Insights · 24 July 2026

Shadow AI: what your staff are already doing with ChatGPT

Shadow AI poses data risks as staff use unsanctioned tools; this 2026 guide outlines UK GDPR considerations and how to protect data while enabling productive use by teams.

Shadow AI is staff use of unsanctioned generative tools, such as ChatGPT, for work tasks without IT approval. In the UK, organisations must treat these tools as a data risk under UK GDPR and follow the Information Commissioner’s Office guidance on AI and data protection (ICO, 2024). ENISA’s 2025 analysis highlights AI-related risks and industry commentary flags unmanaged model use as a source of data leakage (ENISA, 2025, IBM, 2024).

  • What: Shadow AI is staff use of unsanctioned generative tools for work, creating uncontrolled data flows and data protection obligations.
  • Why it matters: Under UK GDPR, the Information Commissioner’s Office requires careful data handling when staff use external models (ICO, 2024).
  • Evidence: ENISA’s 2025 report flags AI misuse as a growing risk and industry analysis warns of data leakage via unmanaged model use (ENISA, 2025, IBM, 2024).
  • Fast wins: Publish an approved-model list, mandate prompt redaction rules, and run a short briefing for high-risk teams.
  • Technical fixes: Block risky browser extensions, log model API calls, and add data loss prevention rules for uploads to public models.

What is shadow AI?

Shadow AI is staff use of unsanctioned generative tools, such as ChatGPT or image generators, for work tasks without IT or governance approval. Shadow AI includes browser plugins, personal accounts, and unauthorised agentic tools that process company data.

Common forms

ChatGPT prompts for drafting, image generators for marketing assets, browser extensions that summarise emails, and low privilege automation scripts are typical forms. Staff choose these tools for speed and convenience, not because they ignore policy. Shadow AI often starts with a quick search or a copied prompt, then expands into regular use.

Why it matters in the UK

Under UK GDPR, controllers must protect personal data that employees feed into external models, and the Information Commissioner's Office (ICO) has published guidance on AI and data protection; see the ICO guidance on AI and data protection. The National Cyber Security Centre (NCSC) highlights AI in its 2025 Annual Review as a priority for organisational risk management, particularly where sensitive data is exposed NCSC Annual Review 2025. ENISA and Verizon research also show rising incident counts where unsanctioned tools contributed to data leakage, making shadow AI an operational and regulatory concern rather than a theoretical one.

Practical steps

Start by mapping where staff already use consumer models, update acceptable use policies, and add simple controls such as approved model lists and data handling rules. If you need a tested assessment methodology, our guide on AI risk assessment explains how to triage tools and data quickly. In our experience, quick wins are an approved model list, mandatory data redaction rules for prompts, and a short staff briefing that explains the ICO expectations and the NCSC advice.

How does shadow AI work in practice?

Shadow AI happens when staff use consumer generative tools for work tasks, for example pasting client data into ChatGPT, installing browser extensions that rewrite pages, or uploading documents to a public model without approval.

Common user behaviours

Employees typically introduce generative tools by copying and pasting text, sharing screenshots, using browser plugins that send page content to a third party, or forwarding emails to an AI assistant. These actions create uncontrolled data flows from corporate systems to model providers and raise the risk of exposing personally identifiable information, client confidentiality and intellectual property.

Survey and incident research shows these behaviours are widespread. IBM's write up on shadow AI summarises industry polling where roughly one in five organisations reported data leakage linked to employee use of generative AI in 2024. ENISA's Threat Landscape 2025 documents multiple incident chains where unsanctioned AI use was a contributing factor to data exposures during investigations, showing how small actions can scale into larger incidents.

How the data actually moves

When a user pastes text or uploads a file, the browser or app sends that payload to the model provider's web endpoint or API, which can be hosted outside the UK. Model providers' terms and technical practices determine whether submitted data is retained, indexed or used for model training. Tools that act with user credentials, sometimes called agentic tools, can widen the blast radius if they access internal systems or forward results to other services.

At CyPro, we commonly find artefacts of shadow AI during assessments: search logs containing model queries, uploaded documents referenced in prompts, and shared prompt libraries with client names. Practical first steps include mapping where staff are likely to try generative tools, deploying a sanctioned alternative, blocking risky extensions, and training high risk teams.

