Shadow AI: Damned If You Do, Liable If You Don't

Your staff are already using AI you haven't approved. Banning it will not stop them. It will only make sure you are the last to know. Here is what to do instead.

The 60-second verdict

  • It is already in the building. Research cited by the National Cyber Security Centre in September found that 71% of UK employees have used AI tools their employer has not approved. Your people are in that number.

  • Bans create blindness, not compliance. Prohibition pushes AI under the desk. And the UK Jurisdiction Taskforce says professionals can be liable for misusing AI and also for failing to use it where a competent peer would have.

  • Three things to do this week.

    • Declare an amnesty.

    • Send every software vendor one email.

    • Put a named human against every AI agent in the business.

If your diary is screaming, stop reading here. I shall assume you’ve gone to do all three.


We have been here before

Cast your mind back to the late 1990s. In wood-panelled sanctuaries of the top law firms and corporate boardrooms, management committees gathered to confront a terrifying new menace: the World Wide Web.

The verdict was swift. The internet was deemed a hotbed of distraction, a vector for operational chaos, and a security nightmare. So plenty of firms banned it from the desktop. Firewalls went up. Leadership dusted off its hands.

It was a triumph of administrative delusion.

In reality, staff simply adjusted. They went home, dialled up on the family phone line (remember the modem dial-up tone?!?), did their research in the evening and emailed the results to their work inbox on Monday morning. Nothing stopped. Management had not eliminated the practice; they had merely audited themselves into total, voluntary blindness.

You are being offered the same illusion today, with AI.

It is called Shadow AI: any algorithm, browser extension, or friendly personal chatbot account operating beyond your visibility or governance. It is the keen junior tidying a client document through a personal Claude account at midnight. It is the unvetted transcription bot sitting quietly in your confidential board meeting. And, most insidiously, it is the "AI-enhanced" feature your software vendor switched on in last Tuesday's update without mentioning it to your CTO.

Last month in London, I had the privilege of moderating a panel at the AI Governance, Trust & Security Leaders Summit. I was surrounded by four veteran practitioners who manage this problem for a living. I asked them how a business is supposed to govern something it cannot see.

Astonishingly, for a stage full of lawyers and governance professionals, nobody said "it depends".

What follows is what I took from that room and from the evidence: why your policy is probably failing, why a total ban carries legal risk of its own, and how to build governance that survives contact with human nature.


A tale of two numbers

Two figures landed nine days apart in September.

On 7 September the NCSC published The hidden risks of shadow AI. It cited Microsoft research finding that 71% of UK employees have used AI tools their employer has not approved.

On 16 September Deloitte published its first GenAI Workforce Survey, with 25,000 UK workers polled by Ipsos. Almost one in ten said they had used an AI tool their employer had banned or would disapprove of.

Seventy-one per cent against roughly one in ten. They are different surveys asking different questions, so this is not a like-for-like comparison. But the distance between the two is where the problem lives.

"Not approved" is not the same as "banned". Most shadow AI is not rebellion. It sits in the space where nobody has said yes and nobody has said no. Deloitte found that 31% of people who use generative AI at work do so without their employer knowing, and most of them assume the employer would be fine with it. Half of users have had no formal guidance or training at all.

71%

of UK employees have used AI tools their employer has not approved

Microsoft research, cited by the NCSC, September 2026

31%

of UK workers who use generative AI at work do so without their employer knowing

Deloitte GenAI Workforce Survey, September 2026

Almost 1 in 10

UK workers have used an AI tool their employer has banned or would disapprove of

Deloitte GenAI Workforce Survey, September 2026

What accounts for this magnificent discrepancy? It turns out that people are remarkably candid when answering an anonymous survey about general productivity habits, and hilariously conservative when asked if they personally break firm policy.

When an employee is asked, "Do you use modern software to complete three hours of work in twenty minutes?" they beam with pride and answer yes. When asked, "Are you violating Section 4.2 of the IT Acceptable Use Policy?" they suddenly develop severe amnesia.

Your staff are not acting out of malice. They are trying to keep their heads above a rising tide of work with the best tools they can find. Meet that with a blanket ban and no decent alternative, and they will not stop using the tools. They will stop telling you about them.

The NCSC says as much. It is not telling people to stop using AI. It expects shadow AI to persist, and says the aim should be to reduce the risk and not to pretend it can be eliminated.

So a ban does not remove the risk. It removes your view of it. The first you hear of a data leak or an invented case citation may then be a letter from a regulator, or from the other side's solicitors.


