22nd July 2025 / AI Business Advice
Imagine one of your team, let’s call her Sarah, is up against a tight deadline. She’s juggling reports, client emails, and a presentation due at the end of the day. So, she turns to ChatGPT to draft that tricky email, uses its image generation for a quick graphic, and asks an AI tool to analyse some sales data. The work is completed in half the time and Sarah’s productivity has hit new highs. Sounds impressive, doesn’t it? Well no, not if Sarah has just shared sensitive company information with tools no one in IT has approved.
This is Shadow AI in action and chances are, Sarah’s not alone. BBC Worklife recently revealed staff across UK firms are ‘smuggling AI into work to beat deadlines’[8]. It’s happening across businesses everywhere, often unnoticed. So, what does this really mean for someone running a business?
Think of Shadow AI like its older cousin, shadow IT, when staff use unapproved software or tools without running it past the IT team. The difference though is that Shadow AI isn’t someone downloading a rogue app. It’s employees using AI tools like ChatGPT, DALL·E, or DeepSeek to make their workday easier. They could be drafting emails, crunching numbers, whipping up presentations, all without making it known they’re using AI in their workflow [1].
Now, before you start picturing rebellious employees, let’s lower the temperature. Most aren’t trying to be sneaky. They’re just trying to get their work done quicker and in a smarter way. With more pressure than ever, who can blame them? The problem is, the potential to copy and paste sensitive information into these AI tools and in doing so, unintentionally hand over confidential company data [1].
That ‘confidential information’ isn’t just commercial secrets, it can include Personally Identifiable Information [PII] like customer emails, phone numbers or NHS numbers which is a direct GDPR red flag.
It’s easy to assume this is something only technology teams dabble in, but Shadow AI pops up everywhere:
These all sound harmless and even appear smart. But without proper oversight, they open the door to data leaks, compliance breaches, and inconsistent quality.
Secret Cyborgs is a term that experts are using to describe employees who are quietly supercharging their productivity with AI behind the scenes [5]. It sounds amazing when you hear the term supercharging productivity, the thing every business wants from its staff. However, do you realise your employees may be unknowingly risking data security every time they ask an AI to “tidy up this client proposal” or “analyse that sales data?”
The extent of stealth adoption shows up in the numbers below:
Microsoft believes that 75% of knowledge workers are already using AI tools at work, mostly without IT or security teams knowing a thing about it [1]. In some companies, over half the staff are secretly using AI, according to Marie-Laure Denis from the National Commission on Informatics and Liberty [2].
But here’s the most worrying thing, research by CybSafe shows 93% of employees using AI have shared confidential information. Even more alarming than that, 38% admitted they’ve shared things they wouldn’t even tell a friend in a bar [6]. Yet only 60% of managers worry their executive team still has no AI roadmap, widening this blind spot [9].
You might be thinking, “We’ve dealt with shadow IT before, how bad can this be?” Well, Shadow AI ups the stakes. Unlike basic software, AI tools process data in ways that aren’t always clear. Where’s your data going? Who’s got access? Is it being stored, or worse, used to train future AI models? If you don’t know the answers, you have a problem [4].
Steve Grossenbacher from Zscaler puts it perfectly, “The reality is this: shadow AI isn’t malevolence; it’s ingenuity unchecked. Employees often take these risks unconsciously, failing to factor in the consequences of their actions. This rising spontaneity needs a controlled, proactive IT response, not blanket block rules that alienate users” [3].
And if you’re in sectors like finance or healthcare, where data rules are strict (GDPR), using unapproved AI could mean serious fines, reputational damage, and many other headaches, such as:
Many of these AI tools are cloud-based. No installs. No obvious red flags. Your team could be using them daily, and unless you’re monitoring internet usage, you won’t spot it through traditional monitoring. That and the constant development and availability of new AI tools.
Banning AI altogether? That’s just asking for more shadow use. As Bernard Marr says, “Shadow AI is often proof you’ve got a forward-thinking team, the trick is keeping that innovation safe” [7].
Here’s a simple plan. Remember, this isn’t about shutting down progress. It’s about guiding it:
Shadow AI isn’t going anywhere. As AI becomes part of everyday software, spotting unsanctioned use will only get harder. The smartest move may be to embrace AI but set clear boundaries.
Your ‘secret cyborgs’ aren’t trying to cause trouble; they’re just making life easier. Help them do it safely.
Get the right policies in place, offer secure tools, and keep the conversation open. AI is already here, better to work with it than pretend you can block it.
[1]: https://www.upguard.com/blog/unmasking-shadow-ai
[3]: https://www.zscaler.com/blogs/product-insights/shadow-ai-growing-threat-corporate-data-security
[4]: https://www.teamviewer.com/en/insights/difference-between-shadow-ai-and-shadow-it/
[5]: https://techpolicy.press/secret-cyborgs-and-their-ai-shadows-navigating-the-copilot-pcs-frontier
[8]: https://www.bbc.co.uk/news/articles/cn7rx05xg2go
[9]: https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part