For deeper work on automation that acts inside your estate, see our Agentic AI security service and our AI risk assessment service for scoping and remediation.

Key Takeaway

Shadow AI usually starts with simple staff actions like copy and paste, browser extensions or email forwards; map those behaviours, then prioritise controls that stop sensitive data leaving corporate systems.

Shadow AI: what your staff are already doing with ChatGPT - supporting illustration

Who in an organisation uses shadow AI, and why?

Junior analysts, lawyers, salespeople, HR staff and developers commonly use shadow AI because it speeds drafting, summarising, research and repetitive coding tasks without waiting for IT or governance approval.

Typical adopters

Business analysts and junior technical staff use shadow AI to draft reports, create SQL snippets and generate test data. Legal teams use generative tools to draft clauses and redline contracts. Sales and marketing use model outputs for outreach messaging and content. HR uses the tools to screen CVs and write job adverts. These groups prioritise speed and convenience over compliance, which is why shadow AI spreads quickly.

Tasks and motivations

People choose unsanctioned tools for four practical reasons: faster first drafts, quick summaries of long documents, help with coding or spreadsheets, and creative ideation. A UK organisation with heavy document workflows sees more shadow AI use in legal, compliance and client-facing teams. Where staff have personal subscriptions to consumer models, use rises because those models are simply available at the point of need.

Shadow AI brings data leakage risk when staff upload customer data, IP or personal data to external models. The Cyber Security Breaches Survey 2025 shows UK firms reporting rising tech-driven incidents, and the 2025 Data Breach Investigations Report illustrates how many breaches arise from everyday user actions rather than exotic exploits. That combination matters for CISOs and Data Protection Officers in the UK because regulators such as the Information Commissioner's Office enforce UK GDPR obligations on unlawful sharing.

At CyPro, we map high-risk teams and common tasks, then propose targeted controls: sanctioned models with data loss prevention, configuration of browser and plugin policies, and role-specific training. Where appropriate, we recommend our AI Cyber Security Code of Practice readiness check to align teams to the UK's guidance and reduce shadow AI usage without blocking useful productivity gains.

How much does it cost to manage shadow AI in the UK? £ ranges and components

For most UK mid-market organisations, managing shadow AI costs between £8,000 and £120,000 upfront, plus recurring costs of £1,000 to £20,000 per month depending on scope and monitoring. These figures cover discovery, policy, tooling, training and managed monitoring.

Cost drivers are the number of users, the sensitivity of data exposed, and whether you deploy sanctioned models or a managed monitoring service. Smaller teams need focused discovery and a simple policy. Larger organisations need tooling, plugin controls and ongoing review, which raises both one-off and recurring spend.

Breakdown of typical components

Discovery and mapping: a targeted discovery to find where staff use generative tools, plus sample prompt analysis, typically costs £3,000 to £12,000 for a single business unit. Policy and governance pack: drafting an AI policy, role rules and acceptable-use guidance is usually £2,500 to £10,000 depending on consultation level. Tooling and integrations: licences for sanctioned models, proxying, or DLP integrations vary widely, from £500 to £6,000 per month. Training and comms: role-specific training programmes cost £1,000 to £15,000 depending on depth and delivery model.

Organisation sizeOne-off (discovery, policy)Recurring monthly (tooling, monitoring)
Small (≤100 staff)£8,000 to £18,000£1,000 to £3,500
Mid-market (100 to 1,000 staff)£18,000 to £45,000£3,500 to £12,000
Large enterprise (>1,000 staff)£45,000 to £120,000£12,000 to £20,000+

Managed monitoring versus self‑service tooling

Managed monitoring is pricier but reduces operational burden; expect managed services to sit at the top of the recurring ranges above. Self‑service tooling has lower monthly costs but needs internal resource to run discovery and investigate alerts. For public-sector and regulated bodies, hidden costs include legal review and data protection impact assessments, which can add £5,000 to £25,000.

