Skip to main content
Download free report
Softblues
Softblues
Back to Blog
AI Strategy & Consulting
July 30, 20268 min read

Shadow AI at Work: What UK Companies Should Do About Unapproved AI Tools

Only 31% of UK organisations have a policy covering AI use and shadow AI (IBM, 2025). A practical 30-day plan to find out what your people are actually using, and route it somewhere safe.

Shadow AI at Work: What UK Companies Should Do About Unapproved AI Tools

By Ivan Pylypchuk, CEO of SoftBlues

Shadow AI is already in your building. Only 31% of UK organisations have a governance policy covering how AI is used and how to prevent it (IBM, 2025). The other 69% are not AI-free. They are AI-unmanaged, which is a different and more expensive condition.

Shadow AI is the free or personally paid AI tool your people already use without anyone signing it off. A public chatbot summarising a client call. A transcription service sitting in a board meeting. A browser extension drafting replies inside your CRM. It is rarely malicious. It is usually someone trying to get their work done faster with the tool they use at home.

The short answer for UK mid-market companies: find out what is actually in use, provide one sanctioned assistant that is better than the shadow option, and write a one-page policy people will read. Banning it moves the usage to personal phones, where you cannot see it at all.

Three cards showing how shadow AI enters a company: personal chatbots used for client work, unapproved browser extensions inside business systems, and free transcription tools joining internal meetings.

Key facts

  • 1 in 5 breached organisations had shadow AI involved in the incident (IBM Cost of a Data Breach, 2025).
  • Those breaches cost an extra $670,000 on average, against a global average breach cost of $4.44m (same report).
  • 97% of organisations that suffered an AI-related breach lacked proper AI access controls (same report).
  • In the UK the average breach cost £3.29m, and only 31% of organisations had a policy to manage AI use and prevent shadow AI (IBM UK, 2025).
  • 78% of people using AI at work bring their own tools to do it (Microsoft and LinkedIn Work Trend Index, 2024).
  • The same research found the pattern is stronger in smaller organisations and spread evenly across age groups. This is not a generational issue.

  • Why do people use AI tools nobody approved?

    Because the approved option is missing, slower, or worse. The reasons are boringly consistent.

    There is no sanctioned tool. Someone asked in March, procurement is still reviewing, and the work did not pause.

    The sanctioned tool is weaker. A licence was bought for one department, or the deployed assistant cannot see the documents people actually need.

    Nobody said it was off-limits. A policy sitting in a PDF nobody has opened is functionally the same as no policy.

    It genuinely works. Organisations underweight this one. The employee pasting a contract into a chatbot gets a useful summary in ten seconds. Any response that pretends otherwise is going to lose.

    Important
    Shadow AI is a demand signal before it is a security problem. Every unapproved tool in your organisation is a documented request for a capability you have not provided.

    What is actually at risk?

    Four things, in rough order of how often they bite.

    Confidentiality. Client data, salary information, unreleased financials and draft contracts pasted into services with consumer terms. Whether that data trains a model depends on the tier and the settings, and almost nobody checks which one they are on.

    Legal basis. Under UK GDPR you need to know where personal data goes and on what basis. "An employee pasted it into a website" is not a processing record you want to take to the ICO.

    Contractual exposure. Client contracts and DPAs list approved subprocessors. A free summarisation tool handling their data breaches that agreement long before anyone breaches your systems.

    Wrong answers, quietly. A model that invents a clause in a contract summary or a figure in a board pack does damage no firewall catches.


    Ban it, ignore it, or route it?

    There are three real strategies, and two of them lose.

    ApproachWhat happensBest forAvoid if
    Ban and blockUsage moves to personal phones and personal accounts, where you have no visibility at allGenuinely restricted environments with an air-gapped alternativeYour people do knowledge work and own a phone
    Ignore itAdoption grows, exposure grows, and you learn the map during an incidentNothingAlways
    Sanction and routeProvide a good approved tool, make it the path of least resistance, monitor the restAlmost every UK and Ireland mid-market companyYou cannot fund any licensed option at all

    Blocking domains is one control inside the third option, not a strategy on its own. Used alone it converts a visible risk into an invisible one.

    Two-column comparison of banning AI tools against sanctioning and routing them, contrasting hidden personal-device usage with an approved assistant that has logging, access controls and a named owner.


    A 30-day plan to bring shadow AI into the light

    This is the sequence we run. It is deliberately fast, because a six-month governance programme guarantees six more months of unmanaged usage.

    1. Find out what is actually in use (week 1). Pull the evidence from where it already sits: expense claims for AI subscriptions, browser extension inventories, SSO and identity logs, network traffic to known AI domains. Then ask people directly, with an amnesty. The survey usually finds more than the logs do.

