What Is Shadow AI, and How Do You Stop Your Team Using Unapproved AI Tools?
Shadow AI is your team using AI tools your business has never approved, usually on a personal account, usually with company information pasted in. The UK's National Cyber Security Centre (NCSC) published a blog post on the hidden risks of shadow AI on 7 September 2026. Its advice matches the advice in this article: a ban will not work. Give your team an approved AI tool that does the job, explain why it matters, and then block the rest.
Why the free chatbot is your problem
Picture a team member who copies a client's contract into a free chatbot to "tidy up the wording". Or one who pastes a spreadsheet of customer details to "make sense of the numbers". Nothing looks wrong, and the work gets done faster. But now a copy of your client's information sits on a server run by a company with which you have no agreement. Nobody in your business has read the terms.
That is shadow AI. The NCSC describes it as AI use that "isn't captured in an organisation's approved systems and processes". It treats it as a form of shadow IT. It is more common than most business owners expect. Research commissioned by Microsoft UK and carried out by Censuswide in October 2025 surveyed 2,003 people working in the UK. It found that 71% had used unapproved consumer AI tools at work, and 51% still did so every week.
Why does your team use AI tools you have not approved?
They use them because the tool they know from home is quicker than asking. In the same Microsoft survey, 41% said they used unapproved AI because they already knew how to use it. Another 28% said their company had no approved alternative to offer.
The NCSC makes the same point in plainer terms. Business policies have not kept pace with how fast AI has arrived, so people have stopped waiting. Most of them are trying to get through the day, and a chatbot on their phone helps. If your business has not told them which AI tool to use and why, they will pick one for you.
What happens to your data when someone pastes it into a free AI tool?
Three things, and the NCSC lists all of them.
Your information leaves your control. Once a client's contract or your pricing is inside a consumer AI service, it may be stored, retained, or used to improve that service. None of that sits inside any security arrangement your business has. If a client asked where their data had been, you could not answer.
You lose visibility. You cannot see what has been shared, by whom, or when. There is no log to check and nothing to search for if a client or a solicitor asks. As the NCSC puts it, "You cannot manage what you do not know."
You open a new door for attackers. This is the risk the NCSC adds to the usual two. AI agents are complex software, and complex software has vulnerabilities. An attacker who exploits one gains the same access as the agent. For a tool signed into someone's Google account, that can be a great deal.
Then there is the regulatory side. If the information was personal data, UK GDPR expected you to know where it went and to have a lawful basis for sending it there. "A team member pasted it into a chatbot" is not an answer the ICO will enjoy.
Why is Gemini the sensible default for a Kimbley IT client?
Gemini is part of the Google Workspace your business already runs on. It sits within the same account, security settings, and admin controls as your email and files. Your team gets a capable AI assistant without anything leaving your Google Workspace.
Google's own commitment to data handling matters here. Google Workspace's privacy hub for generative AI covers this. Your content "is not human-reviewed or otherwise used for Generative AI model training outside your domain without permission". On a free personal account, most consumer AI services' default terms allow them to use your conversations to improve the product. Human reviewers may read them. The technology is similar. The agreement you have with the provider is not.
There is a second advantage. Conversations with the Gemini app are covered by Google Vault, which is included in your Google Workspace by Kimbley IT. Vault has been able to search and export Gemini app conversations since February 2025. Since June 2026, it can apply retention rules and litigation holds to them as well. If you ever need to see what a team member asked an AI, you can do so. That might be an HR investigation, a legal dispute, or a data protection request. With shadow AI, that record does not exist.
Can your team use other AI tools?
Yes, when there is a business reason, and the tool has been checked. Gemini covers most day-to-day work. A specialist tool for your accounts package, your design work, or your customer service system might do a job that Gemini does not.
The process is short. Work out what problem the tool solves. Read its data policy, or ask Kimbley IT to read it for you, and find out what it does with what you type in. Decide what kind of information will go into it and what would happen if that information leaked. Then approve it in writing, on a paid business plan rather than a personal free account, and tell the team it is on the list.
How do you actually stop the rest?
You need three things, and the order matters.
An AI policy your team can read in five minutes. Which tools are approved, and what information can go into them. What can never go into any AI tool at all: client data, financial details, passwords, anything covered by a contract. Keep it to one page.
A proper conversation with your team. The NCSC's advice for organisations is to build a positive cyber security culture in which people feel able to say which tools they use and why. Ask your team what they have been using AI for. The answers will tell you what the approved tool needs to do. You will also hear about the free accounts before they cause a problem.
A technical block for the tools that are not approved. Policies get forgotten on a busy afternoon. Kimbley IT can block unapproved AI tools for your business. A well-meaning team member who tries to open one on a work device or connect it to their Google account simply cannot. This comes as standard with Google Workspace by Kimbley IT. The version of Google Workspace you get from Kimbley IT is not the vanilla one you would get by signing up directly. It has been set up to reflect how a UK business actually runs, and controlling which apps can access your data is part of that.
Free AI on a personal account vs Gemini in your Google Workspace
| Free Personal AI vs Gemini in Your Google Workspace | ||
| What to check | Free AI on a personal account | Gemini in Google Workspace by Kimbley IT |
|---|---|---|
| Used to train the AI | Usually allowed under the default terms of a free account, and human reviewers may read your conversations. | No. Google states your content is not used for model training outside your domain without permission. |
| Who controls the account | The team member. Your business has no access to it and no agreement with the provider. | Your business, through admin controls that Kimbley IT manages for you. |
| Record of what was shared | None. There is nothing to search if a client, HR, or a solicitor asks. | Google Vault can search, export, retain, and place holds on Gemini app conversations. |
| When someone leaves | The account, and everything typed into it, goes with them. | The account stays with the business and is closed off on their last day. |
| Can you switch it off | No. It lives in their account and their personal login. | Yes. Kimbley IT can allow, restrict, or disable it for the whole business. |
Frequently asked questions
-
Shadow AI is the use of AI tools that your business has not approved or set up. Typically, it is a free chatbot on a personal account being used for work. The NCSC treats it as a form of shadow IT. The Microsoft UK survey in October 2025 found that 71% of the UK workers surveyed had used unapproved AI tools at work.
-
Not in itself. If the data includes personal information about clients, team members, or customers, your business remains responsible for it under UK GDPR. If it went to a service you have no agreement with, and nobody kept a record, it is hard to show you handled it properly.
-
Google states that content in Gemini for Google Workspace is not human-reviewed or used to train its AI models outside your domain without permission. Free personal accounts for Gemini, Claude, and ChatGPT are subject to different terms. That is why the difference between a work account and a personal one matters.
-
Yes, if you are on Google Workspace by Kimbley IT. Google Vault can search for and export Gemini app conversations, and since June 2026, it can apply retention rules and legal holds to them.
-
No. The NCSC's advice is to reduce the risk rather than assume you can remove it, because a blanket ban pushes people back to their phones' AI features and shadow AI, which you want to avoid. Give your team an approved, working tool, explain the rules, and then block tools not on the list.
Book a call
If you are not sure which AI tools your team is using, book a video call with Kimbley IT using the form below. The same applies if you want the approved tool and the block set up properly. You will get a plain answer on what is at risk today and what to change first.