Shadow AI: A Rapidly Growing Risk Inside Your Organisation
CyberKainos. Reading time: 6 mins
Shadow AI: How much visibility do you really have today?
Somewhere in your organisation right now, an employee is probably pasting a document or chat thread from Slack into ChatGPT to get a quick summary, or dropping unreleased figures into a browser extension to build a chart. A member of your HR team might be using an AI tool to draft a redundancy letter… sensitive personal data included. None of this was sanctioned. None of it will show up in your next security audit. And almost certainly, none of it has been discussed at board level.
This is shadow AI: the fast-growing, largely invisible use of consumer AI tools by staff, outside any policy, oversight, or IT approval. It’s one of the most significant governance blind spots facing organisations today, and most boards don’t yet grasp how widespread it already is.
The scale of Shadow AI use is bigger than most boards assume
If you asked your leadership team how many employees use unauthorised AI tools at work (we do, regularly), most would guess “a few.” The real numbers tell a very different story.
Research commissioned by Microsoft, surveying over 2,000 UK employees in late 2025, found that 71% of UK employees have used unapproved consumer AI tools at work, and 51% use them every week. These aren’t fringe cases confined to tech-savvy individuals. The survey covered financial services, retail, education, health and social care, in both the public and private sectors. Staff are using these tools to draft communications (49%), build reports and presentations (40%), and handle finance-related tasks (22%).
Perhaps most concerning: only 32% of employees expressed any concern about the data privacy risks of feeding company or customer information into these tools. For most people, AI has simply become part of how they get work done faster. A means to justify an outcome. A risk calculation simply isn’t happening, because most staff don’t see their actions creating a security risk. They see themselves as being efficient.
The picture inside the tools themselves is just as stark. LayerX Security’s 2025 Enterprise AI and SaaS Data Security Report, based on enterprise browser telemetry, found that roughly 18% of employees regularly paste data into generative AI tools, and more than half of those paste events include corporate information. Users who do this are prolific with an average close to seven pastes a day, with the majority containing sensitive material; customer records, financial data, source code, or strategic plans, all typed into tools your organisation has no contract with, no data processing agreement covering, and no visibility into.
Why this belongs on the board’s agenda
It’s tempting to file shadow AI under “IT problem.” That would be a mistake, and here’s why it sits squarely with the board.
Data leakage and confidentiality. When an employee pastes a client contract, unreleased financials, or personal data into a free AI tool, that information may be used to train the underlying model, retained on third-party servers outside your control, or exposed in a future breach. You have no contractual protection, no audit trail, and often no idea it happened until it’s too late.
Intellectual property exposure. Source code, product designs, pricing strategy, M&A documents, once pasted into a public AI tool has effectively left the building. There is no way to claw it back, and depending on the tool’s terms of service, your organisation may have unknowingly granted rights over it.
Regulatory and compliance exposure. If your organization handles personal data under UK GDPR, shadow AI use creates real exposure. An employee using an AI tool to process customer or employee personal data without a data processing agreement, without a documented lawful basis, or without any assessment of where that data goes is a compliance failure waiting to be discovered, most likely during a breach investigation or a regulator’s inquiry, which is the worst possible time to discover it.
Client and contractual risk. Many client contracts, particularly in regulated sectors like financial services, legal, or healthcare, include confidentiality clauses that shadow AI use can breach without anyone realizing it. If a client discovers their data was processed through an unapproved tool, the reputational and commercial fallout can be significant.
For boards, the uncomfortable truth is this: shadow AI isn’t a future risk to plan for. It’s a present risk to govern. And “we didn’t know it was happening” is not a defensible position with regulators, clients, or shareholders.
How to close the Shadow AI gap
Shadow AI is a great example of the governance trap that organisations without a full-time CISO fall into. Someone needs to be asking the right questions, translating a fast-moving technical risk into board-level decisions, and building the practical controls to manage it. Doing this without adding a six-figure hire that many mid-sized organisations don’t yet need or can’t yet justify is exactly where a virtual CISO earns their keep. They bring the expertise to assess your organisation’s actual exposure, the authority to set policy, and the ongoing oversight to keep governance current as AI tools and regulations keep evolving. All on a scale that fits your organisations’ realistic budget:
Build a practical governance framework
The goal isn’t to ban AI. That’s both unrealistic and counterproductive given the legitimate productivity gains on offer. The goal is visibility and control. A practical shadow AI governance framework includes:
Create an AI acceptable use policy. A clear, plainly written policy defining which AI tools are approved, what data can and cannot be entered into them, and what employees should do instead when they need AI assistance for sensitive work. This should be a living document, reviewed as new tools emerge.
Approve tools to shorten the shadow. Banning consumer AI tools without offering a sanctioned alternative simply pushes the behaviour further underground. Organisations that provide or authorise enterprise-grade AI tools with proper data protections in place see meaningfully lower shadow AI use.
Ensure technical visibility. Ensure basic monitoring through browser controls, DLP tooling, or network-level visibility are being used appropriately to understand which AI tools are actually in use across the organisation, rather than relying on assumptions.
Train your staff. Most employees using shadow AI aren’t being reckless; they simply don’t understand the risk. Short, practical training on what data should never go into a public AI tool goes a long way.
Review regularly. AI tools and regulatory guidance are both moving quickly. What’s an acceptable risk today may not be in six months. This needs a standing item on the risk register, not a one-off project.
The bottom line
Shadow AI is already inside your organisation. The only real question for the board is whether it’s being governed, or simply ignored until something goes wrong. If your organisation doesn’t have a full-time security leader driving this conversation, that’s not a reason to leave it unaddressed… it’s the reason a vCISO exists.
How CyberKainos can help
CyberKainos helps organisations without a full-time CISO build practical, board-ready AI governance, from policy to monitoring to ongoing oversight. If you’d like a clear picture of your organisation’s shadow AI exposure, let’s talk.