# Shadow AI: What to Do When Your Staff Are Already Using ChatGPT

Canonical URL: https://business.theaieducator.io/posts/shadow-ai-small-business
Publication: Dan Fitzpatrick Insights
Author: Dan Fitzpatrick
Topic: AI Governance and Risk
Published: 2026-09-25T15:52:44.000Z
Modified: 2026-09-25T16:15:38.925Z

Most staff in small and medium-sized businesses already use AI tools nobody approved. Banning them drives the habit underground. Here is the one-week Daylight Rule for bringing shadow AI into the open: ask first, sort every use into keep, move or stop, and supply an approved home before you forbid anything.

## In brief

When staff are already using AI tools nobody approved, do not ban it or ignore it. Spend one week making it safe to disclose, sort every use into keep, move or stop, and give the uses you keep an approved home before you forbid anything. The UK NCSC's September 2026 advice points the same way.

## Key takeaways

- Shadow AI is any use of AI at work outside the tools and rules the business has approved, and it is the norm rather than the exception.
- In WatchGuard's April 2026 survey of employees at organizations with 50 to 500 staff, 64% said they use unauthorized AI tools for work.
- Okta found 90% of executives confident they could see AI tool use, while 52% of knowledge workers reported using unsanctioned AI tools.
- The danger lies in what goes into the tools: internal emails, HR information and confidential documents top the list of what gets shared.
- The Daylight Rule: make it safe to say what you use before you decide what is allowed. Ask first, sort second, supply third.
- Sort every use into keep, move or stop, and give the Move lane an approved business account before you forbid anything.
- Ask your team what AI has saved them this month, not whether they are using it; curiosity surfaces far more than an audit.

Somewhere in your business this week, someone pasted a client email into a free AI chatbot on their phone and asked it to draft the reply. Nobody approved it. Nobody asked. That is shadow AI, and in most small and medium-sized businesses it is already the everyday way AI gets used.

So what should you do about it? Neither ban it nor ignore it. Spend one week making it safe for people to tell you what they use, sort each use into keep, move or stop, and give the uses you keep an approved home before you forbid anything. The UK's National Cyber Security Centre now gives much the same advice. The risk is real, but the cure is daylight, not discipline.

## What is shadow AI, and how common is it in a small business?

Shadow AI is any use of AI at work that sits outside the tools and rules the business has approved, and in a firm of 20 to 200 people it probably involves most of your staff. The NCSC defines it as “the use of AI technology which isn't captured in an organisation's approved systems and processes” ([NCSC, September 7, 2026](https://www.ncsc.gov.uk/blogs/the-hidden-risks-of-shadow-ai)).

The figures for smaller firms are stark. In April 2026 WatchGuard surveyed 684 employees at organizations with 50 to 500 staff across eight countries, including the US and the UK. Of those, 64% said they use unauthorized AI tools for work, and nearly 40% said their company lacks full visibility into the applications employees use ([WatchGuard, July 14, 2026](https://www.globenewswire.com/news-release/2026/07/14/3326924/0/en/employees-drive-rising-cybersecurity-risk-as-shadow-ai-and-unsafe-work-habits-surge-watchguard-global-survey-finds.html)). These are people admitting to a habit they suspect they should not have, so treat 64% as a floor rather than a ceiling.

The part that should worry an owner is the gap between belief and behavior. Okta's AI Agents at Work 2026 research found that 90% of executives were confident in their organization's visibility into AI tools, while more than half (52%) of knowledge workers reported using unsanctioned AI tools at work ([Okta, May 27, 2026](https://www.okta.com/newsroom/articles/ai-agents-at-work-2026-agentic-enterprise-security/)). If you are certain nobody in your team does this, you are in the 90%.

## Why do staff use AI tools nobody approved?

Most people use unapproved AI because it makes a real part of their job easier and nobody has offered them a better way, not because they enjoy breaking rules. Take a hypothetical 25-person lettings agency. The office manager has 60 tenant emails a day, a free chatbot on her phone that turns a curt note into a polite one in ten seconds, and no company account for anything. She is not a security risk by temperament. She is a busy person with a tool that works.

The NCSC describes where that leads: employees “turn to using AI tools that have not been approved by their organisation, introducing new cyber security risks that can be hard to identify.” Earlier UK research, which I covered in [Does a Small Business Need an AI Policy?](https://business.theaieducator.io/posts/does-a-small-business-need-an-ai-policy), found the two biggest reasons were habit carried over from personal life and the lack of any approved alternative. Neither reason is solved by a warning email. Both are solved by giving people somewhere better to go.