The Legal Catch-22: not using AI can be negligent too

The case for a ban usually rests on risk: confidentiality, privilege, data leakage, liability. Those risks are real. They are also only half the picture. But this argument overlooks a profound shift currently taking place across legal and corporate duties.

In July the UK Jurisdiction Taskforce published its Legal Statement on Liability for AI Harms. Its broad message is that English law does not need a new liability regime for AI. The existing law of negligence will do the job.

For professionals, that cuts both ways.

  • You can be liable for using AI badly. Choosing an unsuitable tool, skipping due diligence, putting confidential material into an insecure system, failing to check the output.

  • You can be liable for not using AI where a competent member of your profession would have. The Statement's examples include a radiologist who ignores an accurate, affordable tool for spotting tumours, and an auditor who does not use AI on transaction volumes too large to review by hand.

The Statement speaks to professionals: lawyers, accountants, surveyors, architects, clinicians. If your business sells its expertise, that means you.

Two caveats, because I am a lawyer and cannot help myself. The Statement is not binding and it is not legislation. And the test is what a reasonable professional of similar rank and specialism would have done, which shifts as adoption spreads. Nobody is being sued today for reading a contract with their own eyes.

But the standard of reasonable skill and care has never stood still. If a tool can read 5,000 disclosure documents in minutes and flag what a tired associate would miss at 2am, declining to use it will eventually stop looking like prudence.

That is the bind. Allow unmanaged use and you risk confidentiality breaches and confident nonsense in client work. Ban AI outright and you push it underground, hand ground to competitors and, in time, risk falling below the standard your clients are entitled to expect.

Damned if you do. Liable if you don't.


Take Action: Three things to do this week

Governance built on wishful thinking does not survive Monday morning. It needs visibility, accountability and clear boundaries. This is where our panel landed.

1. Declare a “Safe-Harbour” Shadow AI Amnesty

The NCSC puts it neatly: "You cannot manage what you do not know." So ask. Announce a two-week, no-blame window across the business.

  • The ask. Every team lists the AI tools, browser plug-ins, personal subscriptions and saved prompts it actually uses for work.

  • The promise. No disciplinary action for past use disclosed in the window. Put it in writing and mean it.

  • The point. An honest inventory of what your people need. If most of a team is quietly using the same summariser, you have not found a discipline problem. You have found a critical software capability your enterprise IT stack fails to provide.

One caveat. An amnesty covers discipline. It does not switch off your own obligations. If a disclosure reveals a personal data breach, you still have to assess it and, where required, report it.

2. Send every vendor one email

Shadow AI does not only arrive with your staff. It arrives inside software you already pay for. Vendors are bolting AI features onto existing products, and some switch them on by default.

Send this to every supplier that holds your data:

Please confirm in writing whether any feature, update or background process in our deployment uses large language models, machine learning or generative AI. In particular: (1) Is our data, or our clients' data, used to train or improve any model, whether yours or a third party's? (2) Where is that data processed and stored? (3) Can our administrators switch off all AI features at tenant level?

If a vendor cannot give you a clear answer quickly, treat the feature as a risk until it can. Then check the answers against your contract and your data processing agreement. What a vendor says in an email and what it has agreed to in writing are not always the same thing.

3. Give every AI Agent a named Human Owner

The deepest risk in shadow AI is diluted responsibility: the comfortable sense that the system produced it, so nobody did.

The law does not share that view. AI has no legal personality. It cannot owe a duty and it cannot be sued. A person or a company always can.

So make it a rule. Every AI agent, automated pipeline and AI-assisted workflow has a named human owner.

  • If AI drafts a clause, summarises a witness statement or screens incoming documents, a named person is recorded as the reviewer and owner of that output.

  • The owner answers for its accuracy, confidentiality and compliance.

  • "The AI hallucinated" is not a defence. It is an admission that nobody checked.


The boardroom checklist

Shadow AI: the usual approach and the better one
Area The usual approach The better approach
Staff use Ban every unapproved AI tool Run a no-blame amnesty to map real use and real need
Vendors Assume suppliers follow your existing security terms Ask in writing about model training, data location and off switches
Risk and liability Look only at the risk of using AI Weigh misuse against the risk of falling behind the professional standard
Accountability Blame the tool, the vendor or the junior Name a human owner for every AI-assisted output

A ban you cannot enforce is theatre. Knowing what is in use, who owns it and what your vendors do with your data is governance.

Banning the future has never worked. Managing it is the only option left.

If you want an AI policy your people will follow, or a second pair of eyes on what your vendor contracts say about your data, book a discovery call.


Frequently asked questions

This article is general information, not legal advice. If any of it touches a live issue in your business, take advice on your own facts.

Next
Next

A New UK Regulator - Data Protection