
Your Team Is Using AI Every Day. You Don't Know What They're Feeding It.
Your Team Is Using AI Every Day. You Don't Know What They're Feeding It.
I was revoking an old employee's access for a client - a routine handover task - when I opened their browser to find a Gemini chat still sitting open.
Full client names. Active project details. Internal business problems typed out in plain language, sent directly to a public AI tool. The employee hadn't done it with bad intent. They were just trying to get help faster. Nobody had told them this was a problem.
That was the first time I saw shadow AI up close. It wasn't the last.
A few weeks later, a different client. A team member had asked an AI assistant to automate a task between their CMS and CRM. The AI said it needed access and context. So the employee pasted the API endpoints directly into the chat. Credentials. Architecture. The keys to the system - dropped into a public tool because the AI asked for them and nobody said not to.
Both situations were completely invisible to management. Neither company had a policy about it. Both thought they were just "using AI to save time."
What Shadow AI Actually Is
You've probably heard about shadow IT - employees using personal apps and devices that IT never approved. Shadow AI is the same thing, but faster, more widespread, and harder to see.
It's the support agent pasting a customer complaint into ChatGPT to draft a reply. The developer debugging code in a public AI tool while the codebase contains proprietary logic and API keys. The finance analyst uploading a quarterly forecast to summarize it faster. The HR manager putting candidate CVs through an AI screener because the approved system is slower.
None of them are being malicious. They're being efficient. And the productivity gains are real - 60% of employees say AI helps them work faster, 57% say it makes their job easier. The problem isn't that people are using AI. The problem is what they're putting into it and where it's going.
One enterprise survey found that 68% of employees who use AI at work do so through personal accounts - meaning no admin visibility, no logging, no control. Another found that 57% admit to entering sensitive or high-risk information into public AI tools. And 79% of IT leaders reported negative outcomes from this, including false answers and sensitive data leakage. Thirteen percent said it led to financial, customer, or reputational damage.
Thirteen percent is not a fringe number. That's roughly 1 in 8 companies already reporting real harm.
Why Nobody Noticed Until Now
The productivity benefit is immediate. The risk is invisible until something goes wrong.
When a team finishes a deck 40% faster because someone used AI to draft the slides, the manager celebrates. Nobody asks what the AI was fed to get there. Nobody checks whether the pricing data, client names, or product roadmap from the brief ended up in a public system.
There's also a perception problem. Most employees don't think of pasting text into an AI as "sending data somewhere." They think of it the same way they'd think of using a spell-checker. But a spell-checker doesn't retain your input, learn from it, or operate under terms of service that let the provider process your data for purposes you haven't read.
When you paste a customer record, a contract clause, or a source code file into a public AI, that information leaves your environment. Where it goes after depends on the tool, the account type, the provider's terms, and whether anyone at your company ever asked those questions - which, in most cases, they didn't.
The Leak Paths Are Ordinary
This isn't about rogue employees or sophisticated attacks. The most common entry points are the most mundane:
Customer support - agents use AI to write faster replies but paste in ticket histories containing names, account numbers, and internal notes.
Marketing - teams use AI to generate campaigns but upload briefs containing pricing strategy, customer segmentation data, and competitor analysis.
Software development - developers use AI to write or debug code and paste in proprietary source code, internal architecture, or actual credentials.
Finance and operations - analysts summarize reports using AI but the reports contain revenue figures, cost structures, and acquisition plans.
HR - teams screen CVs through AI tools, which creates privacy exposure and, in Europe, potential GDPR liability around candidate data.
Each of these looks like a time-saving choice. Together, they form a data channel your company didn't choose to open.
The $25 Million Warning
In 2024, the engineering firm Arup lost $25 million in a single incident. A finance employee received a video call request that appeared to involve the company's CFO and several other colleagues. The faces were real. The voices were real. The instruction was to authorize a transfer. He did.
None of it was real. The call was entirely AI-generated - deepfake video and voice, assembled to impersonate executives convincingly enough that a trained professional didn't question it.
Arup is a global firm with resources most SMEs don't have. The attack didn't require hacking any system. It only required manufacturing trust - and AI now makes that cheaper and more convincing than ever.
For business owners, the lesson isn't only about direct financial fraud. It's that AI is now a tool for attacks on normal business processes: finance approvals, executive communication, vendor verification, contract authorization. If your team relies on "the face on the screen" or "the voice on the call" as a verification step, that assumption is no longer safe.