Evidence: Forrester has documented risks from unsanctioned purchases and tool use in government, which increases hidden costs for remediation Forrester, 2025. UK economic modelling on cyber impact shows remediation and fines can far exceed prevention spending, reinforcing that early investment in managing shadow AI is often cheaper than late remediation GOV.UK, 2025.

At CyPro, we recommend starting with a scoped discovery and a policy pack, then funding tooling based on the discovery outcomes. Our team often pairs discovery with a policy template and a 90‑day monitoring pilot to keep initial spend predictable. For practical next steps, see our AI governance policy template.

What is the difference between shadow AI and approved enterprise AI?

Shadow AI is unsanctioned use of consumer or third‑party AI tools by staff, while approved enterprise AI is centrally managed, logged and governed by IT and risk teams.

Shadow AI typically appears when employees use public chat tools or browser plugins to speed tasks, creating data leakage and compliance risk. Approved enterprise AI enforces data controls, access rules and approved model choices, and integrates with identity and device management tools.

Scope and data controls

Shadow AI often runs outside corporate telemetry, so input data can include personal data, customer IP or confidential code. The European Union Agency for Cybersecurity's publication maps how unsanctioned tools create blind spots that increase incident risk, especially where model outputs are reused in reports (ENISA, 2025).

Approved enterprise AI routes queries through enterprise models, enforces encryption and data minimisation, and applies Data Loss Prevention (DLP) rules at the boundary. That makes audits and incident response feasible under UK GDPR and ICO expectations.

Integration, auditability and human oversight

Shadow AI lacks integration with Single Sign‑On (SSO), device management and logging, so investigations are slower and containment harder. The Information Commissioner’s Office highlighted real UK fines where uncontrolled data outflow caused material harm (ICO, 2025).

Approved enterprise AI includes role‑based access, model approval workflows and retrain/feedback pipelines so outputs can be traced to data sources. That reduces operational risk and helps compliance teams demonstrate due diligence.

In practice, shadow AI and approved enterprise AI overlap: an approved model can be invoked from an unsanctioned plugin, or staff can paste sensitive prompts into public tools. We recommend mapping high‑risk users, enforcing approved tooling, and using monitoring to detect shadow AI use. For deeper technical controls on agent behaviour, see our Agentic AI security service page.

Shadow AI: what your staff are already doing with ChatGPT - supporting illustration

When should you implement controls for shadow AI?

Implement controls for shadow AI as soon as staff use public generative tools with organisation data, or when AI tools touch personal data, credentials or systems with access rights. Early controls reduce the chance of data leakage, regulatory action and unauthorised automation.

When to treat shadow AI use as urgent

Any of these three triggers should prompt immediate action: employees paste customer data or personally identifiable information into public chat models; developers or contractors test unvetted models against live datasets; or AI agents are given credentials or permissions to act on systems. The European Union Agency for Cybersecurity's 2025 report highlights the rising operational complexity from unauthorised automation and AI use, so organisations should prioritise cases that match those triggers (ENISA, 2025).

Practical first steps

Start with discovery, a focused policy and a short technical sweep. Discovery should map which cloud domains, browser extensions and unmanaged tools staff use, and flag where sensitive data appears. An AI acceptable use policy sets clear do and do nots for prompts and model selection. Technical sweeps can include blocking risky browser plugins, tuning existing data loss prevention for prompt patterns, and restricting outbound model endpoints at the network layer.

When to escalate to a programme

Escalate from a pilot to a programme when discovery finds repeated exposures, when regulated personal data is involved, or when board or regulator scrutiny increases. The Information Commissioner's Office's enforcement examples show large fines and remediation costs follow repeated data loss incidents, so escalation is often cheaper than repeated incident response (ICO, 2025).

At CyPro, we usually run a 10 to 30 day discovery, ship an AI acceptable use policy and pilot monitoring for 60 to 90 days to measure prompt exposures and behaviour change. For controlled agentic AI risk assessments see our Agentic AI security service, and for a hands-on risk assessment see our AI risk assessment page.

Key takeaway

Act when staff use public generative models with organisation or personal data. Start with discovery, a short policy and a 60 to 90 day monitoring pilot to quantify risk.

How to choose a provider to manage shadow AI risk?