    2. Sort by data sensitivity, not by tool (week 1). A chatbot used to draft a blog post is not the same risk as the same chatbot used on a client file, even though it is the same URL. Classify by what goes in.

    3. Name the top three gaps (week 2). The tools with the highest usage tell you which capability you are missing: summarising, drafting, research, transcription, coding. That is a requirements list written by your own staff.

    4. Stand up one sanctioned assistant (weeks 2 to 3). Business-tier terms, no training on your data, SSO, audit logging, and permissions that follow the person. Our Claude Enterprise implementation checklist covers the specific settings worth arguing about.

    5. Write a one-page policy people will read (week 3). Green list, amber list, red list. What data never goes into an external tool. Who to ask. One page, plain English, with examples from your actual work.

    6. Make the approved route faster than the shadow one (week 4). Licences issued the same day, inside tools people already have open, with prompts and templates for the five jobs they do most. Adoption is a distribution problem, which is why so many companies find nobody using the AI they bought.

    7. Set a standing review (week 4). Monthly for the first quarter: what is in use, what got blocked, what needs a licence. New tools appear faster than an annual review can cope with.

    💡Tip
    Run the discovery with an explicit amnesty and say so in writing. You are trying to find out what people use, and nobody volunteers that into a disciplinary process.

    What "sanctioned" should mean in practice

    A tool is not sanctioned because somebody approved the invoice. Ask for five properties before you call it approved.

    Business terms. Your inputs are not used to train the provider's models, and that sits in the contract rather than a blog post.

    Identity. SSO, so access ends when employment does.

    Least privilege. The assistant sees what the person is allowed to see, and no more. This is where 97% of the AI-related breaches in IBM's data fell down.

    Logging. You can answer "who asked it what, and when" during an incident or a client audit.

    A named owner. Someone accountable for licences, settings and the review cadence.

    We run our own company this way, on Claude, with the controls we recommend to clients. It is written up in our Claude operating system case study. It is also why we are blunt about the cost: the licence is the small number, and the rollout and permissions work is the real one.


    Red flags in your own organisation

  • Expense claims show individual AI subscriptions on personal cards.
  • Nobody can produce a list of AI tools in use, and the list they produce disagrees with the logs.
  • A client DPA lists subprocessors that exclude a tool your team uses daily.
  • The AI policy runs longer than two pages and was last opened when it was written.
  • Staff describe the approved tool as the slow one.
  • An AI tool has access to a shared mailbox or a document store, and nobody recalls granting it.

  • Frequently asked questions

    Is shadow AI a real security problem, or vendor scaremongering? It is measurable. IBM's 2025 study found shadow AI involved in 20% of the breaches studied, and associated with an extra $670,000 in cost. The risk is real, though unevenly distributed. It concentrates wherever sensitive data meets an unmanaged tool.

    Can we just block AI websites on the corporate network? You can, and it will reduce visible usage while pushing the rest onto personal devices. Blocking works as one control alongside a sanctioned alternative. On its own it makes your exposure harder to see.

    How do we find out what is being used without buying a tool for it? Start with expense data, SSO and identity logs, browser extension inventories, and an anonymous internal survey. That combination finds most of it inside a week, for the cost of someone's attention.

    Does an enterprise AI licence solve it? It solves the biggest cause, which is the absence of a good option. It does not solve distribution. If licences sit unassigned or the assistant cannot see the right documents, people go back to what worked.

    What does UK GDPR actually require here? You need to know what personal data is processed, where, by whom and on what basis, and to be able to evidence it. Shadow AI breaks the record-keeping before it breaks anything else, so treat unapproved tools as an accuracy problem in your ROPA as well as a security one.

    Should we discipline people using unapproved tools? Not as the first move, or you lose the visibility you need. Amnesty first, a clear policy second, and consequences reserved for someone ignoring a clear rule with sensitive data.

    Where does this sit relative to a wider AI policy? Shadow AI is the symptom, governance is the system. The broader framework of roles, approval routes, risk tiers and review sits in our guide to AI governance for UK mid-market companies.


    Where to start

    Spend a week finding out what your organisation is actually using. Not to stop it. To see it. The list will tell you which capability to buy, which data to fence off, and how urgent the rest of it is.

    SoftBlues is a registered Anthropic Partner Network member and a Google Cloud Partner, and we run our own operations on the setup we recommend. If you want help mapping what is in use and standing up a sanctioned alternative people will actually prefer, the first conversation is a diagnosis rather than a pitch.

    Book a call.

    See it in production

    Systems we have built and run for clients, with the numbers that came out of them.

    Browse all case studies

    Related Articles