Shadow AI: Damned If You Do, Liable If You Don't
Your staff are already using AI you haven't approved. Banning it will not stop them. It will only make sure you are the last to know. Here is what to do instead.
The 60-second verdict
It is already in the building. Research cited by the National Cyber Security Centre in September found that 71% of UK employees have used AI tools their employer has not approved. Your people are in that number.
Bans create blindness, not compliance. Prohibition pushes AI under the desk. And the UK Jurisdiction Taskforce says professionals can be liable for misusing AI and also for failing to use it where a competent peer would have.
Three things to do this week.
Declare an amnesty.
Send every software vendor one email.
Put a named human against every AI agent in the business.
If your diary is screaming, stop reading here. I shall assume you’ve gone to do all three.
We have been here before
Cast your mind back to the late 1990s. In wood-panelled sanctuaries of the top law firms and corporate boardrooms, management committees gathered to confront a terrifying new menace: the World Wide Web.
The verdict was swift. The internet was deemed a hotbed of distraction, a vector for operational chaos, and a security nightmare. So plenty of firms banned it from the desktop. Firewalls went up. Leadership dusted off its hands.
It was a triumph of administrative delusion.
In reality, staff simply adjusted. They went home, dialled up on the family phone line (remember the modem dial-up tone?!?), did their research in the evening and emailed the results to their work inbox on Monday morning. Nothing stopped. Management had not eliminated the practice; they had merely audited themselves into total, voluntary blindness.
You are being offered the same illusion today, with AI.
It is called Shadow AI: any algorithm, browser extension, or friendly personal chatbot account operating beyond your visibility or governance. It is the keen junior tidying a client document through a personal Claude account at midnight. It is the unvetted transcription bot sitting quietly in your confidential board meeting. And, most insidiously, it is the "AI-enhanced" feature your software vendor switched on in last Tuesday's update without mentioning it to your CTO.
Last month in London, I had the privilege of moderating a panel at the AI Governance, Trust & Security Leaders Summit. I was surrounded by four veteran practitioners who manage this problem for a living. I asked them how a business is supposed to govern something it cannot see.
Astonishingly, for a stage full of lawyers and governance professionals, nobody said "it depends".
What follows is what I took from that room and from the evidence: why your policy is probably failing, why a total ban carries legal risk of its own, and how to build governance that survives contact with human nature.
A tale of two numbers
Two figures landed nine days apart in September.
On 7 September the NCSC published The hidden risks of shadow AI. It cited Microsoft research finding that 71% of UK employees have used AI tools their employer has not approved.
On 16 September Deloitte published its first GenAI Workforce Survey, with 25,000 UK workers polled by Ipsos. Almost one in ten said they had used an AI tool their employer had banned or would disapprove of.
Seventy-one per cent against roughly one in ten. They are different surveys asking different questions, so this is not a like-for-like comparison. But the distance between the two is where the problem lives.
"Not approved" is not the same as "banned". Most shadow AI is not rebellion. It sits in the space where nobody has said yes and nobody has said no. Deloitte found that 31% of people who use generative AI at work do so without their employer knowing, and most of them assume the employer would be fine with it. Half of users have had no formal guidance or training at all.
71%
of UK employees have used AI tools their employer has not approved
Microsoft research, cited by the NCSC, September 2026
31%
of UK workers who use generative AI at work do so without their employer knowing
Deloitte GenAI Workforce Survey, September 2026
Almost 1 in 10
UK workers have used an AI tool their employer has banned or would disapprove of
Deloitte GenAI Workforce Survey, September 2026
What accounts for this magnificent discrepancy? It turns out that people are remarkably candid when answering an anonymous survey about general productivity habits, and hilariously conservative when asked if they personally break firm policy.
When an employee is asked, "Do you use modern software to complete three hours of work in twenty minutes?" they beam with pride and answer yes. When asked, "Are you violating Section 4.2 of the IT Acceptable Use Policy?" they suddenly develop severe amnesia.
Your staff are not acting out of malice. They are trying to keep their heads above a rising tide of work with the best tools they can find. Meet that with a blanket ban and no decent alternative, and they will not stop using the tools. They will stop telling you about them.
The NCSC says as much. It is not telling people to stop using AI. It expects shadow AI to persist, and says the aim should be to reduce the risk and not to pretend it can be eliminated.
So a ban does not remove the risk. It removes your view of it. The first you hear of a data leak or an invented case citation may then be a letter from a regulator, or from the other side's solicitors.
The Legal Catch-22: not using AI can be negligent too
The case for a ban usually rests on risk: confidentiality, privilege, data leakage, liability. Those risks are real. They are also only half the picture. But this argument overlooks a profound shift currently taking place across legal and corporate duties.
In July the UK Jurisdiction Taskforce published its Legal Statement on Liability for AI Harms. Its broad message is that English law does not need a new liability regime for AI. The existing law of negligence will do the job.
For professionals, that cuts both ways.
You can be liable for using AI badly. Choosing an unsuitable tool, skipping due diligence, putting confidential material into an insecure system, failing to check the output.
You can be liable for not using AI where a competent member of your profession would have. The Statement's examples include a radiologist who ignores an accurate, affordable tool for spotting tumours, and an auditor who does not use AI on transaction volumes too large to review by hand.
The Statement speaks to professionals: lawyers, accountants, surveyors, architects, clinicians. If your business sells its expertise, that means you.
