Shadow AI is the free ChatGPT, or other AI tool, that staff use for work without company approval, and Microsoft’s UK research found that 71% of UK employees have used unapproved consumer AI tools at work. Once someone pastes a client contract into a personal account, the AI company has a copy, it shows up on their own laptop and phone, your company can’t see it or delete it, and it leaves with them when they go. This one-minute video, told by a villain called Shadow AI, shows how it happens and the three fixes: company AI accounts, a short AI policy and blocking unapproved AI tools on company devices.
Why is shadow AI a risk?
The NCSC describes shadow AI as AI use that isn’t part of an organisation’s approved systems and processes. Microsoft’s research, carried out by Censuswide with 2,003 UK employees in October 2025, found that 71% had used unapproved consumer AI tools at work and 51% still do every week. Four in ten said it’s what they’re used to in their personal life, and 28% said their company doesn’t provide a work-approved option.
Say someone pastes a client contract into a free personal account to get a quick summary. The AI company now holds a copy, and the conversation shows up wherever that account is signed in, including a home laptop and a phone your company doesn’t manage. Your company can’t see it or delete it, and when that person leaves, everything they pasted leaves with them. On free consumer plans, conversations may also be used to teach the AI unless the user opts out. Nothing is hacked, and no alert goes off.
The NCSC says that passing sensitive information to consumer AI services is likely to reduce your visibility and control over it, because it may be stored, retained or used to improve the service.
Why client data makes it a legal problem
If that contract holds clients’ personal details, the law makes them your responsibility. The ICO says that whenever an organisation uses another company to process personal data for it, there must be a written contract in place. A personal AI account has no contract with your business, so sharing client data that way can break UK data protection rules and your client agreements. Our guide to how a confidential document walks out of your business covers this in more detail, and our guide to AI phishing attacks covers the other side: attackers using AI to get in.
What to do about shadow AI
- Give your team company AI accounts that you manage. Business plans typically don’t use your content to teach the AI by default, sign-in is tied to your company identity, and when someone leaves you remove their AI access in one place. If you use Microsoft 365, our Copilot readiness assessment looks at whether your business is ready for Microsoft 365 Copilot.
- Write a short AI policy: no client data in personal AI accounts. Say what’s allowed, what isn’t and who to ask, then tell people the approved tool exists.
- Block unapproved AI tools on company devices. Tools such as Microsoft Defender for Cloud Apps show which AI apps are in use, let you approve your chosen tool, and warn on or block the rest. Do this once the approved tool is in place: a blanket ban with no alternative moves people onto the app on their own phone.
The NCSC isn’t recommending that people stop using AI. It says organisations that understand why staff turn to shadow AI are better placed to provide secure alternatives.
Video transcript
Read the full transcript
Shadow AI: I’m shadow AI: the free ChatGPT, or other AI tool, that staff use for work without company approval.
Shadow AI: Say Tom pastes a client contract into his personal account. Now the AI company has it, and it shows up on his home laptop, and his phone.
Shadow AI: Your company can’t see it, or delete it.
Shadow AI: And when Tom leaves, everything he pasted leaves with him.
Shadow AI: And your clients’ personal details? By law, they’re your responsibility.
Shadow AI: So go on. Try and stop me. I’ll wait.
Narrator: That’s shadow AI. Give your team company AI accounts that you manage. Write a short policy: no client data in personal AI accounts. And block unapproved AI tools on company devices.
Narrator: Bring your AI out of the shadows. Talk to Ingenio.
Frequently asked questions
What is shadow AI?
Shadow AI is the use of AI tools that aren’t part of a company’s approved systems, such as a member of staff using their free personal ChatGPT account for work. The company hasn’t approved it and can’t easily see what goes into it.
How common is shadow AI in the UK?
Microsoft’s research with 2,003 UK employees, carried out in October 2025, found that 71% had used unapproved consumer AI tools at work and 51% still do every week. The NCSC quotes the same figure.
Is it safe to paste client data into ChatGPT?
Not into a personal account. The NCSC advises against including sensitive information in queries to public AI chatbots, and OpenAI says it may use content from its services for individuals to train its models. Use a business account your company manages, under an agreement that covers your data.
Does ChatGPT use what I paste to train its models?
On services for individuals, such as free ChatGPT, OpenAI says it may use your content to train its models. For business products, such as ChatGPT Business and ChatGPT Enterprise, it says it doesn’t train on your inputs or outputs by default.
Should we ban AI tools at work?
A blanket ban tends to move AI use onto personal phones, where you can’t see it. The NCSC isn’t recommending that people stop using AI. Give your team an approved tool, write a short policy, and then block unapproved tools on company devices.
Who is responsible if staff share client data with an AI tool?
Your business is. The ICO says overall accountability for data protection compliance lies with the organisation, and that using another company to process personal data needs a written contract.
How we help
At Ingenio, we use AI in our own business and help clients adopt it safely. That means finding out which AI tools are already in use, helping you adopt the ones worth approving, setting up data protection controls in Microsoft Purview and writing a plain-English AI policy, with ongoing managed cyber security so it stays in place. We’re based in Brighton and support businesses across Sussex and the South East.
Final thought
Give your team an approved AI tool, tell them what they can’t paste into a personal one, and block the rest on company devices. Then client data stays in accounts your company controls.
👉 Talk to us about using AI safely in your business. We’re happy to talk it through.
Sources
- NCSC: The hidden risks of shadow AI
- NCSC: ChatGPT and large language models, what’s the risk?
- Microsoft UK Stories: Rise in ‘Shadow AI’ tools raising security concerns for UK (October 2025)
- OpenAI: How your data is used to improve model performance
- ICO: Contracts
- ICO: What are the accountability and governance implications of AI?