Pick a provider that can discover unsanctioned AI use, assess data exposure, and deliver usable controls and policies within 4 to 8 weeks.

Start by insisting on discovery techniques that find both browser and SaaS use, plus clear deliverables: an inventory of shadow AI incidents, a mapped data flow for each, and a prioritised remediation plan.

Selection criteria

Ask whether the supplier has UK data protection experience, including work under UK GDPR and interaction with the Information Commissioner’s Office (ICO). Ask if the supplier uses automated discovery (browser telemetry, SaaS connectors) and manual user interviews. Check whether the supplier maps sensitive data to AI prompts, and whether they provide policy templates and playbooks you can adopt. Evidence matters: request redacted examples and customer references from UK-regulated sectors.

Questions to ask vendors and internal stakeholders

Request three priced scenarios: discovery only, discovery plus policy pack, discovery plus technical controls and monitoring. Ask vendors to state measurable deliverables, for example how many endpoints or SaaS apps will be scanned, and an expected false positive rate for detections. For internal stakeholders, ask where regulated personal data is created or handled and which teams already use generative tools. These steps cut unknowns before you sign.

When to buy a SaaS control, policy pack or bespoke testing

Buy a SaaS control if you need quick blocking or prompt redaction for common apps. Commission a policy pack if you need governance fast and want staff adoption materials. Buy bespoke testing, including prompt-injection and agentic AI assessments, when AI agents have production access to your systems. The ENISA guidance and GOV.UK cyber survey show rising generative AI use, which increases the chance of data leakage during normal staff tasks (ENISA, 2025, GOV.UK, 2025).

At CyPro, we recommend a phased buy: start with discovery, then add policy, then technical controls. Our FAQs page explains the typical 4 to 8 week timelines and deliverables for each phase.

Frequently asked questions

Frequently asked questions

Do I need an AI acceptable use policy if staff use ChatGPT?

Yes, an AI acceptable use policy is advisable when staff use consumer AI tools with work data. Your policy should state permitted data, prompt handling, confidentiality, intellectual property and enforcement. Include practical examples and a clear escalation path to IT and the Data Protection Officer (DPO) so staff know who to contact when unsure.

What are the main shadow AI risks for UK employers?

Data leakage of personal data or client information is the primary risk under the UK General Data Protection Regulation (UK GDPR). Secondary risks include incorrect advice, loss of intellectual property, regulatory non-compliance and reputational harm. Early discovery, prompt governance and remediation reduce exposure and show good-faith compliance to regulators such as the Information Commissioner’s Office (ICO).

How long does it take to get visibility of shadow AI use?

A focused discovery project typically takes two to four weeks for a mid-market UK firm. Discovery methods include staff surveys, log analysis, browser extension audits and targeted interviews. Deliverables should include a ranked remediation plan, policy recommendations and quick-win actions to reduce the highest-risk data flows within days, not months.

Can shadow AI be controlled with existing DLP or CASB tools?

Data Loss Prevention (DLP) and Cloud Access Security Broker (CASB) tooling help but rarely catch every shadow AI use case. Browser extensions, mobile apps and personal devices create blind spots. Combine DLP and CASB with targeted discovery, policy controls and training to close gaps and give risk owners the visibility they need.

What is the typical cost of a policy pack and discovery for shadow AI?

Typical UK pricing varies by organisation size and complexity; expect separate line items for discovery, policy drafting, tooling and a short training run. Costs rise with number of data sources and regulatory obligations such as UK GDPR or Financial Conduct Authority (FCA) rules. Get banded estimates up front and a clear statement of work to avoid surprises.

Can we stop staff using consumer AI tools outright?

A blanket ban is possible but often impractical and hard to enforce. A safer approach is a controlled permit process, a clear acceptable use policy and approved alternative tools. Enforcement works best when compliance is paired with user-friendly approved options and fast onboarding so staff do not resort to unsanctioned consumer tools.

Rocket launching above the AI Governance UK call to action

Start here

Find out where your AI use actually stands

Take a free 45 minute scoping call about how AI is used across your business, and leave knowing what a governance assessment or a security test involves, what it costs and what comes back. No pressure at any point.