arrow_back Back to Insights AI GOVERNANCE

Shadow AI: How to Find Out What Your Staff Are Actually Using

August 2026 8 min read

Most UK businesses have an AI strategy meeting scheduled for next quarter. Almost all of them already have AI running through the business today — they just don’t know which tools, on whose data, under whose terms.

Microsoft’s UK research, conducted by Censuswide across 2,003 employees, found that 71% of UK workers have used unapproved consumer AI tools at work, and 51% still do so every week. Separate research published by SAP and Oxford Economics in February 2026 put it from the employer’s side: 68% of UK businesses say staff regularly use AI tools the organisation hasn’t approved. This is shadow AI, and unlike classic shadow IT it isn’t a rogue file-sharing account — it’s a data-rich conversation in which somebody pastes a contract, a customer list, or a set of management accounts into a service nobody has assessed.

The uncomfortable part is who’s doing it. A TrustedTech survey of 2,000 UK and US employees in March 2026 found 62% of UK senior leaders use unapproved AI tools, against 31% of staff below decision-maker level — while 51% of those same leaders said they were worried about employees doing exactly that. The people with the broadest access to sensitive systems are the heaviest users of the tools nobody has vetted.

Here is how to deal with it properly, in four steps, without pretending you can ban your way out.

First, be honest about what the risk actually is

Shadow AI is rarely a malicious-insider story. It’s a productivity story with governance consequences, and the consequences are specific:

Worth holding onto alongside that: the same Microsoft research estimated UK employees are saving around 12 billion hours a year using these tools. The demand is real and it is not going away. The job is to redirect it, not suppress it.

Step 1 — Discover what’s actually in use

You cannot govern what you can’t see, and asking department heads what their teams use produces a flattering, wrong answer. Use four sources together.

Network and endpoint discovery

If you’re on Microsoft 365 with the right licensing, Defender for Cloud Apps is the fastest route. Point it at your firewall or endpoint traffic logs and it matches observed activity against a catalogue of well over a thousand generative AI apps, each carrying a risk score from 0 to 10 across general, security, compliance and legal factors — where the vendor stores data, whether prompts feed training, which certifications exist, what happens on account deletion. Within days you have a ranked list of what your people actually use, with volumes attached.

Entra ID enterprise applications

Check which third-party apps hold OAuth consent against work identities, and what scopes they were granted. This is where you find the meeting-notes bot with read access to every calendar in the business. Sign-in logs will show you which AI services staff have authenticated to with corporate credentials even when the traffic itself never crossed your network.

Expenses and card statements

Individually expensed £15–£25 monthly subscriptions are the classic blind spot. Search the last six months of claims for the obvious vendor names, then for anything that looks like a monthly SaaS charge nobody in IT recognises.

Just ask — with an amnesty

Run a short anonymous survey: which AI tools do you use for work, what for, and what would you lose if it were switched off tomorrow. Say plainly that nobody is in trouble. Technical discovery finds tools on managed devices; the survey is the only thing that finds the ones running on personal phones, which is a large share of the problem. It also hands you a ready-made requirements list for step 3.

Step 2 — Score the tools against criteria, not vibes

The instinct is to publish an approved list. The better move is to publish the criteria, then apply them — because a fixed list is out of date within a month, while criteria survive contact with a market that ships new tools weekly.

Data handling: are inputs used to train models by default? Can that be switched off contractually, not just in a settings toggle?

Retention & deletion: how long is prompt data kept, and what actually happens on account closure?

Residency: where is data processed and stored, and does that satisfy your client contracts?

Contracts: is there a data processing agreement you can sign, and does the vendor commit to breach notification?

Assurance: ISO 27001, SOC 2, or equivalent — and admin controls, logging, and SSO on the tier you’d actually buy.

Score each discovered tool against those five, then sort into three buckets: approved, approved for non-sensitive work only, and blocked. The middle bucket matters more than people expect — it lets you say yes to a genuinely useful tool for marketing copy while keeping client data away from it. We set out the fuller version of this in our AI governance framework for SMEs.

Step 3 — Give people a sanctioned alternative

This is the step organisations skip, and it’s why blocking fails. Microsoft found 28% of employees use unapproved tools purely because their employer provides no approved option, and 41% because they already use them at home. Block without substituting and the same activity moves to a personal phone, where your visibility drops to zero and your exposure stays exactly the same.

So decide what the sanctioned path is before you enforce anything. For most UK SMEs that’s some combination of an enterprise-tier assistant for general work, and purpose-built internal tools for the two or three workflows where the volume justifies building something. Which way you lean depends on whether your bottleneck is broad individual productivity or one heavy repeated process — the trade-off we cover in Copilot vs custom AI tools. Then tell people, in plain language, what they are allowed to use and for what. Six in ten UK businesses report their staff have had no comprehensive AI training; a thirty-minute session on what not to paste into a chatbot is the cheapest control you will ever deploy.

