Shadow AI: The Hidden AI in Your Business (And How to Find It Before the Regulator Does)
· By Peter Lowe
Category: Governance
Shadow AI is the biggest unmanaged AI risk in most UK SMEs. A 5-step discovery process to find every tool, build an AI register and close the gap.
Most UK business owners think they know what AI they’re running. They can usually name three or four tools — the website chatbot, ChatGPT for marketing copy, maybe a CV-screening tool in HR, the AI features in their CRM.
Do a proper discovery exercise and the real number is usually several times higher. In our work, three to five times higher is normal.
That gap — between the AI leadership thinks is in use and what actually is — is what people now call shadow AI. It isn’t a technology problem; it’s a governance one. And it’s one of the largest sources of [unmanaged regulatory risk](/insights/ai-compliance-governance-uk-business-owners/) most UK businesses carry, precisely because no one has looked.
This piece is about how to find what you’ve got, what to write down about it, and how to stop new tools slipping through the same gap. It’s a job you can do yourself in about a week.
## Why “I don’t know what we have” is the weakest position
Under UK data protection law, you are the one accountable to the regulator for how a tool is used in your business — not whoever built it. A vendor’s obligations don’t discharge yours. So if a free tool one of your team installed last month is quietly feeding customer data into a model trained overseas, that’s your exposure, not the vendor’s. (If you have EU users, the EU AI Act adds its own duties on both the company that builds a tool and the business that deploys it.)
Recent enforcement makes the point. The Clearview AI ruling confirmed that UK data protection law reaches any AI processing data about people in the UK, wherever the tool was built. And the £14m Capita fine — a security-and-oversight failure, settled in 2025 — is a plain reminder that you’re accountable for what runs inside your business and how well you can account for it. “We didn’t realise that tool used AI” is not a defence the ICO accepts.
## Where shadow AI actually hides
In our experience it shows up in five places, and most businesses have it in all five.
**1. AI features switched on by default in tools you already pay for.** Microsoft 365 Copilot, HubSpot’s AI content and lead scoring, Salesforce Einstein, Zoom’s AI summaries, AI categorisation creeping into your accounting software, CV-ranking inside your applicant tracking system. These usually arrive switched on after an update. Nobody reads the release notes. This is the single largest source.
**2. Free tools staff use without telling anyone.** ChatGPT, Claude, Gemini, Grammarly, Canva’s image generator, Otter.ai for transcripts. Each looks harmless on its own. Together they often handle more sensitive data than your formal systems do. If someone in sales pastes a customer’s email thread into a free AI tool to draft a reply, that’s personal data leaving your business — and it’s yours to account for.
**3. Recent software purchases you didn’t buy “for the AI.”** Anything bought in the last two years probably has AI features now, even if AI wasn’t on the shortlist. The email platform writes the emails. The support tool suggests the replies. The HR system scores engagement. None of it was reviewed for AI risk, because it wasn’t bought as AI.
**4. Tools one department runs that leadership has never heard of.** Marketing stacks, SEO and content tools, finance forecasting tools, a customer-service team’s own AI assistant. Each department head knows their own kit. The MD or FD rarely sees the whole picture.
**5. Tools you’ve stopped using but never switched off.** Old subscriptions, auto-renewed trials, free tools tied to ex-employees’ email addresses. Nobody is watching them, and they may still hold data.
## The five-step discovery
This is the same process we run with clients. It takes about one focused week of management attention.
**1. Talk to every department head.** Thirty minutes each. Ask what software “suggests, scores, automates or generates” — don’t lead with the word “AI,” because most people only associate it with ChatGPT and will under-report.
**2. Audit your subscriptions.** List every SaaS tool you pay for and check each vendor’s site or release notes for AI features. The answer is “yes, added six months ago” more often than you’d expect. While you’re there, check what’s switched on by default.
**3. Surface the shadow AI.** Ask staff directly, with no blame, what AI tools they use on work devices — free ones included. Frame it as building a register to support the tools they find useful, not to ban them. Most people will tell you, especially if there’s a chance you’ll pay for the proper version. It’s also the moment to check your acceptable-use policy covers AI.
**4. Review recent purchases.** Go through software contracts signed in the last two years and flag any where AI wasn’t part of the original decision. Those are the least-managed.
**5. Brief new suppliers from now on.** Add one question to onboarding: “Does your product use AI? If so, how, where, and what data does it touch?” That stops the problem growing from today.
## What to record about each tool
Once you’ve found them, you need a register. It doesn’t need a special platform — a spreadsheet is fine. For each tool, record:
- What it’s called and what it does
- Which department uses it
- Who owns it — a named person, not a job title
- Whether it touches personal data about customers, staff or anyone else
- Whether it makes, or influences, decisions that affect people
- Whether you bought it from a supplier or built it in-house
- When you last checked it was being used appropriately
Keep the register somewhere central and review it every three months. Add new tools as they arrive.
## What good looks like after 90 days
By the end of one focused quarter, a business that takes shadow AI seriously has: a complete register with a named owner per tool; a clear view of which tools are high, medium or low risk (our companion piece on [risk classification](/insights/ai-risk-classification-3-question-test/) covers how to sort them); an acceptable-use policy staff have actually read; a standard AI question built into supplier onboarding; and a quarterly rhythm for keeping the register current. That is not a transformation programme. It is a few weeks of work that closes the single biggest gap most UK businesses are carrying right now.
## The honest bit about what you’ll find
Every discovery exercise we run turns up at least one tool that needs switching off, retraining or replacing — a free tool processing customer data outside the UK, an AI feature inside a paid platform doing something nobody authorised, a well-meaning workaround with no oversight. That isn’t a failure. It’s the point. You can’t fix what you can’t see, and the discovery is what makes everything else possible.
## Where to start this week
Pick one department — usually marketing or HR — and ask the head the four-word question: what suggests, scores, automates or generates? You’ll have a starter list within the hour. Every department after that is easier.
If you’d rather have someone run the exercise with you — usually two to three half-day sessions, ending with a complete register, a risk rating for every tool, and a short set of recommendations — that’s a [discovery engagement](/services/ai-readiness-assessment/) we run at Smart AI Studio. It’s also the natural first step before the [AI governance workshop](/workshops/), which is led by an AI governance expert and scheduled around their availability. [Book a call with Peter](/contact/) and we’ll talk through what your business needs.
## Frequently asked questions
### What is shadow AI?
Shadow AI is any AI tool used in your business without leadership’s knowledge or oversight — free chatbots, AI features inside paid platforms, or staff workarounds. The risk is that it processes company or customer data with no one accountable for it.
### Why is shadow AI a compliance risk?
Because you cannot govern what you cannot see. Shadow AI often moves personal data outside the UK, sits outside your [data protection records](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/), and has no human oversight — exactly the gaps regulators focus on.
### How do I find shadow AI in my business?
Go department by department and ask one question: what suggests, scores, automates or generates? Start with marketing and HR, build a register of every tool, then rate each for risk. Most businesses find three to five times more AI in use than leadership expected.
*Smart AI Studio works with UK business owners and leadership teams on practical AI adoption, including compliance, governance and risk. This article reflects the regulatory position as of July 2026 and is general guidance, not legal advice. AI regulation and enforcement are moving quickly, so check the current position before acting. For specific compliance questions, consult a qualified solicitor or data protection specialist.*
This article was written by Peter Lowe. The ideas and opinions are his own; AI was used to assist with drafting and editing.