Shadow AI is the use of personal or unapproved AI accounts for work, outside any company oversight. It typically looks like staff pasting client data into a personal ChatGPT or Claude login because no sanctioned tool exists. The risk is not the technology but the absence of a record: no audit trail, no data boundary, and no way to answer a regulator asking where the information went.
Why it matters for a UK business
It is almost certainly already happening in your business. In most organisations of 15 to 200 people the first governance conversation starts with the discovery that staff have been using personal AI accounts for months, and that nobody can say what went into them.
What it looks like in practice
A sales lead pastes a client contract into a free ChatGPT account to summarise it. A finance assistant drops a payroll export into a personal login to tidy the formatting. Neither is malicious. Both are a data breach waiting for someone to notice, and neither leaves a record.
What to do about it
Bans move the behaviour rather than stopping it. The fix is a sanctioned tool with a data boundary, a short written policy that says what may and may not go in, and an amnesty for what has already happened so people tell you the truth.
Related terms
Read next
Shadow AI: the hidden risk in your business → · All 22 terms in the glossary · The resource library
If this is the term that has come up in your business and you want it worked through against your own situation rather than in the abstract, that is a conversation, not a page.
Speak to ChrisWritten by Chris Duffy. Last reviewed .