When the privacy company Proton warned that shadow AI is a hidden risk to your business, it named a problem most small business owners already have and have not spotted. Shadow AI is the everyday use of artificial intelligence tools, usually free chatbots, that nobody in the business has approved, checked or even heard about. A member of staff pastes a customer list into ChatGPT to tidy the formatting, or drops a draft contract into a free summariser, and in seconds your data has left the building.
The short answer for a small business: shadow AI is not a reason to ban AI, it is a reason to know who is using what and what they are feeding into it. The danger is not the technology, it is unmanaged use. This article explains what shadow AI actually looks like in a small firm, the real risks (data protection, confidentiality, accuracy), how the main tools handle your information, and a simple plan to bring it under control without killing the productivity everyone is enjoying.
What shadow AI actually looks like
Shadow AI is the AI cousin of “shadow IT”, the old problem of staff using software the business never signed off. Because modern AI tools are free, fast and need nothing more than a browser, adoption happens quietly and from the bottom up. Nobody submits a request. They just start using them.
In a typical UK small business it looks like this:
- An office manager pastes a spreadsheet of client names, emails and order values into a free chatbot to write a summary.
- A salesperson uploads a signed customer contract to get a plain-English breakdown before a renewal call.
- A bookkeeper drops a batch of invoices into an AI tool to extract figures, invoices that contain supplier bank details.
- A marketer feeds your unpublished pricing strategy into a chatbot to “make it sound better”.
Each of these feels harmless and saves real time. The trouble is that the person doing it has no idea where that information goes, whether it is stored, or whether it might be used to train a future model. That uncertainty is the risk.
Why shadow AI is a genuine problem, not just IT nervousness
Data protection and UK GDPR
If your staff put personal data (customer names, contact details, health or financial information) into a consumer AI tool, you may be transferring that data to a third party, often outside the UK, with no lawful basis and no contract in place. Under UK GDPR you remain the data controller and you are accountable for where personal data ends up. The Information Commissioner’s Office (the ICO) is clear that using someone else’s AI service does not move the responsibility off your shoulders. A serious breach can trigger reporting duties and, in the worst cases, fines.
Confidentiality and lost trade secrets
Contracts, pricing, product roadmaps and client lists are often your most valuable assets. Once pasted into a tool with weak data terms, you cannot be sure they are private. This matters even more if you have signed non-disclosure agreements with clients: an employee’s quick summarising job could technically breach them.
Accuracy and made-up answers
AI models can produce confident nonsense, often called “hallucination”. A staff member who trusts a chatbot’s summary of a lease, a tax rule or an HMRC deadline can act on something simply wrong. For anything touching money, law or compliance, the output needs a human check. This is one reason security specialists such as KnowBe4 argue SMEs must protect both people and machines as AI use spreads.
How the main AI tools handle your data
Not all AI tools treat your information the same way, and the difference usually comes down to which plan you are on. Consumer free tiers tend to be the riskiest; paid business and enterprise tiers usually offer stronger promises that your data will not be used to train models. The table below is a general guide to help you shortlist, not a guarantee, so always read the current terms before you rely on any tool.
| Tool | Provider | Rough UK cost | What it is generally known for |
|---|---|---|---|
| ChatGPT | OpenAI | Free; Plus around £16-£20 per user/month; Team and Enterprise higher | The best known chatbot. Business tiers offer data controls; free tier terms are looser. |
| Copilot | Microsoft | Around £18-£19 per user/month for Microsoft 365 Copilot | Built into Word, Excel and Outlook, with enterprise data protection on business plans. |
| Gemini | Included in some Google Workspace plans; paid add-ons | Tied into Gmail, Docs and Sheets for Workspace users. | |
| Claude | Anthropic | Free; Pro around £14-£15 per user/month; Team higher | Strong on long documents and drafting, with a safety-first reputation. |
| Lumo | Proton | Free tier; paid plans within Proton subscriptions | A privacy-focused assistant from the Swiss firm behind Proton Mail, built around not logging your conversations. |
The point of naming these is simple: a business plan you actually pay for almost always comes with clearer commitments about your data than a free account someone signed up for on their phone. If your team is using AI daily, moving them onto a managed, paid tier is often the single biggest risk reduction you can make.
Tools that help you find and control shadow AI
You cannot manage what you cannot see. A handful of specialist firms focus on discovering which AI tools staff are using and stopping sensitive data leaving through them. Worth knowing about beyond the household names:
- Metomic, a UK data security firm that helps businesses spot and control sensitive information moving through SaaS and AI tools.
- Harmonic Security, which focuses specifically on monitoring and governing employee use of generative AI.
- Nightfall AI, which scans for personal and financial data being shared where it should not be.
These are more relevant to larger SMEs with in-house IT than to a five-person firm. For most small businesses, the answer is policy and good habits rather than expensive tooling. It is also worth checking what protection you already own: endpoint security such as Malwarebytes, now available on the Microsoft Store, addresses malware rather than AI leakage, so do not assume your antivirus covers this.
A simple shadow AI plan for a small business
You do not need a policy the length of a phone book. You need a page your team will actually read.
- Approve a short list of tools. Pick one or two, on paid business plans, and tell staff these are the ones to use. Naming approved options is far more effective than a vague “be careful”.
- Set a red line on data. The clearest rule: never paste customer personal data, financial details, contracts or passwords into any AI tool. If in doubt, leave it out.
- Explain the why. People follow rules they understand. A five-minute team talk on UK GDPR and confidentiality lands better than a memo.
- Keep humans in the loop. Anything financial, legal or compliance-related gets checked by a person before it goes out.
This fits neatly alongside the broader software decisions in our guide to the tools every UK owner should consider in 2026, and it complements rather than blocks the productivity gains covered in our piece on improving your marketing with AI tools.
Frequently asked questions
Is it illegal for staff to use free AI tools at work?
Not in itself. It becomes a legal problem when personal data is shared without a lawful basis under UK GDPR, or when confidential information is disclosed in breach of a contract. The activity is rarely the issue; the data involved is.
Should I just ban AI tools completely?
Usually no. Bans tend to push usage further into the shadows, where you have even less visibility. Approving a small number of safe, paid tools and setting clear data rules keeps the productivity while cutting the risk.
How do I know which AI tools my team is already using?
Start by asking, openly and without blame, in a team meeting. Most staff will happily tell you what they use because they think they are being helpful. For larger teams, discovery tools from firms such as Metomic or Harmonic Security can surface it automatically.
Does a paid AI plan really make my data safer?
Generally the business and enterprise tiers from OpenAI, Microsoft, Google and Anthropic offer stronger commitments not to train on your data than their free consumer versions. It is not a magic shield, so always read the current terms, but it is a meaningful improvement over an unmanaged free account.
What if a breach has already happened through shadow AI?
Treat it like any data incident. Establish what data was shared and with which tool, check the tool’s data handling terms, and assess whether it is reportable to the ICO. If personal data is involved and there is a risk to individuals, you may need to report within 72 hours of becoming aware.
What to do next
- Run a five-minute amnesty. Ask your team, without blame, which AI tools they use and for what. You cannot manage what you cannot see.
- Choose your approved tools. Pick one or two on paid business plans, whether that is Microsoft Copilot, ChatGPT Team, Claude or a privacy-first option like Proton’s Lumo, and tell everyone which to use.
- Write one page of rules. Set a clear red line on personal data, contracts and passwords, and require a human check on anything financial or legal.
- Review it every few months. AI tools and their data terms change fast, so revisit your list and your policy as your business grows.