## Is shadow AI actually dangerous for a small business?

Yes, but the danger lies in what goes into the tools, not in the fact that people use them. The NCSC names three risks: sensitive information may be exposed, the organization loses visibility and control of its data, and complex AI software opens new routes for attackers.

Okta's data shows what actually goes in. Of the knowledge workers using unapproved AI tools, the three most-shared kinds of information were internal messages and emails (54%), HR-related information (45%), and confidential company documents (39%). Read that list as a small-business owner: it is your inbox, your staff files and your client contracts.

In the UK, personal data about clients or staff that someone pastes into an unapproved service is still your business's responsibility under data protection law. In the US, the exposure more often runs through client contracts, confidentiality promises and state privacy laws. In both places, the uncomfortable fact is the same: you cannot protect data you do not know has left.

The newer risk is connection rather than copying. An AI assistant that someone has quietly linked to the company email or shared drive can read far more than any single paste. If that is happening in your business, the four questions in [What Do AI Agents Mean for Small Businesses?](https://business.theaieducator.io/posts/ai-agents-for-small-businesses) are the place to start.

## What should you do in the first week? The Daylight Rule

The first week after you discover shadow AI should be spent finding out, not clamping down. I call it the Daylight Rule:

> **The Daylight Rule** is how I suggest a small business responds when it finds staff using AI tools nobody approved: make it safe to say what you use before you decide what is allowed. Ask first, sort second, supply third. Nobody is disciplined for anything they disclose that week, every use is sorted into keep, move or stop, and the business gives the uses it keeps an approved home before it forbids anything.

The order matters. Ban first and people stop telling you, so the shadow gets darker. Sort before you ask and you are sorting guesses. Here is the week, sized for a business without an IT department.

**Monday: say it out loud.** Tell the whole team, in person or on your usual channel, that you know people are using AI, that this is sensible, and that nobody will be in trouble for anything they share this week. Say why you are asking: you want to keep the good uses and make them safe.

**Tuesday and Wednesday: ask three questions.** What AI tools do you use for work, including on your phone? Which jobs do you use them for? What goes into them? A ten-minute conversation or a three-line form both work. Write down the job, not only the tool name.

**Thursday: sort every use into one of three lanes.**

| Lane | What it looks like | What you do |
|---|---|---|
| Keep | No client, staff or financial data goes in, and a person checks the result: tidying the wording of your own email, brainstorming headlines, summarizing a public report | Approve it, write it down as an example of good use, and name the tool |
| Move | A valuable job done in the wrong place: client emails or contracts drafted in a free personal account | Keep the job, move it into a business account with data controls you have checked, and set a date for the switch |
| Stop | Anything that puts staff records, login details or client personal data into an unapproved tool, any AI tool connected to company systems without approval, and any AI deciding something about a person | End it this week, explain why, and offer the approved route if one exists |

**Friday: supply before you forbid.** Choose the approved home for the Move lane, even if that is a single business subscription for the three people who need it most. Then write your Stop list on one page. That page is the first draft of a proper policy: the [One-Page Five](https://business.theaieducator.io/posts/does-a-small-business-need-an-ai-policy) turns it into answers every new starter can read on day one.

The Stop lane is where my governing principle does the work: outsource the doing, not the thinking. Drafting a reply is doing. Deciding whether a tenant, a candidate or a supplier gets a yes is thinking, and it stays with a person.

## The Question to Ask Your Team

The question that brings shadow AI into the open fastest is not “Are you using AI?” but “What has AI saved you this month?” The first sounds like an audit, and audits get silence. The second sounds like curiosity, and the answers arrive with the tool names attached.

When I train business teams, the people who have been using AI quietly are usually relieved to be asked. Whether I am working with a government department or a 20-person firm, the principle I start from is the same. People work around rules they cannot see the point of, and they follow rules they helped shape. My advisory work with the UK Department for Education, KHDA in Dubai and the Ministry of Education in Kazakhstan has only sharpened that view.

A month later, check whether it worked with the Confidence Test. The Confidence Test is three questions I ask a member of staff, not their leader, to find out whether AI confidence exists in an organization: Do you know what you are allowed to use it for? Have you used it on your own work this week? If it got something wrong, would you tell someone? Confidence is when all three answers are yes from the people least likely to give them.

