Shadow AI: Governing the Tools Your Team Already Uses
Only 24% of UK firms using or considering AI have controls for it. What unmanaged AI risks in a regulated business, and how to govern it calmly.
Nerdster Team
Your team is using AI. That is not a warning; for most firms it is straightforward good news, and the evidence for the productivity is now reasonably solid. The awkward part is narrower and more specific: in a regulated business, you need to be able to say what happens to your clients’ information, and unmanaged AI use is a gap in that account.
This is a governance problem rather than a behaviour problem, and it has a calm and fairly ordinary solution.
What the evidence says about AI at work
Microsoft’s 2026 Work Trend Index, published on 5 May 2026, surveyed 20,000 workers who use AI across ten markets including the UK, fielded by Edelman Data x Intelligence between 18 February and 20 April 2026, alongside anonymised Microsoft 365 telemetry.
Two findings describe the pull:
- 66% of AI users say AI has allowed them to spend more time on high-value work.
- 58% say they are producing work they could not have produced a year ago.
And one finding describes the gap. The report places each respondent in one of five zones based on individual readiness and organisational readiness. Only 19% sit in the “Frontier” zone, where both are strong. 10% are in “blocked agency” — individuals who have built the skill but whose organisations lack the systems to apply it. Half sit in the emergent middle, and 16% are stalled on both dimensions.
That 10% is worth pausing on, because it is shadow AI described from the inside. These are capable people in organisations that have not yet given them a supported way to work. They do not stop; they route around. The report’s own summary of the pattern is that workers are ready and their organisations are not.
There is also a reassuring finding: 86% of AI users say they treat AI output as a starting point rather than a final answer, and when asked which human skills matter more as AI takes on more work, quality control of AI output topped the list at 50%. The instinct to check is already there. What is usually missing is a requirement that makes it consistent.
How much of this your organisation can actually see
The Cyber Security Breaches Survey 2025/26, published on 30 April 2026 from fieldwork between August and December 2025, added a section on AI for the first time. It found:
- 21% of UK businesses had adopted some AI tools, rising to 39% of medium-sized businesses and 45% of large ones.
- Among organisations using AI, adopting it, or considering it, only 24% had security practices or processes in place to manage the risks. A further 38% planned to put them in place within twelve months, and 31% had no plans to do so at all.
Read those two surveys side by side carefully, because they are asking different questions. The Breaches Survey asks the organisation what it has adopted. The Work Trend Index asks individual AI users about their own experience. Neither measures unsanctioned individual use, and no survey really can.
That is the honest position: no published survey gives a reliable figure for how much AI is running inside any individual firm. Which means the useful response is not to estimate the number but to make the activity visible.
What is actually at risk
For a firm holding client data under professional or regulatory obligations, four things matter, and none of them require an alarming story to be worth fixing.
Data leaving your tenancy
When a document, a client list, a contract or a set of figures is pasted into a public AI service, it is processed on someone else’s infrastructure under someone else’s terms. Whether it is retained, where it is held, and whether it contributes to model training all depend on the specific service and the specific plan — and consumer tiers frequently differ from business ones.
The everyday examples are unremarkable, which is exactly why they happen: a proposal drafted from client names and financial details, a contract summarised, board minutes turned into an action list, a performance note written up, a code snippet pasted with credentials still in it.
The Breaches Survey adds a relevant detail: 14% of UK businesses said they held personal data not protected by techniques such as anonymisation or encryption. Where that is true, the material most likely to be pasted into a chat window is also the material with the least protection around it.
No audit trail
If a client, a regulator or your own insurer asks what was shared with an external service, when, and by whom, an unsanctioned tool has no answer to give. This is often the most consequential gap, because it turns a question that should take an hour into an investigation that cannot conclude.
No retention or deletion control
Data protection obligations do not pause for tools nobody registered. A request to erase personal data, or a retention schedule you have committed to, cannot be honoured in a system that is not on your list. The ICO’s guidance on AI and data protection is a reasonable starting point for working out your own position; note that it is currently under review following changes made by the Data (Use and Access) Act.
Licensing, IP and third-party status
Two separate questions sit here. What do the provider’s terms say about your inputs, your outputs, and the confidentiality of both? And is this arrangement, in substance, a third party processing your data?
