Shadow AI The Risk No One Is Talking About — Unauthorised Data Sharing

Shadow AI is employees using unauthorised generative tools (for example ChatGPT or Microsoft Copilot) that can leak client, payroll or staff records outside your control; treat it as an active data‑loss vector and start an immediate discovery and containment sweep with your IT provider and the ICO where appropriate.

Staff pasting client spreadsheets into public chat — block the flow, then retrain

Problem: people copy and paste data into a public AI chat because it feels faster than internal tools. That single action can send names, addresses, payroll figures or intellectual property to an external model provider with different privacy terms. Diagnosis: this usually shows up as unexplained uploads from end‑user devices or repeated use of personal browser tabs on company machines.

Action: implement browser and endpoint controls to prevent unauthorised uploads and add a short, mandatory retraining session for affected teams. Block public AI endpoints on corporate devices while you identify which teams need exceptions. Logins via single sign‑on to approved AI platforms reduce the temptation to use personal accounts.

Operational steps you can complete inside one working week: deploy simple URL blocks for known public AI domains, push a one‑page acceptable‑use update, and run a two‑hour awareness session with managers. For technical help, ask your IT partner to include this in their patch and policy rollout — for example, our managed IT and AIOps work often bundles endpoint policy with training.

IT has no central record of AI queries — start prompt logging and retention rules

Problem: your business has no single place where AI queries are recorded, so no audit trail exists when a prompt contains personal or commercially sensitive data. Diagnosis: ask yourself whether you can show who queried what and when; if not, you lack necessary evidence to investigate or notify regulators.

Action: require approved AI tools to operate under accounts you control and enable logging of prompts and responses. Keep prompts for a short, documented retention period and delete unnecessary logs on a schedule that your data protection impact assessment (DPIA) supports. The ICO’s guidance on AI and data protection explains the linkage between automated decisioning, personal data and accountability — follow their framework when you draft your retention policy (ICO’s guidance on AI and data protection).

Technical note: centralised logging need not store full responses; store hashes, metadata and a redaction flag so you can investigate incidents without keeping extra copies of sensitive output.

Unknown third‑party model providers in your supply chain — map, assess and contract quickly

Problem: staff use niche tools or integrations that rely on third‑party model providers you have not assessed as processors. Diagnosis: this shows up as unusual API keys in code repositories, unknown invoices, or user requests for new SaaS tools without procurement sign‑off.

Action: perform a supplier map focused on AI integrations and treat any model provider that receives personal or commercial data as a data processor. Carry out a quick DPIA for any supplier that handles identifiable data and ensure contracts include data processing clauses and deletion obligations. If a supplier will train models on your data, insist on contractual guarantees that your data will not be used to improve general models or that training will be on segregated datasets.

Practical checklist: within two weeks, list every tool that ingests text or files; within four weeks, have processors assessed and contracts amended or paused where necessary.

No approved‑tool policy — approve one secure platform and limit ad‑hoc use

Problem: without an approved‑tool register, teams use whatever is quickest: free public tools, unvetted browser extensions, or personal subscriptions. Diagnosis: if IT ticketing systems show many “which tool should I use” requests, you lack a governance path for adoption.

Action: nominate a single approved AI platform for the organisation, connect it to corporate identity management, and require business cases for alternatives. Approve one platform for routine use and ban public accounts on corporate devices until controls are in place. Pair this with role‑based access: legal and HR teams often need different levels of access than marketing.

Make the approval process simple: submit a one‑page security and business case, and allow a fast lane for time‑sensitive pilots that includes a 30‑day review. That keeps innovation possible while preventing uncontrolled proliferation.

Related reading

FAQ

Can shadow AI use trigger an ICO data breach notification?

Yes — if personal data is exposed outside your control and it meets the breach thresholds you must consider reporting; under UK law, breaches that are likely to result in a risk to individuals should be assessed and reported to the ICO within 72 hours where feasible.

How quickly should I find and stop shadow AI activity?

Begin discovery immediately and aim to deploy basic blocking controls and staff guidance within two weeks; complete a fuller supplier and DPIA review within one month.

Will banning all AI tools on staff devices stop the business impact?

Banning can reduce immediate risk but also blocks legitimate productivity gains; instead, approve a controlled platform and impose technical controls so staff can continue productive work without uncontrolled data sharing.

How much does a basic shadow AI risk audit typically cost?

Prices vary, but expect a focused external audit and remediation plan to fall in a modest range depending on headcount and complexity; ask providers for a fixed‑price proposal tied to deliverables and timelines.