## What does good look like three months later?

Good looks like a business where AI use is visible, boring and owned. You would see:

- One or two approved tools, with business accounts, that everyone knows by name.
- A Stop list short enough that staff can recite it.
- A named person who answers “can I use it for this?” within a day.
- A standing question at the monthly team meeting: what has AI saved you, and did anything go wrong?
- New starters told the rules in their first week, before they have time to build their own habits.

Notice what is missing: monitoring software, a ban, and a 20-page policy nobody reads. Shadow AI shrinks when the approved route is easier than the hidden one. If you want the wider picture of where to begin, [How Should a Small Business Start Using AI?](https://business.theaieducator.io/posts/how-should-a-small-business-start-using-ai) sets out the first job to choose once the week is done.

## Where to go next

If your leadership team cannot yet answer “What may I do with it?” in one sentence, that is exactly the question my [AI strategy and governance session](https://theaieducator.io/ai-strategy-and-governance?utm_source=business.theaieducator.io&utm_medium=referral&utm_campaign=shadow-ai-small-business) is built to settle. If you would rather start with a score, the free [Workplace AI Readiness Check](https://theaieducator.io/workplace-ai-readiness?utm_source=business.theaieducator.io&utm_medium=referral&utm_campaign=shadow-ai-small-business) takes eight minutes and will tell you whether permission or protection is your weakest dimension.

## Sources and further reading

- “The hidden risks of shadow AI,” National Cyber Security Centre (NCSC), September 7, 2026. [ncsc.gov.uk](https://www.ncsc.gov.uk/blogs/the-hidden-risks-of-shadow-ai)
- “Employees Drive Rising Cybersecurity Risk As Shadow AI and Unsafe Work Habits Surge, WatchGuard Global Survey Finds,” WatchGuard Technologies via GlobeNewswire, July 14, 2026. [globenewswire.com](https://www.globenewswire.com/news-release/2026/07/14/3326924/0/en/employees-drive-rising-cybersecurity-risk-as-shadow-ai-and-unsafe-work-habits-surge-watchguard-global-survey-finds.html)
- “AI Agents at Work 2026: Securing the agentic enterprise,” Okta, May 27, 2026. [okta.com](https://www.okta.com/newsroom/articles/ai-agents-at-work-2026-agentic-enterprise-security/)
- “Does a Small Business Need an AI Policy?” AI for Business with Dan Fitzpatrick. [business.theaieducator.io](https://business.theaieducator.io/posts/does-a-small-business-need-an-ai-policy)

*Dan Fitzpatrick is The AI Educator: a Forbes contributor, international keynote speaker and bestselling author who helps businesses use AI well, safely and every day. [More about Dan](https://theaieducator.io/about).*


## Frequently asked questions

### What is shadow AI?

Shadow AI is any use of AI at work that sits outside the tools and rules the business has approved, such as an employee drafting client emails in a free personal chatbot account. The UK National Cyber Security Centre defines it as AI use not captured in an organization's approved systems and processes.

### Should I ban ChatGPT at work?

A ban on its own rarely works, because staff who find AI useful simply move to personal phones where you cannot see what data goes in. A better first step is to find out what people use, keep the safe uses, move valuable ones into approved business accounts, and stop only the risky ones.

### How common is shadow AI in small businesses?

Very common. In an April 2026 WatchGuard survey of 684 employees at organizations with 50 to 500 staff across eight countries, 64% said they use unauthorized AI tools for work. Because the figures are self-reported, the true share is probably higher rather than lower.

### What are the risks of employees using unapproved AI tools?

The main risks are sensitive data leaving the business, losing visibility and control of that data, and new routes for attackers through AI software. Okta found that internal emails, HR information and confidential documents were the information most often shared with unapproved tools.

### What should I do when I find out staff are using AI without permission?

Spend the first week finding out, not clamping down. Promise nobody will be disciplined for what they disclose that week, ask what tools they use and what goes in, sort each use into keep, move or stop, and give the uses you keep an approved home.

### Is shadow AI a data protection problem for a UK business?

It can be. If staff paste personal data about clients or colleagues into an unapproved AI service, the business remains responsible for that data under UK data protection law. That is why the Stop lane covers client personal data, staff records and login details going into unapproved tools.

---
Source: [Shadow AI: What to Do When Your Staff Are Already Using ChatGPT](https://business.theaieducator.io/posts/shadow-ai-small-business)
Publisher: [The AI Educator](https://theaieducator.io)
