← Articles

AI Governance

Your Business Is Probably Using More AI Than You Think: How to Find Your Shadow AI

Your business may be using considerably more AI than you realise. Before writing policies or conducting risk assessments, start by finding the AI tools your people are already using and understanding what they are using them for.

Matthew Spurr13 min read

If you run a small business and I asked you to list every AI system your company uses, how confident would you be in your answer?

You'd probably remember the obvious ones.

ChatGPT. Microsoft Copilot. Perhaps Claude. The AI features you've deliberately switched on in your CRM. Maybe the chatbot on your website.

But what about the AI meeting recorder somebody in sales installed six months ago?

The browser extension your marketing manager uses to rewrite emails?

Canva's AI features?

The prospecting tool somebody found on LinkedIn?

The personal ChatGPT account an employee uses because they prefer it to the company-approved software?

Or the employee who discovered that uploading a spreadsheet to an AI assistant gets them an answer in five minutes instead of spending an hour wrestling with Excel?

This is shadow AI.

And I suspect a lot of small businesses have considerably more of it than their owners realise.

Shadow AI doesn't necessarily mean somebody is doing something wrong

This distinction matters.

When people hear "shadow AI", it sounds inherently sinister. Employees secretly feeding company secrets into mysterious artificial intelligence systems behind management's back.

Sometimes the reality is much more mundane.

Someone has a job to do.

They discover a tool that makes that job easier.

They start using it.

That's it.

In fact, the UK's National Cyber Security Centre published guidance on shadow AI this week that makes almost exactly this point. It defines shadow AI as AI technology that isn't captured within an organisation's approved systems and processes, and warns that where official policies and tools don't meet people's business needs, employees are likely to find alternatives themselves.

Microsoft research published last year found that 71% of UK employees surveyed had used unapproved consumer AI tools at work, with 51% saying they continued to do so weekly.

So if you haven't explicitly approved much AI in your organisation, that doesn't necessarily mean your organisation isn't using much AI.

It might simply mean you can't see it.

I wouldn't start with a policy

This is where I think a lot of organisations will instinctively get things backwards.

Management discovers people are using unapproved AI.

Someone writes an AI policy.

The policy says:

Employees must not use unauthorised AI systems for company business.

Everybody receives it by email.

Everybody clicks whatever they need to click.

Management can now say it has an AI policy.

Problem solved.

Except, of course, it isn't.

If the unofficial tool saves somebody five hours a week and the approved alternative doesn't, you've done nothing about the reason they were using it.

You've just told them to stop.

And if employees think admitting that they're using AI will get them into trouble, you've potentially made the original problem worse.

You've turned unknown AI use into AI use people have an incentive not to tell you about.

I'd do the opposite.

Start with a 15-minute conversation

Before banning anything, I'd find out what's actually happening.

For a small company, this doesn't need to begin with specialist software, consultants or a three-month discovery programme.

I'd send something like this on Slack or Teams:

Quick one: we're looking at how AI is being used across the business so we can make sure we're providing the right tools and accounts. What are the top three AI tools, features or browser extensions you've tried or used for work in the last month? No judgement at all. We just want to understand what's useful and what's already being used.

The wording is deliberate.

I'm not asking:

Which unauthorised AI systems have you been using?

I'm asking:

What's making your job easier?

You'll get much better information.

And I'd include AI-enabled features, not just obvious standalone products.

Increasingly, AI is disappearing inside ordinary software. Someone may truthfully tell you they don't "use AI" while regularly using an AI feature built into software they've used for years.

Your objective at this stage isn't to assess everything.

It's to discover it.

Build an AI inventory before you build an AI bureaucracy

Once you've got the answers, put them somewhere.

A spreadsheet is fine.

For a small business, I'd initially want to know things like:

What is the tool?

Who's using it and what are they using it for?

Is it a personal account or a company-managed service?

What sort of information is being put into it?

What happens to the output?

Could that output reach a client, customer or the public?

Does the tool connect to any other company systems?

Have we actually approved this use?

That's enough to start seeing the shape of your AI use.

Interestingly, this isn't just my preferred approach.

The UK government's AI Management Essentials work begins with an AI system record, asking whether organisations maintain a complete and up-to-date record of the AI systems they develop and use, whether new systems are added through an established process, and how frequently that record is reviewed.

The guidance is particularly relevant to SMEs and start-ups, which were specifically among the organisations the government designed the approach to help.

ISO/IEC 42001 also takes an inventory-like approach to relevant AI resources, including systems, tooling, data and people.

But you don't need to begin with a management system.

You need to begin with visibility.

Not every AI use deserves the same response

This is where proportionality comes back in.

Imagine your discovery exercise uncovers these four things:

1. Someone occasionally asks an AI assistant to improve the wording of an internal email.

2. Marketing uses generative AI to create ideas for social posts, which a human then writes and approves.

3. A salesperson regularly uploads spreadsheets containing customer information into a personal AI account.

4. HR is experimenting with an AI system to help rank job applicants.

It would be ridiculous to treat those four uses as though they present exactly the same questions.

