
Shadow AI is already in your business
Almost half of employees are using unsanctioned AI tools at work, and a third are doing so with confidential data, creating hidden compliance risk for UK SMEs. This article shows decision-makers and compliance managers what the evidence says and what to do about it.


Most UK SME decision-makers assume that if they have not formally rolled out AI, there is no real AI risk to manage. That assumption is reasonable. It is also wrong.
Survey data highlighted this week on LinkedIn shows that 45% of respondents used unsanctioned AI tools in the last 30 days. Of those, 36% did so with confidential data. The tools bypassed every policy and control their employers believed was in place. This is shadow AI, and it is already inside your business whether your board has approved it or not.
This article is for SME decision-makers and compliance managers who want to understand what shadow AI actually means, why the risk is real, and what a proportionate response looks like.
Why this myth feels so convincing
The belief that low official adoption equals low risk is not careless thinking. It follows a logical pattern that has served business leaders well in other contexts.
If a company has not deployed a new system, that system cannot expose data. If staff have not been given access to a tool, they are not using it. These rules hold for most enterprise software, which requires installation, licensing, and IT provisioning.
AI is different. Consumer-grade tools such as ChatGPT, Claude, and Gemini are free to access from any browser on any device. A team member can paste a client contract, a financial summary, or a patient record into a chat window before their first coffee of the morning. No ticket raised. No IT approval. No audit trail.
The same LinkedIn commentary notes that only 16% of UK businesses formally use any AI technology, while 80% are neither using nor planning to use it. Leaders see those figures and reasonably conclude their risk exposure is low. The shadow AI data tells a more complicated story.
What the evidence says about hidden AI use
The gap between official adoption and actual use is the defining feature of the shadow AI problem. Understanding what drives it helps leaders respond effectively rather than reactively.
Staff are not using unsanctioned tools to undermine their employers. They are trying to do their jobs faster. When no approved option exists, capable people find their own way. That behaviour is a signal, not a disciplinary matter.
The compliance implications are nonetheless serious. UK GDPR places responsibility on the data controller for where personal and confidential data goes and how it is processed. The fact that a team member acted without authorisation does not transfer that responsibility away from the organisation. If client data was pasted into a free AI tool whose terms of service allow training on user inputs, the controller may have a breach on their hands regardless of intent.
For regulated sectors, the exposure is sharper. Financial services firms, legal practices, and health-related businesses operate under sector-specific rules that sit on top of UK GDPR. Commentary on EU AI Act compliance notes that governance expectations are tightening across both EU and UK policy frameworks, and that client contracts in B2B settings often carry their own data handling obligations. A single unsanctioned AI interaction involving client data could trigger a contractual breach as well as a regulatory one.
Research published in August 2026 found that three quarters of UK SMEs have no formal AI governance policy. That absence does not prevent staff from using AI. It simply means there are no guardrails in place when they do.
Why compliance managers carry more risk than they realise
Compliance managers in UK SMEs are accustomed to managing known risks. Shadow AI introduces a structural problem: the risk is invisible until something goes wrong.
A data subject access request, a client audit, or an incident investigation can surface AI use that nobody in the business knew about. At that point, the organisation must explain what data was processed, by which tool, under what legal basis, and with what safeguards. If the answer to each of those questions is unknown, the regulatory and reputational consequences can be severe.
Technology podcast commentary recommends that organisations begin with an AI inventory: a record of which tools are in use, by whom, on what data, and at what cost. That inventory does not need to be elaborate. A structured conversation with team leads, combined with a review of browser history or expense claims for AI subscriptions, can surface most of what is in use within a week.
This is not a technology project. It is a process step that compliance managers are well placed to lead.
A realistic approach for time-poor leaders
Addressing shadow AI does not require a large programme. It requires a sequence of proportionate steps taken in the right order.
The first step is visibility. Before writing a policy or choosing an approved tool, a decision-maker needs to know what is already happening. An informal audit across departments, asking specifically about AI use in the last 30 days, will surface the actual picture quickly.
The second step is a short policy update. This does not need to be a comprehensive AI governance framework. It needs to answer three questions for staff: which tools are approved, what categories of data must not go into any AI tool without explicit sign-off, and where to go if they are unsure. A one-page document achieves this.
The third step is to provide an approved alternative. The reason staff use unsanctioned tools is that they are useful. Banning AI without offering a sanctioned option simply drives the behaviour further underground. Providing a configured, approved workspace removes the incentive to go outside it.
SMEs with limited internal resource to run this process may find it practical to use external support. gecco's Quick-Start programme provides structured onboarding over four weeks, covering approved AI tool adoption and the frameworks staff need to use them responsibly. It is one option among several for organisations that want to move from informal AI use to a governed, productive setup.
Honest limitations of what we know
The 45% and 36% figures come from survey data shared via LinkedIn, and the full methodology of the underlying research is not publicly documented in the source material available. Survey data on technology behaviour often overstates or understates the true picture depending on how questions are framed and who responds.
What is consistent across multiple independent sources is the direction of the finding: actual AI use in UK workplaces significantly exceeds formally sanctioned AI use. The precise gap may be smaller or larger than the survey suggests. The existence of the gap is not in serious dispute.
It is also worth noting that not every instance of shadow AI carries the same level of risk. A team member using an AI tool to summarise publicly available news presents a different risk profile from one using it to draft a client proposal that contains commercially sensitive terms. A proportionate response accounts for those differences rather than treating all unsanctioned use as equally serious.
Finally, governance for its own sake achieves little. The goal is not to produce a policy document. It is to ensure that the AI activity happening inside the business is visible, controlled, and aligned with the organisation's obligations to clients, regulators, and staff.
Your next step
If your business has not formally adopted AI but your team members almost certainly have, the AI Readiness survey is the practical first step to understanding where you stand.
Take the AI Readiness survey. You will get access to 65+ free resources and a custom AI Readiness report. We then offer a free 45-minute AI Readiness call to walk through your results.
gecco works with SME decision-makers and compliance managers to formalise AI use through structured onboarding, and the Quick-Start programme is designed to reduce the compliance risk that shadow AI creates while giving staff the approved tools they are already looking for.

Most SMEs have no AI governance policy
Three-quarters of UK SMEs have no formal AI governance policy, leaving teams exposed to data risk and inconsistent use. This article explains what good AI governance looks like in practice and how to build it.

How automated reporting pipelines save SME teams hours each week
Manual reporting is one of the most common time drains in UK SMEs. An automated AI reporting pipeline can replace repetitive data work with a working system in four to six weeks.

