Loading...
Loading...
Shadow AI is not a future policy problem. It is already happening in ordinary work.

The first AI policy in most small businesses is not written by the owner.
It is written by the employee who pastes a client email into ChatGPT and asks for a cleaner reply. It is written by the assistant who drops a proposal into Gemini and asks for a summary. It is written by the manager who copies a spreadsheet into a chat window because the formula is not working and the client is waiting.
Nobody calls that a policy. That is the problem.
Most of these people are not careless. They are trying to work. They are under time pressure. They have heard that AI can help, and in many cases it can. The tool gives an answer in seconds. The business gets a faster draft. The employee feels competent. Nothing explodes.
But a decision has still been made.
Client information left the business and entered a third-party AI service. Maybe that service was a free personal account. Maybe it was a managed business tenant. Maybe the data can be used for training. Maybe it cannot. Maybe a human reviewer can see it. Maybe retention is short, long, or configured by an administrator. Maybe nobody in the business knows which of those is true.
That is shadow AI. Not a dramatic breach. Not a malicious insider. Just useful work happening outside any decision the business actually made.
A lot of AI risk hides inside a simple assumption: ChatGPT is ChatGPT. Gemini is Gemini. Copilot is Copilot. Claude is Claude.
That is not how these services work.
Consumer and business tiers can have different data terms, different retention settings, different admin controls, different audit options, and different training defaults. OpenAI says its business products do not train on workspace data by default. Microsoft says Microsoft 365 Copilot prompts and responses are protected by enterprise data protection and are not used to train foundation models. Google gives Gemini Apps users activity and auto-delete settings, but also warns users not to enter confidential information they would not want reviewed or used to improve services. Anthropic's consumer and commercial retention terms are different, and the company has changed consumer data settings over time.
The details matter less than the pattern. The protection depends on which account, which plan, which setting, and which tool.
Your employee does not know that when they are trying to finish a task at 4:45pm.
They see a box. They paste the text. The box answers.
If you have not told them what is allowed, they will invent the rule in the moment.
People imagine AI data exposure as a dramatic secret: source code, passwords, bank records, medical files. Those matter. But most of the risk in a small business is less cinematic.
A client complaint.
A contract clause.
A renewal notice.
A payroll question.
A list of customers who have not paid.
A set of notes from a sales call.
A spreadsheet with names, emails, balances, dates, or internal comments.
Each item looks ordinary to the person copying it. They are not thinking about data classification. They are thinking about finishing the task. The problem is that ordinary business information can still be confidential, personal, regulated, or contractually restricted.
Canada, the UK, the EU, Panama, and the United States do not all use the same privacy framework, but they share a practical theme: if you collect or handle personal information, you remain responsible for how it is used and disclosed. In health care, HIPAA de-identification is not a vibe. Removing obvious names is not the same as meeting the standard. In Panama, personal data law applies to public and private actors that process personal data under the law. In Canada, commercial organizations subject to PIPEDA remain accountable for personal information, including when it crosses borders.
You do not need to turn every small business into a compliance department. You do need to stop pretending that a copy-paste action is harmless because it is easy.
The simplest response is to say "do not use AI."
That may be necessary in a few settings. It is also hard to enforce in a small business where people already use personal accounts, personal phones, browser tools, writing assistants, and AI features embedded in the software they already have.
A ban without an approved alternative usually creates better hiding, not better behavior.
The better first step is a short acceptable-use policy that normal people can remember.
It should name the approved tools. It should say which accounts must be used for business work. It should name the data that cannot be entered into public tools. It should tell employees what to do when they are unsure. It should require human review before AI output reaches a client. It should make one person responsible for updating the policy when tool terms change.
That policy does not need to be long. Long policies are often proof that nobody will read them. The first version can fit on one page.
What matters is that the business makes the decision before the employee is under pressure.
In a business with no IT department, AI responsibility cannot live in the air.
It cannot belong to "everyone." It cannot belong to the person who is most excited about AI. It cannot belong to an outside provider by assumption. It belongs to the business owner until the owner deliberately assigns it.
That does not mean the owner needs to become technical. It means the owner needs to decide the boundaries.
Which tools are approved?
Which data stays out?
Which account type is required?
Who reviews output?
Who can add a new AI tool?
Who checks the terms when a tool changes?
Those are management questions. They have technical consequences, but they are not technical trivia. They decide whether client trust is protected by design or by luck.
If you want to find shadow AI in your business, do not start with a survey full of jargon.
Ask your team one plain question: "What have you pasted into an AI tool in the last month?"
Make it safe to answer. You are not looking for someone to blame. You are looking for reality. The first answers will tell you where the policy needs to begin.
Then separate the uses into three buckets.
Low risk: public information, internal drafts with no client data, brainstorming, tone adjustment, plain-language rewriting.
Needs rules: internal documents, client context, financial summaries, operational notes, anything that would be awkward if exposed.
Not allowed without review: regulated data, medical information, credentials, source code, legal advice, confidential client records, nonpublic financial information, donor lists, employee records.
That simple sorting exercise will put most small businesses ahead of where they are today.
The danger is not that your staff are trying AI. The danger is that they are doing it alone, under pressure, with no agreed boundary between useful work and unacceptable exposure.
If you need to know where AI is already entering your business, start a conversation.
Related Reading
More Insights
← Back to all articles