A prospect sends you a vendor security questionnaire. Question 14: Which third-party AI services process our data, and under what terms? You have thirty minutes to answer, and the honest answer is that you don't know. Your ops lead has been summarizing client contracts in a free chatbot since spring. A contractor built a lead-scoring sheet on top of an API key nobody logged. Someone connected a note-taking bot to the shared calendar, which means it has been sitting in client calls for four months.
That gap between what you can attest to and what is actually happening is shadow AI. It is not a future problem. It is a question you will be asked, in writing, by a customer or an insurer, and the answer is either documented or it isn't.
Understanding Shadow AI
Most coverage of this topic treats it as a discipline problem: employees are going rogue, so tighten the rules. That framing is wrong and it will cost you good people. Staff reach for these tools because the sanctioned path is slower than the unsanctioned one. When approval takes two weeks and a browser tab takes two seconds, the tab wins every time.
The useful reframe is that shadow AI is a contract and evidence problem wearing a technology costume. You have signed agreements with clients about how their information is handled. You may have an NDA, a data processing addendum, a professional services agreement with a confidentiality clause. Those promises follow the data wherever it goes, including into a text box your team opened on a personal account.
What Shadow AI Actually Is
Shadow AI is any AI tool processing company or client information outside the agreements, accounts, and controls your organization can actually point to. Note what that definition does not say. It says nothing about which model or which brand.
The line that matters is the account tier, not the logo. The same provider often applies materially different data terms depending on how you signed up:
- Business and API tiers. OpenAI states in its enterprise privacy documentation that it does not train on business data by default, that customers own their inputs and outputs where law allows, and that retention is admin-controlled on certain plans.
- Consumer tiers. Terms here move, and they move quickly. In August 2025, Anthropic announced updates to its consumer terms covering Claude Free, Pro, and Max, giving individual users a choice about whether their chats help improve the models. The company noted the changes did not apply to services under its commercial terms, including Claude for Work and API access.
Read those two bullets together and the operational point becomes obvious. Your employee did not choose a model. They chose a contract, on your behalf, without reading it, and that contract can be amended by the provider while your client agreement stays exactly where it was.
The Risks, Ranked by What Actually Bites
Generic risk lists ("data security, compliance, inconsistency") are true and useless. Here is the version an operator can act on, roughly in order of how likely it is to hurt you first.
1. You made a promise you can no longer verify
The most common exposure for a small firm is not a dramatic breach. It is a confidentiality clause you can't substantiate. If your MSA says client materials will not be disclosed to third parties without consent, and a paralegal pasted a deal memo into a personal account, the disclosure already happened. Nobody has to hack anything.
2. Regulators treat privacy promises as enforceable, AI or not
The FTC's Office of Technology has been direct about this. In a January 2024 post, agency staff wrote that model-as-a-service companies failing to abide by privacy commitments to users and customers may be liable under the laws the FTC enforces. A follow-up post warned that adopting more permissive data practices and disclosing them only through a quiet, retroactive amendment to terms of service could be unfair or deceptive. The principle cuts both directions. It applies to the vendors your team is using, and it applies to the privacy page on your own site if that page no longer describes what your business actually does with customer data.
3. The cost data is no longer speculative
IBM and Ponemon Institute's 2025 Cost of a Data Breach study reported that one in five organizations experienced a breach tied to shadow AI, that high levels of shadow AI were associated with roughly $670,000 in higher average breach costs, and that 63% of breached organizations either had no AI governance policy or were still drafting one. Among those that did have a policy, only 34% ran regular audits for unsanctioned AI use. The 2026 edition put the global average breach cost at $4.99 million and found more than 20% of organizations reported a breach targeting AI models or applications. Coverage of the 2026 report by Cybersecurity Dive noted the share of incidents involving shadow AI more than doubled year over year, to 43%.
Read these as directional rather than as your own risk profile. This is survey research on breached organizations, weighted toward larger enterprises, and a ten-person firm is not a bank. The trend line is the signal: the gap between adoption and oversight is widening, not closing.
4. Connected accounts, not chat windows
Pasting text is the visible risk. The larger one is the OAuth grant. A meeting assistant with calendar and drive access, a browser extension with permission to read every page, an automation that holds a long-lived token: these keep working after the employee who authorized them leaves. Standing access outlives the person who granted it.
5. Output nobody checked
Unreviewed output creates a quieter liability. A generated statistic in a proposal, a citation that does not exist in a client memo, a compliance summary that misreads a clause. NIST's Generative AI Profile (NIST AI 600-1) catalogs confabulation and information integrity among the risks unique to or exacerbated by generative systems. When the work is unsanctioned, there is no review step, because there is no acknowledged process to attach one to.
