Somebody on your team pasted a customer list into a free AI tool last month. They wanted it tidied into a table, they had 20 minutes before a meeting, and the tool did it in nine seconds.
They didn’t ask you. Why would they? Nobody had told them not to, and the job got done.
That’s shadow AI: tools your staff use for work that your business never bought, never approved and can’t see. It isn’t a rogue employee story and it isn’t a technology story. It’s the most predictable thing in the world, and if you employ more than a handful of people it is already happening in your business today. The question worth your time isn’t whether it’s going on. It’s what’s going out, and what the pattern of it is telling you about how your business runs. If you’re at the start of all this, AI for small business is the wider picture and this post is one corner of it.
It isn’t defiance. It’s the shortest route.
Nobody does this to be difficult.
A free AI tab costs nothing, needs no purchase order, no IT ticket, no conversation with you, and it’s open in the same browser as everything else. Set that against the approved way of doing the job, which is a system somebody chose four years ago that takes six clicks and a password reset.
Given those two options at 4pm on a Thursday, your team picks the tab. So would you.
And the people doing it most are rarely the ones you’d suspect. In our experience it’s the person who cares about turnaround, the one who’d rather get it out the door than wait. Owners and managers are frequently the worst offenders, partly because nobody is going to tell them off and partly because they’re the ones under the most time pressure.
Treat it as a discipline problem and you’ll be wrong about the cause and wrong about the fix.
What actually leaves the building
“Company data” is too vague to make anyone careful. Be specific about what gets pasted in, because it’s always the same short list:
- Customer records. Names, email addresses, phone numbers, delivery addresses, order history. Usually as a spreadsheet somebody wanted reformatted or deduplicated.
- Your pricing and the margin behind it. Pasted in to draft a quote, which means the quote, the cost and often the discount logic all go in together.
- Contracts and terms. Dropped in to get a plain English summary before a call. Frequently somebody else’s contract, which your business signed a confidentiality clause over.
- CVs, interview notes and staff records. Candidate details go in to get a shortlist ranked. So do performance notes, at review time.
- Half-finished financials. Month end, a messy export, and somebody asking for the numbers explained.
- Whole email threads. Including the part where the client said something they’d never put in writing to anyone else.
None of that is theft and none of it is carelessness in the way people usually mean it. The person doing it is thinking about the table, or the summary, or the shortlist. They’re not thinking about where the text goes after they press enter, because nothing on the screen ever asked them to.
Whose problem this is, which is the bit owners get wrong
Your customers gave you their data. Not the tool. They’ve never heard of the tool.
That distinction is the whole of it. When personal data about UK customers or staff sits in your systems, the responsibility for looking after it sits with your business, and the Information Commissioner’s Office is who you’d be explaining yourself to. “One of my team did it on her own laptop, on her own account” is not the defence people assume it is. She was doing your work, on your instruction, with data you hold. The same accountability follows data you hand to a supplier, which is why the contract matters as much as the tool: who owns the code and the data covers the questions worth settling before you sign one.
There’s a second thing worth understanding, because it’s the one detail that changes behaviour once people grasp it: a free consumer account and a paid business account are not the same product with different limits. They sit on different terms. Business and enterprise tiers generally come with contractual commitments about how your content is handled and whether it can be used to improve the underlying model. Free personal accounts, by default, often do not. Same logo on the screen, materially different deal behind it.
Then there’s the commercial risk, which tends to land sooner than the regulatory one. If you do work for other businesses, look at what you’ve already signed. Confidentiality clauses cover their data in your hands, and a growing number of contracts now name third-party AI tools directly. Losing a client over a clause you agreed to is a faster and more expensive outcome than anything a regulator does.
Three responses that don’t work
Ban it. The most popular and the worst. The work still has to be done and the tool still exists, so use moves to personal phones and personal accounts where you can’t see any of it, can’t train anyone on it, and will find out about it after something has gone wrong. A ban doesn’t stop shadow AI. It stops you hearing about shadow AI.
Ignore it. Some owners land here by accident, having decided it’s a big-company problem. It isn’t. Small businesses hold exactly the same personal data, usually with fewer controls around it and nobody whose job it is to notice.
Buy everyone a seat and call it done. Better than the other two, and still not a policy. A licence tells your team which logo to use. It tells them nothing about what they can put into it, and the person who was pasting the customer list into a free tab last week will now paste it into a paid one, which is progress but not much. Seats are plumbing. Rules are the thing.
The one page that fixes most of it
You don’t need a policy document. You need one page that a new starter reads in four minutes and actually remembers. Three lists and a name.
Green. Put anything here into any tool we’ve approved. Marketing copy, your own website text, job adverts, general drafting, anything already published, anything you invented on the spot.
Amber. Only in the accounts the business pays for. Internal documents, process notes, draft plans, anonymised numbers, anything commercially sensitive but not personal.
Red. Never, in any tool, unless we’ve agreed it in writing first. Customer personal data, staff records, anything covered by a client confidentiality agreement, bank and card details, logins, health information, and anything that would have to be reported if it leaked.
A name. One person who decides when something doesn’t fit the lists. That’s the part most businesses miss, and it’s the part that makes the rest work. A list with no route for the awkward cases sends people straight back to guessing.