How Europe and South Asia Experience This Differently
The risk is real in both regions, but the pressure to act comes from different directions.
In Europe, the regulatory environment is accelerating fast. The EU AI Act is now in force, with governance obligations for general-purpose AI models already applicable from August 2025. Combined with GDPR, European companies face a situation where shadow AI use can simultaneously create privacy breaches, compliance failures, and AI Act violations. A bank employee drafting a customer complaint response using a public chatbot - where the prompt includes account details and case notes - may be creating a reportable incident before the reply is even sent.
In South Asia, the dynamic is different. Adoption is fast. Governance is often not. In India, Bangladesh, Nepal, and neighboring markets, AI is in heavy use across IT services, outsourced operations, fintech, and customer support - but many of the firms using it lack formal AI policies, approved tooling, or training on data handling. The risk often surfaces first as a client-trust issue: a BPO team summarizes a support transcript using a public AI tool, the transcript contains personal data, the foreign client finds out, and the business relationship breaks.
Regulation will eventually reach these markets too. The firms that build governance ahead of that curve will be significantly better positioned than the ones scrambling to patch it when a client or regulator forces the issue.
What the Vendors Are Saying - And What They're Not Saying
OpenAI states that business data processed through ChatGPT Enterprise, ChatGPT Team, and the API is not used for model training by default, and that enterprise accounts include configurable retention and encryption controls. Microsoft positions Microsoft 365 Copilot around existing identity boundaries, sensitivity labels, and compliance frameworks. Google makes similar claims about Gemini in Google Workspace.
Their argument, broadly, is: the problem isn't AI - it's unmanaged AI. Switch to enterprise tools and most of the risk goes away.
That argument is half right.
Enterprise tools do reduce the risk of data leaving through the AI provider's system. What they don't fix is the human behavior underneath. Surveys consistently show that employees continue using personal accounts even when enterprise tools are available, because the personal account is faster, already open in their browser, or not blocked. And even within enterprise AI systems, companies still need policies on what data can be entered, who reviews the outputs, and how AI-generated decisions get checked before they create liability.
The vendor sells the controlled environment. The company still has to build the controls.
What a Real Response Looks Like
A functional response to shadow AI has three layers: what the rules are, what the tools are, and whether anyone is actually following either.
Policy means writing down what data can never go into an AI tool - customer records, source code, financial projections, active contracts, credentials, anything covered by client confidentiality - and making sure employees know what that list covers and why.
Tooling means giving employees approved AI access so they're not pushed toward personal accounts by default. If the approved system is slower, harder to access, or blocked behind too many steps, employees will route around it. The tool has to be the path of least resistance, not an obstacle. (Curious what secure, approved systems look like? Check out the tech stack I use in my marketing and RevOps toolkit).
Monitoring means knowing what's happening. AI discovery tools, data-loss prevention systems, and access audits are not about distrust - they're about visibility. You can't govern what you can't see.
The practical starting list:
- Write a clear acceptable-use policy with specific examples of prohibited data types. Not just "don't share sensitive information" - that's vague enough to mean nothing. Name what's off-limits.
- Provide enterprise AI tools and make them the default, not an option employees have to request.
- Train staff regularly. Not a one-hour session at onboarding. Quarterly. With real examples, not policy abstracts.
- Implement data-loss prevention and auditing tools that surface shadow AI use before it becomes an incident.
- Treat AI governance as an ongoing process, not a one-time memo. The tools change. The risk changes. The rules need to keep up.
A Simple Test for Where You Are Right Now
Ask yourself three questions:
Do you know which AI tools your team is using today?
Do you know what data they're putting into those tools?
If an employee left tomorrow, would you know whether they'd shared any confidential information with an AI system you don't control?
If you can't answer all three, you have a shadow AI problem. It may not have caused visible damage yet. That's different from not existing.
The biggest AI risk in most businesses isn't a hallucination or a bad output. It's employees using AI faster than the company can govern it.
The gap between "using AI" and "managing AI" is where most of the real damage happens - and right now, most businesses are sitting firmly in that gap.
If you want to understand where your business actually stands on this - what's already exposed, what needs a policy, and what tools would close the gap - I do infrastructure and RevOps audits. You can reach me there, or send me a message directly on LinkedIn.
Enjoyed this case study?
Share it with your colleagues and network.
Get the next breakdown
Paid ad campaigns and marketing systems, taken apart in detail. No spam, unsubscribe anytime.
