Shadow AI: The AI Your Firm Already Uses (That You've Never Seen)

Shadow AI is work done with AI tools the firm hasn't approved or can't see. Ask how the last client deliverable was made, then check its sources, conclusions and client-data sharing.

An open desk drawer holds a tablet below a closed document with a red clip.
A finished deliverable does not tell you which tools were used to make it.

Your firm can be using AI in client work even if you've never bought a tool, announced a rollout or approved a policy.

Someone can draft an email in a personal ChatGPT account, paste a spreadsheet into Gemini or ask Claude to review a contract, then bring the answer back into the work without telling you how it was made.

That is shadow AI, employees using AI tools without the employer's knowledge, approval or oversight. The risk for a service firm is that it can change the work you bill for while the people responsible for its quality don't know the process has changed.

I wouldn't assume this is happening in every seat in your company. But I also wouldn't accept “we haven't adopted AI” as proof that none of your client work is passing through it, because that answer usually describes what management approved, not everything people do.

The term comes from shadow IT, software and systems people use outside the approved setup. The concerns overlap, especially around access and client data, but AI also gives you something that can go straight into a deliverable, an analysis, a recommendation or a number that looks as though somebody checked it.

So you need to ask about the output as well as the account. Knowing which tools are installed doesn't tell you which one helped write the proposal that left on Thursday.

There is evidence that the company view and the employee view can be very different, but I want to be careful with the numbers because they measure different things.

In its May 2026 report, JPMorganChase Institute tracked payments to AI services through the end of 2025. It found adoption on that payment measure at 10.3 percent for Baby Boomer-owned businesses and 22.1 percent for Millennial-owned businesses.

That is a difference in purchasing behavior among the businesses it studied. It doesn't tell us how much free AI their employees used, whether a manager approved each use or whether the owner's age caused the difference.

And Microsoft's 2024 Work Trend Index reported that 78 percent of AI users brought their own AI tools to work. That is among people already using AI, not 78 percent of all workers, and bringing your own tool doesn't automatically mean the employer forbids it or doesn't know.

You can't subtract those figures to calculate how much AI is hidden in your firm. They come from different samples, years and questions, one measures business payments and the other asks AI-using knowledge workers about their tools.

What they give you is a reason to look beyond the tools the company paid for. My operating concern is that the official plan can move at the owner's pace while people doing the work find other ways to get help, and a subscription list won't show you all of those ways.

Some use is hidden deliberately. Employment Hero's July 2026 account of its AI Paradox survey says 42 percent of Gen Z respondents used AI without their employer's knowledge, and the same share presented AI-generated work as their own.

The study surveyed workers and business leaders across the UK, Australia, Canada and New Zealand, not the United States. So I wouldn't turn that into a claim that close to half of your youngest hires are hiding something, but it is evidence that concealment happens, even where employers say they want AI skills.

And there can be a cost to admitting it. Reif, Larrick and Soll's 2025 PNAS paper found that people described as receiving AI help were judged lazier and less competent than people receiving human help or no help.

In its hiring experiment, the manager's own AI use mattered, managers who rarely used it favored the candidate who didn't use it, while frequent users favored the AI-using candidate. These are experimental findings about judgment, not proof of what every manager in your firm thinks.

But they make it easier to understand why someone might hesitate to tell you. If using AI is praised as a company priority and treated as taking a shortcut when an employee does it, the employee has to work out which message you actually mean.

I don't think you fix that by calling the team dishonest and stopping there. You still need clear rules, but you also need to make it possible for people to tell you what they've used and what went wrong without feeling that the admission itself is the mistake.

Otherwise the same silence that hides a useful shortcut can hide a bad result. Someone who didn't tell you which tool helped with the first report may be even less willing to explain why the second report needs correcting.

I've seen five kinds of problems in unsanctioned AI output through delivery across a franchise network, and I want to stay with them for a moment because checking only for a data leak misses most of the work.

One is inconsistent style and angle across the same deliverable. Different people use different tools and instructions, and the report comes back sounding as though several separate arguments have been joined together without anyone deciding what the firm is trying to say.

