The foundation: engage.re
AI Governance 30 July 2026 9 min read

Shadow AI: Two in Three Staff Already Do This

Close to two in three staff use public AI tools at work, and most organisations hold no policy that covers it. A ban is the usual first response, and a ban fails for a reason worth understanding. Four conditions produce the behaviour, and three of the four are your own. This article names them, and lists the four records that turn an unknown exposure into a countable one.

Connect with us about safe AI use · · Replies within 24 hours

2 in 3
staff report using public AI tools at work
54%
of UK SMEs used AI in 2026, up from 35% in 2025
4
records that make the exposure countable

What is shadow AI?

Shadow AI is the use of AI tools at work without approval, oversight or a record. A member of staff pastes a document into a public chat tool to summarise it, and no policy covers the action.

The behaviour follows the same pattern as shadow IT, and the National Cyber Security Centre's shadow IT guidance describes it. Staff adopt a tool because it solves a problem the approved tools do not.

The NCSC also published a specific assessment in ChatGPT and large language models: what is the risk?

Why do staff use unapproved AI tools?

Four conditions produce the behaviour, and you control three of them.

  1. The task is slow. A person spends an hour summarising a report, and a tool does it in a minute.
  2. The approved tools do not do it. Your systems hold the data and offer no way to ask a question of it.
  3. The rule is unclear. No policy names the tool, so the person applies judgement.
  4. The tool is free and immediate. This is the condition you do not control.
A ban addresses the third condition only. The task stays slow, your systems still cannot answer the question, and the tool remains a browser tab away. A ban therefore moves the behaviour off your network rather than ending it.

What is the actual exposure?

Three risks, and they differ in kind.

  • Disclosure. Personal or confidential data leaves your control, and you cannot say which records went.
  • Unrecorded reliance. A decision rests on an output nobody kept, so you cannot reconstruct the reasoning.
  • Unattributed action. An output enters a record with no note of its origin, and it then reads as staff work.

The ICO's guidance on AI and data protection applies to all three. The duty sits on your organisation, whether or not the tool was approved.

The second and third risks receive less attention than the first, and they last longer. A disclosure is an event, and an unrecorded decision is a permanent gap in a record.

How large is the pattern?

Adoption is already broad. The Office for National Statistics reports UK SME AI use at 54% in 2026, up from 35% the year before, in its 2023 to 2026 series.

Organisational adoption and individual use are separate figures, and the second is larger. Staff adopted these tools faster than organisations wrote policies for them.

The Cyber Security Breaches Survey shows how much UK organisations still lack basic controls, and a new class of tool arrived on top of that position.

The four records

An exposure you cannot count is an exposure you cannot manage. Four records make it countable.

Record The question it answers
Approved toolsWhich tools may staff use, by name?
Permitted dataWhich categories of data may go into each one?
Use logWhich staff used which tool, and when?
Origin markingWhich content in your records came from a model?

The fourth record is the one almost nobody keeps, and it decides whether your case notes remain evidence. A note that a model drafted, held with no marking, is indistinguishable from a note a person wrote.

What works instead of a ban?

Address the first two conditions, because they produce the behaviour.

  • Name the approved tool. One named tool with a stated data boundary removes the judgement call.
  • Make the approved route faster. Staff choose the quickest path, so the approved path must be the quickest.
  • Let your systems answer questions. The pasted document exists because your systems hold data and answer nothing.
  • Mark the origin automatically. A person will not remember to label a draft, and a system can.

The NCSC's machine learning security principles cover the technical controls that sit around this.

What ESRE Media offers

We build your system on engage.re, and four of its properties bear on shadow AI.

  • Your systems can answer questions. Your records carry declared meaning, so a model can query them correctly. The reason for pasting a document into a public tool is removed.
  • Every access is recorded. Each read and write is an event in a signed chain, so a use log exists without anybody maintaining one.
  • Origin is data. A record written by an agent carries that agent's identity, so model-generated content is distinguishable from staff work.
  • Permission is narrow. An approved tool receives a grant for one action on one scope, and the grant is cancellable on the next call.

Sense Future built engage.re, and it has run in production since December 2025.

The same behaviour at two sizes

A council writes a policy that prohibits public AI tools, and it holds no way to detect use. Officers keep summarising long reports, because the alternative is an hour each time. The council now holds a policy it cannot enforce, and it has lost the ability to ask staff what they use.

A care home group has no policy at all. A senior carer drafts family updates in a public tool, using resident details. Three homes rather than thirty services, and special category health data instead of case files.

The care home software and school software pages set out the sector detail. Our guides to safeguarding records under KCSIE and family portals for care homes cover the records that must stay attributable.

What we do not claim

  • Better systems do not remove all shadow use. Some staff will prefer a familiar tool whatever you provide.
  • A policy still matters. It is necessary, and it is not sufficient on its own.
  • The two-in-three figure comes from self-reported surveys, and methods vary. Treat it as an order of magnitude rather than a precise measure.

What to do next

  1. Ask your team which tools they use, and ask without a threat attached. The answers are your baseline.
  2. Name one approved tool this month, with a stated data boundary.
  3. Find the slowest recurring task in your week. That task is where shadow use starts.
  4. Check whether any record in your systems shows that a model wrote it.
  5. Then decide whether the approved route is the fastest route. Where it is not, the behaviour continues.

Common questions

What is shadow AI?

The use of AI tools at work without approval, oversight or a record. A member of staff pastes a document into a public chat tool to summarise it, and no policy covers the action. The pattern matches shadow IT: staff adopt a tool because it solves a problem the approved tools do not.

How many staff use AI tools without approval?

Close to two in three, on self-reported survey figures. Organisational adoption is a separate and lower figure. The Office for National Statistics puts UK SME AI use at 54% in 2026, up from 35% the year before, and individual use runs ahead of organisational policy.

Why does banning AI tools not work?

Because a ban addresses one of the four conditions that produce the behaviour. The task stays slow, your systems still cannot answer the question, and the tool remains a browser tab away. A ban moves the behaviour off your network rather than ending it, and it removes your ability to ask staff what they use.

What are the risks of shadow AI?

Three. Disclosure, where data leaves your control and you cannot say which records went. Unrecorded reliance, where a decision rests on an output nobody kept. Unattributed action, where model output enters a record with no note of its origin and then reads as staff work. The second and third last longer than the first.

What records should we keep?

Four. A list of approved tools by name. A statement of which data categories may go into each one. A log of which staff used which tool and when. A marking of which content in your records came from a model. The fourth is the one almost nobody keeps, and it decides whether your case notes remain evidence.

What does ESRE Media build?

We build your system on engage.re. Your records carry declared meaning, so a model can query them directly and the reason for pasting a document elsewhere goes away. Every access is an event in a signed chain, a record written by an agent carries that agent's identity, and an approved tool holds a narrow grant you can cancel on the next call.

Connect with us about safe AI use · · Replies within 24 hours

Sources and further reading