Creating an AI Acceptable Use Policy That People Follow
Most AI policies fail for the same reason most expense policies fail: they list prohibitions without providing a faster permitted route. Build the permitted route first.
NIST's voluntary AI Risk Management Framework organizes this work into four functions: Govern, Map, Measure, and Manage, with governance cutting across the other three. You do not need an enterprise program to borrow the sequence. A one-page policy for a small company should answer five questions in plain language:
- Which accounts are approved. Name the workspace, not the brand. "Our company workspace on X" is enforceable. "ChatGPT is fine" is not, because it does not distinguish a governed tenant from a personal login.
- What never goes in, under any account. Keep this list short enough to memorize. Client PII, credentials and keys, unredacted contracts, anything covered by a specific NDA, anything a regulator would call sensitive.
- What requires a human check before it leaves the building. Anything a client reads, anything with a number in it, anything that makes a factual claim about a person.
- How to request a new tool, and how fast you will answer. Commit to a response window. If approval is slower than the workaround, you have written a policy that trains people to route around you.
- Who owns the decision. One named person. Not a committee, not "IT" at a company with no IT department.
Pair the document with practice. A policy nobody has rehearsed is a document, not a control. Short working sessions where the team redacts a real (sanitized) client brief together will do more than a slide deck. If you want a structured starting point, our learning resources cover the redaction and review habits that make this stick, and the AI consulting practice exists for founders who would rather not write the first draft of a governance framework alone.
How to Find Shadow AI Without Starting a Witch Hunt
You will find more in an afternoon of records review than in a month of surveillance tooling. Work in this order.
- Start with money. Pull twelve months of card statements and expense reimbursements and filter for AI vendors. Subscriptions are the cheapest discovery mechanism you own.
- Audit third-party app access in your identity provider. Google Workspace and Microsoft 365 both list which external applications have been granted access to company accounts, by user and by scope. This is where the connected note-takers, browser extensions, and automation platforms surface. Revoke what is stale.
- Inventory browser extensions on company-managed devices, and check for personal accounts signed into work browser profiles.
- Run an amnesty window. Say plainly that nobody is in trouble, ask what people are using and what problem it solves, and give a two-week window. Announce a penalty phase only after you have given a clean way to comply. The list you get back is also your automation roadmap, because every entry is a task someone found painful enough to solve on their own.
- Re-check quarterly. The 2025 IBM findings suggest most organizations with policies still are not auditing for unsanctioned use. A recurring calendar block costs nothing and closes that gap.
What you learn will point at real bottlenecks. If three people are separately pasting invoices into chat windows to extract line items, that is not a policy violation to punish; it is a business automation project with a demonstrated internal user base. Recurring, high-volume workflows usually belong in something governed and built on business-tier APIs rather than in a chat tab, which is the territory our software work tends to live in.
A Reasonable 30-Day Sequence
Week one: pull the billing records and the OAuth grant list. Week two: open the amnesty window and write the one-page policy while responses come in. Week three: stand up one approved business-tier workspace, migrate the highest-volume use case into it, and revoke dead app grants. Week four: run a 45-minute working session on redaction and review, then set the quarterly recurring audit. Small company, real coverage, no consultants required to start.
Frequently Asked Questions
What should I do if I find unauthorized AI tools being used?
Find out what job the tool was doing before you address the rule. Then take three concrete steps: determine what data actually went in and whether any of it is covered by a client agreement, check whether that account was consumer or business tier because it changes your disclosure position, and give the person a sanctioned path to the same outcome within days. If client-covered information was exposed, review your contractual notification obligations before deciding whether to disclose. That is a call to make with counsel, not from a blog post.
How can I educate my team about approved AI tools?
Teach the boundary, not the buttons. People retain "client PII, credentials, and unredacted contracts never leave the approved workspace" far longer than they retain a feature tour. Run short, recurring sessions with real work rather than one long onboarding. Give one named person the authority to answer "can I use this?" quickly. Peer pressure works better than policy here, which is one reason operators compare notes at our events and inside the Tech Lab Miami community.
Should we just ban AI tools outright?
Bans push usage onto personal devices and personal accounts, which is the worst of both outcomes: the same data exposure, minus your visibility into it. Prohibition works only where you can actually enforce it and where you have removed the underlying need. Neither is usually true.
We are ten people. Is this really our problem?
Your client contracts do not scale with headcount. A single confidentiality clause in a single enterprise MSA can create obligations that a ten-person firm has no infrastructure to meet. Small teams do not need enterprise governance. They need one approved workspace, one short policy, one owner, and one quarterly check.
The goal is not to slow your team down. It is to be able to answer question 14 in writing, without guessing, and to keep the productivity your people already found on their own.
Visuals

