Close to two in three staff use public AI tools at work, and most organisations hold no policy that covers it. A ban is the usual first response, and a ban fails for a reason worth understanding. Four conditions produce the behaviour, and three of the four are your own. This article names them, and lists the four records that turn an unknown exposure into a countable one.
Connect with us about safe AI use · · Replies within 24 hours
Shadow AI is the use of AI tools at work without approval, oversight or a record. A member of staff pastes a document into a public chat tool to summarise it, and no policy covers the action.
The behaviour follows the same pattern as shadow IT, and the National Cyber Security Centre's shadow IT guidance describes it. Staff adopt a tool because it solves a problem the approved tools do not.
The NCSC also published a specific assessment in ChatGPT and large language models: what is the risk?
Four conditions produce the behaviour, and you control three of them.
Three risks, and they differ in kind.
The ICO's guidance on AI and data protection applies to all three. The duty sits on your organisation, whether or not the tool was approved.
The second and third risks receive less attention than the first, and they last longer. A disclosure is an event, and an unrecorded decision is a permanent gap in a record.
Adoption is already broad. The Office for National Statistics reports UK SME AI use at 54% in 2026, up from 35% the year before, in its 2023 to 2026 series.
Organisational adoption and individual use are separate figures, and the second is larger. Staff adopted these tools faster than organisations wrote policies for them.
The Cyber Security Breaches Survey shows how much UK organisations still lack basic controls, and a new class of tool arrived on top of that position.
An exposure you cannot count is an exposure you cannot manage. Four records make it countable.
| Record | The question it answers |
|---|---|
| Approved tools | Which tools may staff use, by name? |
| Permitted data | Which categories of data may go into each one? |
| Use log | Which staff used which tool, and when? |
| Origin marking | Which content in your records came from a model? |
The fourth record is the one almost nobody keeps, and it decides whether your case notes remain evidence. A note that a model drafted, held with no marking, is indistinguishable from a note a person wrote.
Address the first two conditions, because they produce the behaviour.
The NCSC's machine learning security principles cover the technical controls that sit around this.
We build your system on engage.re, and four of its properties bear on shadow AI.
Sense Future built engage.re, and it has run in production since December 2025.
A council writes a policy that prohibits public AI tools, and it holds no way to detect use. Officers keep summarising long reports, because the alternative is an hour each time. The council now holds a policy it cannot enforce, and it has lost the ability to ask staff what they use.
A care home group has no policy at all. A senior carer drafts family updates in a public tool, using resident details. Three homes rather than thirty services, and special category health data instead of case files.
The care home software and school software pages set out the sector detail. Our guides to safeguarding records under KCSIE and family portals for care homes cover the records that must stay attributable.
The use of AI tools at work without approval, oversight or a record. A member of staff pastes a document into a public chat tool to summarise it, and no policy covers the action. The pattern matches shadow IT: staff adopt a tool because it solves a problem the approved tools do not.
Close to two in three, on self-reported survey figures. Organisational adoption is a separate and lower figure. The Office for National Statistics puts UK SME AI use at 54% in 2026, up from 35% the year before, and individual use runs ahead of organisational policy.
Because a ban addresses one of the four conditions that produce the behaviour. The task stays slow, your systems still cannot answer the question, and the tool remains a browser tab away. A ban moves the behaviour off your network rather than ending it, and it removes your ability to ask staff what they use.
Three. Disclosure, where data leaves your control and you cannot say which records went. Unrecorded reliance, where a decision rests on an output nobody kept. Unattributed action, where model output enters a record with no note of its origin and then reads as staff work. The second and third last longer than the first.
Four. A list of approved tools by name. A statement of which data categories may go into each one. A log of which staff used which tool and when. A marking of which content in your records came from a model. The fourth is the one almost nobody keeps, and it decides whether your case notes remain evidence.
We build your system on engage.re. Your records carry declared meaning, so a model can query them directly and the reason for pasting a document elsewhere goes away. Every access is an event in a signed chain, a record written by an agent carries that agent's identity, and an approved tool holds a narrow grant you can cancel on the next call.
Connect with us about safe AI use · · Replies within 24 hours