That's where an inventory starts becoming useful.

It lets you triage.

What information is involved?

Could individuals be affected?

Is the AI influencing a meaningful decision?

Is confidential or personal information being processed?

Does the output leave the organisation?

What happens if it's wrong?

Who reviews it?

The UK government's AI Management Essentials approach makes a similar distinction between maintaining an AI system record and subsequently assessing impacts and risks. Its risk material includes areas such as privacy, bias, reputational risk and the potential impact of AI systems on individuals and society.

Discovery comes first.

Then you decide what deserves closer attention.

Sometimes the employee has discovered something useful

There's another side to this that I think gets overlooked.

Imagine an employee discovers an AI tool that saves them five hours every week.

They've solved a genuine business problem.

If management's entire response is:

You aren't allowed to use that.

...I think management has missed half the point.

The right response might still be that the particular tool can't be used.

Perhaps its terms aren't suitable.

Perhaps the information being entered is too sensitive.

Perhaps there's a contractual, privacy or security problem.

But the conversation shouldn't end there.

The interesting question is:

What were you trying to achieve, and can we give you a safe way to achieve it?

Maybe there's an appropriate company version of the same product.

Maybe there's another approved tool that does the job.

Maybe the company should actually adopt the thing the employee discovered.

This is where I think governance gets unfairly confused with restriction.

Good governance shouldn't simply produce a longer list of things people can't do.

It should help an organisation understand how people want to use AI, decide which uses it's comfortable with and then make the safe route as easy as possible.

Make the approved tools better than the unapproved ones

If I were running a small company now, this would be one of my basic principles.

If employees are getting genuine value from AI, I'd rather provide appropriate company-managed tools than spend my life trying to police personal accounts.

Give people the better version.

Give them work credentials.

Configure the organisational controls appropriately.

Explain what kinds of information are and aren't suitable.

Make it clear when human review is required.

Then explain why.

Not:

Clause 4.7 of the AI Acceptable Use Policy prohibits this activity.

But:

Our clients trust us with information that isn't ours to share. Use the company workspace for client work and don't put confidential information into random AI services.

One sounds like compliance.

The other sounds like protecting the business and its customers.

And if necessary, reinforce that with technical controls.

But the first control I'd reach for is still making the safe behaviour the easiest behaviour.

This isn't a one-off exercise

There's one obvious problem with creating an AI inventory.

The moment you've finished it, somebody can discover another AI tool.

That's why the useful part isn't really the spreadsheet.

It's the habit.

When somebody wants to introduce a new AI service, there should be a simple route for saying:

I've found this. Here's what I want to use it for.

Someone can then make a proportionate decision.

For a small business, that decision doesn't necessarily need an AI committee.

It might be the founder.

It might be whoever owns IT or operations.

It might involve whoever is responsible for data protection or security when relevant.

The important thing is that somebody owns the decision.

And periodically, ask the team again.

What's new?

What stopped being useful?

What are people experimenting with?

What has changed?

The objective isn't to produce a perfect inventory that remains accurate forever.

It's to stop your organisation's use of AI becoming invisible again.

Shadow AI is partly a culture problem

Looking back at my own time running a SaaS company, I can see why this matters.

We were a small technology business.

We experimented.

We discovered software.

We changed processes.

We tried things because they might make the product or the company better.

That behaviour is one of the reasons small technology companies can move quickly.

I wouldn't want governance to kill it.

What I've learned since studying management systems and AI governance more formally is that you don't have to choose between experimentation and control.

The answer isn't:

Nobody uses anything until management approves it.

Nor is it:

Everyone use whatever you like and we'll hope for the best.

There's a sensible middle ground.

Experiment.

Tell us what you're experimenting with.

Be careful with information that matters.

Understand when AI can affect somebody else.

Keep humans responsible where they need to be.

And if something proves genuinely useful, let's work out how to use it properly.

That's a culture I'd have been perfectly happy with at Quuu.

I'd just have been much more deliberate about creating it if I'd understood then what I understand now.

Before you govern AI, find it

If you're running an SME and you've never actually asked your staff what AI they're using, don't assume you already know the answer.

And don't begin by sending everyone a policy.

Ask them.

You might discover risks you hadn't considered.

But you might also discover clever uses of AI that are already saving your company time and money.

Both are useful things to know.

Because before you can decide what AI use is acceptable, what needs a risk assessment, what requires stronger controls and what should simply be encouraged, you need a reasonably accurate picture of what's happening.

That's why, for me, the first practical step in AI governance isn't certification.

It isn't a committee.

It isn't even a policy.

It's an inventory.

You can't govern AI you don't know you're using.

About Matthew

Matthew Spurr is a former SaaS founder developing his professional specialism in AI management, governance and responsible adoption. He is undertaking formal professional development across AI management systems, AI risk management, information security and quality management, including the ISO/IEC 42001 family of standards.

Related articles