Two caveats, because I am a lawyer and cannot help myself. The Statement is not binding and it is not legislation. And the test is what a reasonable professional of similar rank and specialism would have done, which shifts as adoption spreads. Nobody is being sued today for reading a contract with their own eyes.
But the standard of reasonable skill and care has never stood still. If a tool can read 5,000 disclosure documents in minutes and flag what a tired associate would miss at 2am, declining to use it will eventually stop looking like prudence.
That is the bind. Allow unmanaged use and you risk confidentiality breaches and confident nonsense in client work. Ban AI outright and you push it underground, hand ground to competitors and, in time, risk falling below the standard your clients are entitled to expect.
Damned if you do. Liable if you don't.
Take Action: Three things to do this week
Governance built on wishful thinking does not survive Monday morning. It needs visibility, accountability and clear boundaries. This is where our panel landed.
1. Declare a “Safe-Harbour” Shadow AI Amnesty
The NCSC puts it neatly: "You cannot manage what you do not know." So ask. Announce a two-week, no-blame window across the business.
The ask. Every team lists the AI tools, browser plug-ins, personal subscriptions and saved prompts it actually uses for work.
The promise. No disciplinary action for past use disclosed in the window. Put it in writing and mean it.
The point. An honest inventory of what your people need. If most of a team is quietly using the same summariser, you have not found a discipline problem. You have found a critical software capability your enterprise IT stack fails to provide.
One caveat. An amnesty covers discipline. It does not switch off your own obligations. If a disclosure reveals a personal data breach, you still have to assess it and, where required, report it.
2. Send every vendor one email
Shadow AI does not only arrive with your staff. It arrives inside software you already pay for. Vendors are bolting AI features onto existing products, and some switch them on by default.
Send this to every supplier that holds your data:
Please confirm in writing whether any feature, update or background process in our deployment uses large language models, machine learning or generative AI. In particular: (1) Is our data, or our clients' data, used to train or improve any model, whether yours or a third party's? (2) Where is that data processed and stored? (3) Can our administrators switch off all AI features at tenant level?
If a vendor cannot give you a clear answer quickly, treat the feature as a risk until it can. Then check the answers against your contract and your data processing agreement. What a vendor says in an email and what it has agreed to in writing are not always the same thing.
3. Give every AI Agent a named Human Owner
The deepest risk in shadow AI is diluted responsibility: the comfortable sense that the system produced it, so nobody did.
The law does not share that view. AI has no legal personality. It cannot owe a duty and it cannot be sued. A person or a company always can.
So make it a rule. Every AI agent, automated pipeline and AI-assisted workflow has a named human owner.
If AI drafts a clause, summarises a witness statement or screens incoming documents, a named person is recorded as the reviewer and owner of that output.
The owner answers for its accuracy, confidentiality and compliance.
"The AI hallucinated" is not a defence. It is an admission that nobody checked.
The boardroom checklist
| Area | The usual approach | The better approach |
|---|---|---|
| Staff use | Ban every unapproved AI tool | Run a no-blame amnesty to map real use and real need |
| Vendors | Assume suppliers follow your existing security terms | Ask in writing about model training, data location and off switches |
| Risk and liability | Look only at the risk of using AI | Weigh misuse against the risk of falling behind the professional standard |
| Accountability | Blame the tool, the vendor or the junior | Name a human owner for every AI-assisted output |
A ban you cannot enforce is theatre. Knowing what is in use, who owns it and what your vendors do with your data is governance.
Banning the future has never worked. Managing it is the only option left.
If you want an AI policy your people will follow, or a second pair of eyes on what your vendor contracts say about your data, book a discovery call.
Frequently asked questions
-
Shadow AI is any AI tool used for work outside an organisation's approved systems and processes. It covers personal chatbot accounts, browser extensions, meeting transcription bots and AI features that a software vendor switches on without telling you. The National Cyber Security Centre treats it as a form of shadow IT.
-
Very common. Microsoft research cited by the National Cyber Security Centre in September 2026 found that 71% of UK employees have used AI tools their employer has not approved. Deloitte's GenAI Workforce Survey of 25,000 UK workers found that 31% of people who use generative AI at work do so without their employer's knowledge.
-
A blanket ban rarely works. People keep using the tools and stop telling you, so you lose sight of where your data is going. The National Cyber Security Centre is not recommending that people stop using AI and says the aim should be to reduce the risk. Approve tools that meet real needs, set clear rules and find out what is already in use.
-
Potentially, if you are a professional. The UK Jurisdiction Taskforce's Legal Statement on Liability for AI Harms, published in July 2026, says a professional could be liable in negligence for failing to use AI where a competent member of their profession would have done so. The Statement is not binding, but earlier UKJT statements have been followed by the English courts.
-
It is a short, no-blame window, for example two weeks, in which staff disclose every AI tool they use for work without fear of disciplinary action. The aim is an honest inventory of what is in use and why. It does not remove the organisation's own obligations, so a disclosed incident that amounts to a personal data breach must still be assessed and, where required, reported.
-
Ask three things in writing. Does any feature in our deployment use AI, and is our data used to train or improve any model? Where is that data processed and stored? Can our administrators switch AI features off at tenant level? Then check the answers against your contract and data processing agreement.
-
A person or a company, never the AI. Under English law AI has no legal personality, so it cannot owe duties or be liable. Liability falls on the people and businesses that build, deploy or use it, under ordinary legal principles. That is why every AI agent and AI-assisted workflow should have a named human owner who checks the output.
This article is general information, not legal advice. If any of it touches a live issue in your business, take advice on your own facts.