That doesn't prove AI was involved, human teams can produce the same problem. But when AI is involved and there is no shared process, you need an editor who checks the whole thing, not three people who each approve their own section.

Another is a wrong fact stated confidently. A sentence can be easy to read and completely wrong, and the client has no reason to know the fact was generated rather than checked against a source.

So the check has to go back to the source, not just ask whether the sentence sounds reasonable. If the source isn't available, you haven't verified it by reading it twice.

I've also seen the numbers themselves be real while the conclusion drawn from them is wrong. That is a different review job, because checking that the spreadsheet figures were copied correctly doesn't tell you whether the analysis means what the report says it means.

Someone has to understand the business question and the comparison being made. A neat chart can carry the wrong answer just as easily as a paragraph can, and the underlying numbers being genuine can make the mistake harder to notice.

Then there are made-up statistics, numbers that don't appear in the source material at all. I've seen that happen with client financial data, so I don't treat a plausible-looking number as something we can let through because it fits the story.

I don't have a documented client outcome to add to that observation. The risk is clear enough without inventing one, if a client uses an unsupported number in a decision or repeats it elsewhere, the correction has more work to catch up with.

The fifth problem is client information going into a tool that the firm hasn't cleared for that data. Depending on what was shared and the firm's obligations, that can become a trust, security or legal problem, and checking the final report won't show you where the source material went.

A public example shows why the sharing settings matter. On July 28, 2026, the BBC reported that hundreds of Claude conversations could be found through search engines, including some with personal and work information.

Those were conversations users had chosen to share by link, not evidence that ordinary private chats were all public. The BBC also reported that search availability had been removed, while some conversations had already been saved and shared elsewhere.

That distinction doesn't make the risk disappear, it tells you which action created it. A person can think they are sending a useful link to a colleague without understanding that anyone with that link can access the content and that public web content may be copied or indexed.

So your rules need to cover what information may go in and what may be shared afterward. Approving the name of a tool isn't enough if nobody has decided which account, settings and data uses the approval covers.

And please don't aim all of this at the youngest people. Microsoft's bring-your-own figures cover AI users across generations, and older research summarized by NBER in December 2024 found work use across age groups, with lower use among older workers rather than no use.

That's historical adoption evidence, not a current age cutoff you should put into a policy. The senior person whose work gets the least checking can also use AI, so an audit based on birth year misses the person whose judgment you were relying on.

Learning isn't standing still either. Rebecca Perron's June 2026 article in ASA Generations describes a narrowing age gap in LinkedIn Learning participation.

That is a learning-participation measure, not proof that everyone has reached the same skill level. It is another reason I wouldn't wait for a generational change to solve a problem that needs a decision about work today.

The separate question of who benefits most from AI depends on the person and the task. Here, your job is to find out what is already being used and bring the work under a review process the firm can stand behind.

I would start with a conversation, before buying a monitoring product or writing a long policy. Ask what AI tools people already use, which tasks they use them for and what they find useful, and say that you want an accurate picture rather than the answer they think management wants.

You can make room for candor without approving everything you hear. If someone is putting restricted client information into an unsuitable account, that use needs to stop and the work needs a safe route, even while you thank them for telling you.

What I wouldn't do is announce a blanket ban and assume the absence of discussion means the tools disappeared. A ban without a workable alternative can make disclosure harder while leaving the deadline and the need for help unchanged.

Then take a sample of recent client work and walk through it with the people who prepared and reviewed it. Find out which parts used AI, where the source material came from and whether the result was checked against it.

Look for the mixed voice, the unsupported fact, the wrong conclusion from correct numbers and the statistic nobody can trace. Separately, check what client data entered the tool and whether any conversation, file or output was shared beyond the intended people.

Don't treat a clean-looking sample as proof there is no shadow AI. You are checking a piece of work and learning how it was made, not certifying the whole firm from one report.

For the uses you keep, name who owns review and put the data boundary and checking rule somewhere the team can find. A short AI policy can help carry those decisions, but it has to describe the work people actually do.

If nobody in the firm can judge a particular AI output, keep that part of the work manual until someone can. The first useful move this week is to ask how the last client deliverable was made, then check the answer against the work itself.

Topics: