand behind.

Why bans backfire

The instinct of a cautious leadership team is to prohibit personal AI use and move on. It is an understandable reflex, and it almost never works. A ban does not remove the demand that created shadow AI; it removes your visibility of it. The estimator who found ChatGPT genuinely useful does not stop finding it useful because a policy said so. They keep using it, on a phone, on a home laptop, more quietly. The behaviour moves further into the shadows, which is the one direction that makes it harder to govern, not easier.

Bans also carry a cost that is easy to miss: they concede the productivity to competitors who found a safer answer. If capable people have decided a tool helps them do their job, telling them to stop simply asks them to work more slowly than the market. The organisation ends up with the worst of both outcomes, no governance and no gains. A prohibition is a policy document standing in for an operating decision. It signals disapproval; it does not change behaviour. The lesson from decades of shadow IT is the same one here: you do not police your way out of a capability gap, you close it.

How to audit your exposure

Before fixing shadow AI you need an honest picture of it, and the honest picture is usually larger than leadership expects. The aim of an audit is not to catch people; framed that way it guarantees people go quiet. The aim is to understand where governed work is missing so you can supply it. Run through these five questions with your teams, and make it safe to answer them truthfully.

The Shadow AI self-audit

  1. Which tasks are people already using AI for, and in whose accounts? Ask openly, without penalty, and expect the real answer to surprise you.
  2. What company information is leaving the perimeter to get those tasks done, and how sensitive is it?
  3. For work produced with AI in the last month, could you show what each output was based on, and reach that evidence?
  4. Did everyone who used the material have permission to see everything it drew on?
  5. If that work were challenged a year from now, is there any record of who made it, what it rested on, and who approved it?

Every uncomfortable answer is not a mark against your staff. It is a map of where the organisation has not yet given work a governed home. Treat the findings as demand you now know how to meet.

How to fix it: make the governed path the easiest one

Shadow AI ends when the sanctioned way to work becomes the path of least resistance. If the governed tool is as fast and as capable as the personal chatbot, and it reaches the material people actually need, the shortcut stops being worth taking. Nobody detours around the easiest route. The work, then, is to build that route:

  • Provide a genuinely good governed alternative. It has to be at least as useful as what people already reach for. A locked-down tool that cannot do the job simply guarantees the workaround continues.
  • Keep AI inside the perimeter you already own. Build on the environment that already holds your identity, permissions and files, principally Microsoft 365, so access is inherited rather than reinvented and material never has to leave to be useful.
  • Ground the output in evidence. Answers and documents should draw on your own records and stay linked to their sources, so what comes out is traceable rather than merely plausible.
  • Put a policy gate around the AI. Every AI request runs permission-aware, metered and logged, so leadership can see usage and trust it, without slowing the person down.
  • Keep the memory. Because the work happens inside the organisation, the reasoning, sources and approvals stay on an append-only record. The knowledge is retained by the organisation, not carried out the door in a browser tab.

This is the practical shape of governed work: automation and business rules carry the repeatable tasks, and AI is used where reasoning genuinely adds value, always inside the governed environment. Fixing shadow AI is not a separate project from adopting AI well. It is the same project, seen from the staff’s side of the desk.

What this looks like with Square One

Square One is an operating platform built to be that easier, governed path. It builds on the Microsoft 365 ground an organisation already owns, inheriting identity, permissions and files rather than working around them, so nobody has to paste sensitive material into a personal account to get value from AI. Inside that perimeter, generation is evidence-grounded with per-sentence source traceability, every AI request runs behind a policy gate that keeps it permission-aware, metered and logged, and the work is kept on an append-only record. Square One is model-agnostic: it uses the right model for each task and holds the governance constant as models change.

The most direct answer to shadow AI is a governed place to ask anything: AI over your organisation’s own knowledge, permission-aware, so the questions people currently take to a personal chatbot have a sanctioned home, the answers stay inside the perimeter, and the judgement of experienced people is retained rather than leaked. When the governed path is genuinely the easiest one, shadow AI stops being a policy fight and becomes a solved problem.

Frequently asked questions

What is shadow AI?

Shadow AI is staff using AI tools such as ChatGPT, Claude or Copilot in personal or unsanctioned accounts to do their work, outside the organisation’s governance, evidence and permissions. The defining feature is not the tool but that the use is ungoverned.

Is shadow AI a security problem or a people problem?

Neither, at root. It is a supply problem. Capable people found AI useful and the organisation had not yet given them a governed way to use it. Treating it as staff misconduct points at the wrong fix and usually makes the behaviour quieter, not rarer.

What are the main risks of shadow AI?

Four things go missing: evidence (output with no defensible source), permissions (sensitive material leaving the perimeter), approval (work skipping a deliberate human check), and memory (work the organisation never keeps). The risk is not one wrong answer but a steady build-up of output nobody can stand behind.

Should we just ban ChatGPT and personal AI accounts?

A ban rarely works. It removes your visibility of the behaviour without removing the demand that created it, so the use moves further out of sight, and it concedes the productivity to competitors who found a safer answer. The durable fix is a better governed path, not a prohibition.

How do we find out how much shadow AI is happening?

Run an honest, no-penalty audit. Ask which tasks people already use AI for and in whose accounts, what information is leaving the perimeter, and whether recent AI-assisted work can be traced to its evidence, checked against permissions, and shown to have been approved. Our Shadow AI self-audit sets out five questions to start with.

How do we stop shadow AI for good?

Make the governed path the easiest one. Provide an AI tool at least as useful as the personal chatbot, keep it inside the perimeter you already own, ground its output in your own evidence, put a policy gate around it, and keep the memory. When the sanctioned route is the fastest route, the shortcut stops being worth taking.

Is all use of AI at work shadow AI?

No. Shadow AI is specifically ungoverned use, in accounts the organisation does not control or see. The same task done inside a sanctioned, permission-aware, evidence-grounded environment is not shadow AI. The tool is not the issue; the absence of governance around it is.

Does fixing shadow AI mean replacing Microsoft 365?

No. The stronger approach builds on the environment you already run, inheriting your existing identity and permission structures rather than creating a parallel, uncontrolled layer. See our guide to AI governance on Microsoft 365.

Related reading

Give shadow AI a governed home. See the easier, safer path running on the work your organisation already does.

Talk to us
SQUARE ONE IS A PRODUCT OF INHOUSE CX© 2026 INHOUSE CX