For regulated firms the second question now has a deadline attached. The FCA’s Policy Statement PS26/2, published on 18 March 2026, makes operational incident and material third-party reporting mandatory from 18 March 2027, including a register of material third-party arrangements submitted annually — our note on FCA operational resilience covers what that involves. DORA has applied to in-scope EU financial entities since 17 January 2025 and carries a comparable register requirement. Neither asks whether you knew about the arrangement.
One more, from the other direction
AI is also changing the attacks arriving at your firm. IBM’s Cost of a Data Breach Report 2026, published on 29 July 2026, found one in four malicious breaches were AI-enabled, a 56% increase on the previous year, and that these cost an average of $6 million against a global average of $4.99 million — global figures rather than UK ones, and best read as direction of travel. The Breaches Survey’s qualitative interviews found the same concern voiced from the ground up: organisations worried that AI-written phishing, with the spelling and grammar errors removed, is harder for staff to spot.
Giving people a good option before closing the others
The sequence matters more than the components. Provide a supported tool first, then set the rules, then enforce them technically. Done the other way round, the rules land as an obstacle and the enforcement pushes the activity onto personal devices where nothing can see it.
In practice that usually means:
- A capable AI tool inside your own tenancy, so the data stays within the boundary and compliance framework you already run. For most firms on Microsoft that means Microsoft 365 Copilot, with the governance work done properly first — our note on Copilot security and governance covers the permissions tidy-up that needs to happen before rollout, because Copilot surfaces whatever a user can already reach.
- Business or enterprise agreements where a specialist tool is genuinely needed, with the data handling terms read rather than assumed. The differences between consumer and business plans are exactly where the risk sits.
- Support, not just access. The Work Trend Index found that organisational factors — culture, manager support, how AI features in how work is evaluated — account for more than twice the reported impact of individual effort. A licence nobody is helped to use produces very little. Our Microsoft Copilot deployment and adoption support covers what actually moves the needle.
A shadow AI policy short enough to be read
Four sections is usually enough:
- Approved tools — what is sanctioned, and for what kind of work.
- Data classification — what may go into them, and what may not. Be concrete: name the systems and the document types, not just “confidential information”.
- Review requirements — which outputs need a human check before they go anywhere. Client-facing documents, anything with a figure in it, anything going to a regulator.
- Prohibited uses — the short list of things nobody does, such as AI-generated client advice or automated regulatory submissions.
One page that everyone has read beats twenty pages nobody has opened. It should also say who to ask when a new tool looks useful, so the answer to “can I use this?” is a person rather than silence.
Controls that guide rather than only refuse
Policy needs something underneath it:
- Data loss prevention rules that recognise sensitive material heading towards an AI service.
- Application governance across your identity platform, so you can see which third-party services staff have connected to their work accounts and with what permissions. This is often the fastest way to discover what is already in use.
- Network and browser controls that log or restrict unapproved services, wired into a managed detection capability so that anything unexpected gets looked at rather than merely recorded.
Where you can, make the control redirect rather than simply deny. A block that says “use the approved tool for this, here is the link” teaches something. A silent failure teaches people to find another route.
Reviewing it on a schedule
AI tooling changes faster than most policies are revisited, so put a date in the diary: reassess the approved list quarterly, read your DLP and application-governance logs to see what people actually use, ask staff whether the sanctioned tools meet their needs, and update as regulatory guidance develops. The ICO’s own guidance being under review is a fair indication of how much is still moving.
Check where you stand
Seven questions, and the count of noes is the finding:
- Do you have an AI acceptable use policy, and has everyone actually read it?
- Do you provide sanctioned AI tools that genuinely meet your team’s needs?
- Can you see which external AI services are connected to your work accounts?
- Would your DLP controls notice sensitive material heading for an AI tool?
- Has your team had any practical training on using AI safely?
- Is one named person or team responsible for AI governance?
- Do you review the approach on a schedule?
More than two noes and this is worth a morning of someone’s time this quarter.
Getting it in place
We help London firms put practical AI governance in place: working out what is already in use, deploying Microsoft 365 Copilot with the Microsoft 365 governance work done first, writing a policy people will follow, and putting the DLP and application-governance controls behind it.
If that would be useful, book a conversation. We will map what AI activity is visible in your tenancy today, set out where the data protection and third-party gaps are, and give you a governance framework sized to how your firm actually works.