Shadow AI: Your Team Is Already Using ChatGPT. Here Is How to Handle It.
Banning it does not stop it, it just stops you hearing about it. How to find out what your team is actually using, and how to make it safe without killing the benefit.

The average small business now uses a median of five AI tools. The number their leadership could name is usually lower.
This is shadow AI: staff using tools nobody approved, on personal accounts, with company information, because the tool was there and the work needed doing. It is not a discipline problem. It is what happens when people are given targets and no guidance, and it is nearly universal.
This article is part of our guide to AI training for UK businesses.
Why banning does not work
A ban does not stop the behaviour. It stops you hearing about it.
The person still has a deadline, still has a phone, and now has a reason not to mention what they did. You have converted a visible risk you could manage into an invisible one you cannot, and you have lost the ability to tell them which tool would be safe.
There is a second cost. The people most likely to adopt these tools are usually the ones getting the most done, and telling them the answer is no is a good way to lose them to somebody whose answer is different.
What is actually at risk
Three things, in order of how often they bite.
Confidential information leaving. The big one. Client data, unpublished figures, HR matters, anything under an NDA, pasted into a consumer tool whose terms may permit retention and training. This is the most common real AI incident in UK businesses by a distance.
Wrong output going out unchecked. Under time pressure, with fluent output, verification is the first thing to go. The consequence is a client receiving an invented figure with your name on it.
Work you cannot account for. If a decision was shaped by a tool nobody knew about, you cannot explain how you reached it. That matters for anything touching individuals, and it matters in any regulated context. See AI regulation in the UK..
Find out what is actually happening
Before deciding anything, find out. This takes a week and the method matters more than the tooling.
Ask, in a way that makes honesty safe. Say plainly that you are not looking to discipline anyone, that you assume people have been using these tools because the work needed doing, and that you want to make it safe rather than stop it. Then ask what they use and what for. You will get most of the picture, and the parts you do not get tell you something about how the question landed.
Check expenses. Personal subscriptions to AI tools frequently appear on expense claims, which is a useful and unambiguous signal.
Look at what your existing tools have added. Half the shadow AI in a business arrived inside software it already pays for, switched on by an update nobody read.
What you should not do is start with network monitoring. It finds less than the conversation does, and it poisons the conversation you will need to have afterwards.
What to do with what you find
Approve something good, quickly. The single most effective action. Pick one or two tools, buy the business tier where training on your data is off by default, and give people access this month. Most shadow AI disappears when a sanctioned option exists that is not worse than the unsanctioned one.
Write the short list of what must never go in, and put it in your AI use policy. Not "confidential information", which means nothing to a person in a hurry. Specific categories: named client data, unpublished financials, anything from HR, anything covered by an NDA, source code. Five lines, on one page.
Explain the difference between tiers. Most people have genuinely no idea that a business account behaves differently from the free one they use at home. This one fact, explained once, prevents a large proportion of incidents.
Make reporting a near-miss normal. If someone realises they pasted something they should not have, you want to know within the hour, not never. That requires the first such report to be met with thanks rather than a process.
Then train. In that order. Training before approving tools produces enthusiasm with nowhere to go, which is how this started.
The uncomfortable bit
If a good deal of shadow AI has appeared in your business, it usually means the official tools are not good enough or the official answer took too long.
That is worth sitting with before deciding the problem is the staff. Shadow AI is a symptom, and the underlying condition is normally that people were asked to do more with the same time and found a way. Handled well, you get a faster team and a manageable risk. Handled as a compliance matter, you get the same behaviour with less visibility.
Key Takeaways
- Shadow AI is near-universal. The median small business uses around five AI tools and leadership can usually name fewer.
- Banning does not stop the behaviour, it stops you hearing about it, and it turns a manageable risk into an invisible one.
- Ask before monitoring. A conversation framed as making it safe finds more than network tooling does and preserves the relationship you need next.
- Approve one or two good tools on business tiers within the month. Most shadow use disappears when a sanctioned option exists.
- Replace "no confidential information" with five specific categories. Vague rules do not survive contact with a deadline.
Frequently Asked Questions
Is using ChatGPT with client data actually a breach?
It depends on the tier, the terms, your lawful basis and what you told the client. Under UK GDPR, putting personal data into a third-party tool is processing, and it needs a basis, transparency and appropriate safeguards. The consumer tier of most tools is a considerably weaker position than the business tier. Treat it as a real question rather than assuming either way.
How do we handle someone who has already done this?
Establish what went in and whether it is recoverable, tell the client if the situation warrants it, and fix the underlying cause. Disciplining the first person who admits to it guarantees they are the last person who admits to it, which is the worst possible outcome.
What if we cannot afford business tiers for everyone?
Buy them for the people handling sensitive information, and be explicit that everyone else must not put anything from the restricted list into a tool. Partial coverage plus a clear rule is a far better position than a blanket ban that nobody follows.
Want to find out what your team is actually using, and make it safe? Talk to Halo Technology Lab. Our support and training service starts with that conversation, not with monitoring software.
Enjoyed this? Get the next one by email
Practical AI playbooks, build logs and tool teardowns. One email a week, free, unsubscribe in one click.
Related Articles
How to Measure Whether AI Training Actually Worked
Attendance and satisfaction scores tell you nothing. Four measures that do, how to capture a baseline before you start, and what a realistic return looks like.
Training a Team That Thinks AI Is Coming for Their Job
Resistance is usually a reasonable response to a badly handled rollout. How to run AI training when people are worried, and why pretending nothing will change makes it worse.
Workshop, Programme or Course? Choosing the Right Shape of AI Training
A half-day workshop, an ongoing programme and a self-serve course solve different problems. What each is good at, what each costs, and how to tell which one your team needs.