
For months, the front desk at a growing service business had been drowning in reschedules, no-shows, and last-minute cancellations that never made it back onto the calendar. The office manager, understandably tired of chasing sticky notes, found an AI scheduling assistant that could text customers, handle changes, and update the calendar automatically. She signed up with a company card, connected it to the shared inbox, and had it running within a week. IT never heard about it. Neither did leadership. It just worked, and that was the point.
Stories like this play out in businesses of every size, every week. An employee finds a tool that solves a real problem faster than asking for help would and adopts it without a second thought. Multiply that pattern across departments and a business ends up with a growing set of AI tools that leadership never approved, never reviewed, and in a lot of cases doesn’t even know exist.
There’s a decades old term security teams have used for this very practice: Shadow IT. It’s when employees quietly adopt apps and tools without going through the proper channels. This modern version is now being dubbed “Shadow AI” which is the same instinct applied to a far more capable category of tool.
How common this already is

*Source: US Chamber of Commerce Technology Engagement Center
It’s a simple chart but illustrates the point quite effectively. Small business use of generative AI has climbed considerably over the last several years (23% → 40% → 58% from 2023-2025), according to the U.S. Chamber of Commerce’s most recent Empowering Small Business Report. That’s not a slow, early-adopter curve, and it tracks with what shows up in broader workplace data. According to the most recent Verizon Data Breach Investigations Report, 67% of users are leveraging non-corporate accounts to access AI services from their corporate devices. Meaning most AI access currently happens through personal accounts rather than anything the company set up or can see. That second point matters more than the growth number itself. AI use isn’t just increasing. It’s increasing in a place where leadership has no visibility at all.
Now just because an employee is using an unsanctioned AI tool doesn’t automatically mean they’re acting recklessly. Grammarly, Claude, or another AI tool may very well end up on the approved list, but the pattern is the real issue: someone finds a useful tool, implements it to solve a bottleneck, and no one above them ever had a chance to weigh in. When you consider neither leadership nor IT have said a word about AI use in the workplace, why wouldn’t they?
Why leadership should care
An unnamed policy doesn’t mean no policy exists. It means employees are setting the policy themselves, one individual decision at a time, without knowing (or even thinking about) what’s actually at stake.
Consider what that looks like in practice. A hiring manager runs candidate resumes through a free AI tool to speed up screening, without realizing that candidate data, including protected characteristics, is now sitting inside a system nobody vetted for compliance. A salesperson uses a personal AI note-taker on client calls, and those conversations are now stored somewhere the business has no contract with and no control over. An operations lead connects a scheduling tool directly to the customer database because it “just needed access” to work properly.
Each choice might seem reasonable in isolation. Together, they add up to a business that has quietly outsourced a set of real decisions about data handling, vendor risk, and system access to whoever happened to solve their own problem first. If something goes wrong later and a regulator asks where candidate data lives, “we didn’t know that tool was in use” is not a defensible position for leadership.
Questions worth asking
A few honest questions can surface most of this before it becomes a problem:
- Do you know which AI tools your team has adopted without asking IT first?
- If an employee left tomorrow, would you know what company data lives inside tools you don’t manage?
- Does your AI policy name the tools that are approved, or does it only say what’s prohibited?
- Who in your organization would even find out if a new AI tool showed up in a department’s workflow next month?
None of these require a technical background to answer, and none of them require a crackdown. They just require someone to ask.
For IT leaders
Discovering shadow AI doesn’t require a major security program to start. Most organizations already own a starting point: Microsoft 365 and Google Workspace both offer OAuth app-consent review, showing which third-party services employees have already granted access to company data. Browser extension policies can flag meeting-assistant extensions before they quietly collect page content. And for a broader inventory, SaaS and CASB discovery tools can surface AI services already in use across the network, including ones nobody signed up for through any formal purchase. None of this requires banning anything. It requires knowing what’s already there.
Where this leaves leadership
No one wants to stifle employee productivity. And some of the existing, yet unsanctioned AI tools may very well be worth formally adopting. The goal here is to close the gap between what’s actually happening inside the business and what leadership can see. It’s to ensure the decision around which tools are safe to use gets made deliberately and by someone who’s accountable for it, rather than by default.
So to recap, do you know which AI tools your team has already adopted on their own? It’s worth finding out before someone else has to ask you first. This series is working towards an AI Readiness & Security Checklist, and you can bet it includes a section on usage visibility for exactly this reason.
Naming the tools already in use is the first step. The next is knowing what to ask before your organization formally adopts any of them. More to come soon.
Source: This article draws on guidance from the OWASP Top 10 for LLM Applications, 2025 (LLM02: Sensitive Information Disclosure), and on adoption data from the U.S. Chamber of Commerce’s 2025 Empowering Small Business Report and Verizon’s 2026 Data Breach Investigations Report.

Leave a Reply