
Emma Challinor
Chief Creative Officer
September 18, 2026

Most business owners know they need to keep an eye on company laptops, email accounts and file access.
But there is a newer problem now.
AI tools.
Not the approved ones. Not the tools that have been checked, set up properly and explained to the team.
The risky bit is the AI your business does not know about.
That is shadow AI.
It is when staff start using AI tools without anyone really knowing which tool they are using, what information they are putting into it, or where that information goes.
Most of the time, it is not done with bad intent.
Someone is busy. They need to write an email, summarise a document, tidy up some notes or get a quick answer. They find a free AI tool, paste the information in and get the job done faster.
On the surface, that sounds useful.
The problem is what might have gone into that tool.
AI only becomes a business risk when it starts touching business data.
That could be:
If that information is copied into an AI tool the business has not approved, you may have no clear view of what happened next.
Was the data stored? Was it used for training? Who can access it? Is it covered by the right terms? Can it be deleted later?
Those are not questions you want to be asking after the fact.
Shadow AI is not really a brand-new behaviour.
It is the modern version of staff using personal Dropbox, WhatsApp, Gmail or USB sticks because it felt quicker than the approved way.
The intent is usually simple: “I just needed to get it done.”
But the risk is still real.
The business loses control of where information lives. The audit trail disappears. Sensitive data ends up outside approved systems. IT cannot protect what it cannot see.
AI makes that problem easier to create because the tools are so quick and tempting.
Paste it in. Get an answer. Move on.
That is exactly why businesses need to talk about it before it becomes normal.
Microsoft has been building more security controls around AI agents and unmanaged AI tools.
That tells you something.
This is not a theoretical risk. The big platforms are already expecting businesses to need visibility, control and policies around AI use.
Microsoft Defender and Agent 365 updates are aimed at helping organisations discover and manage AI agents across devices and cloud services. In plain English, that means businesses need to know what AI tools are being used and put sensible controls around them.
That matters for smaller businesses too.
You do not need to be a huge company to have confidential information. A ten-person business can still have payroll data, client contracts, supplier agreements and commercially sensitive emails.
The answer is not “ban AI”.
That probably will not work anyway.
The better answer is to give people a safe way to use it.
Start with a few plain rules.
A good AI usage policy does not need to be 20 pages long.
In fact, it is probably better if it is not.
For most teams, a simple version is enough:
That is a much better start than pretending nobody is using AI.
Because they probably are.
AI can be useful. We are not against it.
But it needs the same sensible thinking as any other business technology.
Who has access? What data is involved? What happens if someone leaves? Is there a backup? Is there a record? Is the tool actually approved for business use?
If you would not upload a client contract to a random website, you probably should not paste it into a random AI tool either.
That is the simple test.
Shadow AI is not about stopping people from working smarter. It is about making sure “working smarter” does not quietly create a data problem in the background.
The businesses that handle this well will not be the ones with the longest policies.
They will be the ones that make the safe way the easy way.