Four rules for writing it:
- Keep it to a page. An eight page policy is a policy nobody has read, which is the same as no policy with more admin.
- Use the nouns your business actually uses. “The customer spreadsheet on the shared drive”, not “customer data assets”. People match rules to things they can picture.
- Say why the red list is red. One line each. Adults follow rules they understand and quietly route around rules they don’t.
- Open with an amnesty. State plainly that nobody is in trouble for anything they’ve already done. You want the truth about what’s being used, and you’ll only get it once.
Then give them something better than the free tab
A policy with no approved route is a ban wearing a lanyard.
So pair the page with a real alternative. Paid accounts on the business plan for the people who’d use them. Turn off model training on your content where the setting exists, and check it, because the default is not always the one you’d pick. Keep the accounts in the company’s name so they don’t walk out of the door when somebody leaves.
Then spend half an hour, once, showing your team what good and bad input looks like using their actual work. That half hour moves behaviour further than any second page of policy ever will.
Do this much and you’ve handled the risk side. What follows is the part that’s worth more.
That list of what they’re using is worth money
Once you’ve run the amnesty and you know what your team is quietly using AI for, you’re holding something you could not have bought: an honest list of the jobs in your business that are repetitive enough that somebody went looking for a shortcut without being asked.
Nobody pastes a one-off into a chat window. They paste the thing they do every week.
Which means you now have a shortlist of automation candidates, ranked by the people who do the work, by how much the work hurts. Most owners pay a consultant to produce a worse version of that list. Yours arrived free because you asked the right question and promised not to shout.
Two things to look for in it.
Where the same task appears in more than one person’s answer. That’s volume, and volume is what makes a build pay. Which processes to automate first covers how to rank them properly, and the systemisation scorecard will do the ranking for you.
Where somebody is bridging two systems by hand. A surprising share of shadow AI use is a person copying data out of one thing, getting a tool to reshape it, and pasting it into another thing. That’s not really an AI habit, it’s a missing connection between two systems, and it’s the single clearest sign that the answer might be something built rather than something bought. Build vs buy for AI has the honest test for which of those it is.
Worth being clear on the difference while you’re looking. A person pasting into a chat window is not the same thing as a system doing the work on its own, and the gap between them is where most of the value sits. AI agents vs chatbots vs automations sets out which is which, and what AI can actually do for a small business covers where the honest limits are.
Why this turns into a stalled project so often
Owners who take shadow AI seriously frequently do the right thing and then stall in the same place.
They write the page. They buy the seats. They tell everyone. And six months on, nothing about how the business runs has changed, because the work is still being done by a person and a chat window, one task at a time, with the same copy-paste in the middle of it.
That’s the same wall most small business AI pilots hit. A policy makes the existing habit safer. It doesn’t take the work off anybody. Turning “Sarah pastes the enquiry list in every Monday” into something that just happens without Sarah is a different job, and it starts with counting what that Monday actually costs you. The manual work cost calculator gives you that figure in about five minutes, and the cost of manual work explains what to do with the number once you have it.
What this looks like when it’s designed in
When we run an audit, one of the first questions we ask is what people are already using and what for. It gets us to a true picture of how the business runs faster than any process map somebody drew for us, because it’s evidence rather than description. Half of what surfaces gets fixed with a setting and a sentence in the policy. The rest is the automation list.
It matters more the more personal data you hold. MidShift serves over 20,000 professionals, so personal data isn’t an edge case there, it’s the whole product. Where that data could and couldn’t go was settled while the thing was being built, which is a great deal cheaper than deciding it afterwards with a policy and some hope. The MidShift build covers how that ran.
If you’re weighing up outside help on any of this, how to choose an AI consultant lists what to ask, including the questions about data handling that most people forget until the contract stage.
The short version
Your team is already using AI. Assume it, because it’s true.
They’re not doing it to spite you, they’re doing it because it’s faster than the approved route, and the fix is a better approved route rather than a stricter rule. Write one page: green, amber, red, plus one name to ask. Run an amnesty so you find out what’s really going on. Pay for the accounts and check the training setting.
Then read the list of what they’ve been using it for as what it is, which is your automation backlog, written by the people closest to the work, for free. When you pick one off it, this is how you teach an agent the job properly.
Related reads
- Who owns the code and the data when you hire an AI consultant?
- How to train an AI agent on how your business actually works
- AI for small business: the complete guide
- What AI can actually do for a small business (and what it can’t)
- Why most small business AI pilots never ship
- Which processes to automate first (and how to rank them)
- The cost of manual work: what repetitive admin really costs
- Build vs buy for AI: when off-the-shelf is genuinely fine
- AI agents vs chatbots vs automations: what’s the difference
- What an AI audit is and what you should get from one
- How to choose an AI consultant (and the red flags)
- How MidShift built an AI career guidance engine for 20,000+ professionals
Want to know what your team is actually using, and what to do about it?
An AI audit maps every repeatable process in your business, costs it in hours and pounds, and ranks what to fix first. The shadow AI conversation is part of it, because it’s the quickest way to see how the work really flows rather than how the org chart says it does.
Fixed price, agreed in writing before anything starts. No day rates, no paid discovery phase.
Book a free call and tell us what you’ve found.