Skip to content
Under attack?Get emergency help now
All articles
28 September 2026F1 IT Solutions

Shadow AI: When Staff Paste Company Data Into Public AI Tools

AICybersecurityMicrosoft 365Data ProtectionManaged IT

Ask most business owners whether their staff use AI tools at work and the honest answer is usually "probably, but I'm not sure how." That gap between what leadership assumes and what actually happens on employees' laptops has a name now: shadow AI. It is shadow IT's newer, faster-moving cousin, and it deserves a place on the same risk register.

Why this is suddenly everyone's problem

A few years ago, shadow IT meant a marketing team signing up for a file-sharing tool without telling anyone. Shadow AI is quicker to start and much harder to see. There is no software to install and often no approval screen to click past. An employee opens a free AI chatbot in a browser tab, pastes in a contract, a spreadsheet of client details or a chunk of source code, and asks for a summary or a rewrite. The whole exchange takes thirty seconds and leaves no trace on the company network.

Multiply that by every person in the business who has discovered how useful these tools are for drafting emails, summarising meetings or tidying up a proposal, and you have a steady, invisible flow of company and client data leaving the building every day.

What actually leaves with it

The risk is not that AI itself is dangerous. It is that free, personal-account AI tools were never built with a business's confidentiality obligations in mind. Depending on the tool and the account type, inputs can be retained, used to improve the underlying model, or simply sit on a server outside the country and outside any agreement your business has signed. None of that is unique to any one vendor, and enterprise-tier agreements from the major AI providers do offer proper data handling terms. The problem is that most shadow AI use happens on the free, personal tier, where those protections either do not apply or were never checked.

For a business handling client records, health information, financial data or anything covered by POPIA or GDPR, that is a real compliance exposure, not just an untidy habit. A single pasted client list or a contract with a confidentiality clause is enough to turn a productivity shortcut into a breach notification.

Bringing it into the open, not shutting it down

Banning AI tools outright rarely works, and it is not the right goal anyway. Staff use these tools because they genuinely help, and a flat ban just pushes the behaviour further out of sight. A better approach treats shadow AI the way good security awareness training treats any risky shortcut: understand why people reach for it, then make the safe option the easy one.

Start by finding out what is already happening

You cannot govern what you cannot see. Microsoft 365 tenants already generate signals worth reviewing: browser and network logs show which AI domains staff visit, and Microsoft's own Purview data security posture management tools for AI are built specifically to surface where sensitive data is heading toward AI apps, sanctioned or not. This is a discovery exercise, not a witch hunt. The point is a realistic picture of current use.

Give people a sanctioned alternative

Once you know what staff are trying to achieve, whether that is drafting, summarising or coding help, look at putting a proper enterprise AI tool in front of them under your own tenant, with data handling terms your business controls. Our AI solutions work often starts exactly here: identifying what a team actually needs an AI assistant to do, then deploying it inside a governed environment rather than leaving people to find their own way there.

Write a short, usable policy

A one-page policy that says what can and cannot go into an AI tool, and which tools are approved, beats a long document nobody reads. Cover client data, personal information, source code and anything under an NDA. Make it part of onboarding, not a one-off memo.

Keep watching, not just once

Shadow AI use changes as new tools launch and old habits creep back. Treat this the same way you would treat any other control inside your cybersecurity programme: something to review on a schedule, not a project you finish and file away.

A sensible middle ground

The businesses handling this well are not the ones pretending AI tools do not exist on their network. They are the ones who found out where they were already being used, gave staff a safer sanctioned option, and set plain rules for what does not belong in a chat box. That is a far more workable outcome than either ignoring the problem or trying to lock it down completely, and it tends to leave staff more productive, not less.

If you are not sure what is already leaving your business through an AI tool nobody signed off on, that is worth finding out before a client or a regulator finds out for you.

Want this handled for you?

Talk to the F1 team about cybersecurity, AI and managed IT for your business.