Step 4 — Put technical controls behind the policy

A policy nobody can enforce is a document, not a control. In a Microsoft 365 tenant the practical layers are:

  1. Unsanction in Defender for Cloud Apps and push the block to your firewall or Defender for Endpoint, so tools that failed step 2 stop resolving on managed devices.
  2. Purview DLP policies that inspect what users paste into browser sessions with generative AI sites, blocking or warning on sensitive types — card numbers, NI numbers, client identifiers, source code.
  3. Entra ID app consent policies so users can no longer grant mailbox or file access to arbitrary third-party AI apps without admin review, plus a one-off audit revoking the grants you found in step 1.
  4. Sensitivity labels on your genuinely confidential material, so the DLP rules have something reliable to key off.
  5. Review cadence — a standing quarterly look at the discovery report. Shadow AI is not a project you finish; new tools appear continuously.

None of this requires enterprise-scale budget. Most of it is already sitting in a Business Premium or E5 tenant, unconfigured. If you want the M365-specific detail, that’s the ground our Microsoft 365 AI consultancy work covers.

The regulatory clock is now running

One development that changes the calculus this month: the EU AI Act’s Article 50 transparency obligations became applicable on 2 August 2026. They require that people are told when they’re interacting with an AI system rather than a human, and that AI-generated or manipulated audio, images, video and text be marked in a machine-readable, detectable format. Non-compliance carries fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher; systems already on the EEA market before that date have until 2 December 2026 to comply.

The UK has no equivalent statute and no immediate plans for one. But a UK business whose chatbot serves EU customers, or whose AI-assisted content reaches EU users, is in scope regardless of where it’s registered — and you cannot make a transparency declaration about systems you don’t know you’re running. Discovery isn’t just hygiene any more; it’s the prerequisite for the compliance statement.

What to do in the next two weeks

If you do nothing else: turn on cloud app discovery and get one report; audit Entra ID third-party app consents and revoke anything unrecognised; run the anonymous survey; and publish a one-page interim rule covering what must never be pasted into a public AI tool. That is a fortnight’s work and it converts an unknown into a managed list.

The organisations that come out of this well won’t be the ones that banned the most tools. They’ll be the ones that found out what people were actually doing, worked out why, and gave them a better-governed way to keep doing it. If you want a starting point for the policy itself, our free UK AI usage policy template is written for exactly this situation.

FAQ

Shadow AI is the use of AI tools inside a business without IT approval or oversight — typically free consumer chatbots, browser extensions, meeting-note takers, and image or code generators that staff sign up for with a work email or a personal account. It is the AI-specific version of shadow IT, and it matters more because the interaction is data-rich: people paste contracts, customer records, financials, and source code into a service whose retention, training, and jurisdiction terms nobody has read. Microsoft research conducted by Censuswide in October 2025 found 71% of UK employees have used unapproved consumer AI tools at work and 51% still do so every week.
Use four sources together. First, network and endpoint discovery: Microsoft Defender for Cloud Apps ingests firewall or endpoint traffic logs and matches them against a catalogue of over a thousand generative AI apps, each scored 0 to 10 on security, compliance and legal factors. Second, Entra ID enterprise applications and sign-in logs, which show any AI service staff have authorised against their work identity — often with read access to mail or files. Third, expense claims and card statements, which surface individually expensed subscriptions. Fourth, simply ask, via an anonymous survey with an amnesty attached. Technical discovery finds tools on managed devices; the survey finds the ones on personal phones.
Blocking alone reliably fails. Microsoft’s UK research found 28% of employees use unapproved tools specifically because their employer offers no approved alternative, and 41% because they already use them personally — so a block without a substitute pushes the same activity onto personal phones where you have no visibility at all. The workable approach is criteria-led: publish the standards a tool must meet (data not used for training, defined retention, tenant or enterprise controls, a signed data processing agreement, appropriate residency), approve the tools that meet them, block the ones that clearly don’t, and keep a route for staff to request assessment of something new.
It can be both. Under UK GDPR you remain the controller for personal data your staff paste into a third-party AI service, which means you need a lawful basis, a processor agreement, a record of processing, and a handle on international transfers — none of which exist for a tool IT has never seen. Separately, the EU AI Act’s Article 50 transparency obligations became applicable on 2 August 2026, requiring people to be told when they are interacting with an AI system and requiring AI-generated content such as synthetic audio, images, video and text to be machine-readably marked, with non-compliance carrying fines up to €15 million or 3% of worldwide annual turnover. The UK has no equivalent statute, but any UK firm whose AI-touched output reaches EU users is in scope.

Want to know what’s really running in your tenant?

We run shadow AI discovery for UK SMEs — a clear report of which AI tools your people actually use, scored against criteria you can defend, with the Microsoft 365 controls configured to match. Get in touch or book a 30-minute call — no sales theatre.

Book a Free Discovery Call