Guide

Your staff are already using AI. You just don't know what they've sent.

By Gershom Lewis · August 2026

A paralegal has a client letter to tidy up. It's 4:40 on a Thursday. She opens a free AI chatbot, pastes the whole letter in — client name, matter, numbers — and asks it to make the tone firmer. Twelve seconds later she has a better letter. And the owner of that firm has no idea it happened, no record that it happened, and no way to find out.

She did nothing anyone told her not to do. There was no policy. The firm doesn't have an AI tool, so she used the one that was free and already open. This is happening in your business right now.

Why you don't know

Shadow AI is invisible in a way most technology risk isn't. No software to install, so it never crosses IT's desk. No invoice, so it never appears in the books. It happens in a browser tab that closes.

And crucially — it works. The letter was better. Nobody has any reason to mention it, because from where they're standing they didn't do anything wrong. They did their job well.

Your people are not the problem

Your staff aren't being careless. They're being effective. They found a tool that removes friction from work they're judged on. That's the behaviour you hire for.

The failure isn't theirs. Nobody gave them a rule, and nobody gave them a sanctioned alternative. In the absence of both, people default to whatever works.

So when you find out how much of this is happening — do not make an example of anybody. The moment you do, it doesn't stop. It moves somewhere you can't see.

What's actually at risk

You may have lost the ability to say where client information is. A law firm's duty of confidentiality has no "but the tool was free" exception. If you handle patient information, the agreement was never signed with the tool your front desk used.

"We don't train on your data" is a promise about the paid tier. The free tier your staff are using may be governed by entirely different terms.

You can't answer the three questions: what went out, who sent it, and can you prove it's gone. Not because the answer is bad — because there is no record at all.

The mistake almost every owner makes

The instinct is to send an email banning AI tools. Don't.

A ban doesn't stop the behaviour. It moves it. The paralegal who used a browser tab on the office computer now uses the same tool on her phone, on her own account, at lunch. Same client data. Same third party. Except now it's on a device you don't own, under an account you can't audit, and she won't tell you — because now she'd be admitting to breaking a rule.

A ban is not a policy. A ban is a policy that relocates the activity to a phone you can't see.

What a real policy looks like

It fits on one page and it has four parts.

1. The approved tool

Name it. One tool — the business-tier account the company pays for. Owners skip this part, and skipping it is why the rest fails. If you don't provide something, you've banned the thing without replacing it, and you're back to the phone at lunch.

2. The green light / red light list

Not principles — examples, in your own business's language.

✅ Green light: rewriting a job posting · drafting a social post · summarizing a public article · brainstorming · cleaning up your own internal notes · general "how do I..." questions.

🛑 Red light: client, patient or customer names · case or medical or account details · financial statements · anything from a file with someone's name on it · contracts · employee records · passwords or logins, ever.

The test people actually remember: if it has a person's name on it, it doesn't go in. That one sentence will do more than three pages of policy.

3. What to do when you're unsure

Give them a person and permission. "If you're not sure, ask — you will never be in trouble for asking." Without this, unsure defaults to yes, because the work still has to get done by five.

4. What gets logged

Say plainly what's recorded and why: not to police people, but so the business can answer when somebody asks. Framed that way, staff are almost always fine with it.

First, find out what's already happening

Before the policy, one conversation. Not an investigation — an amnesty. Ask openly: "Who's been using AI to help with work? I'm not asking to get anyone in trouble — I want to know what's useful so we can get the right version of it."

You'll learn how much is happening, which tasks people actually need help with (your automation roadmap, free), and who your early adopters are. Run it punitively and you'll learn nothing and lose visibility for good.

None of this is new

Acceptable-use policy. Data classification. Sanctioned tooling. Audit trail. These are the ordinary controls enterprise IT has run for thirty years. I spent those thirty years inside them — hospitals, a major international law firm, a sixty-branch public library system.

We solved this before. When staff forwarded work email to personal accounts. When USB drives showed up. Every time the answer was the same: provide a sanctioned option, be specific about the line, log enough to answer questions, and don't punish people for solving problems you hadn't solved for them.

The takeaway

You don't have a shadow AI problem in the future. You have one now. The only decision is whether it stays invisible.

One page. One approved tool. One clear line: if it has a person's name on it, it doesn't go in. You can have that in place by Friday.

Not sure where AI fits your business?

That's the whole point of a free 30-minute Executive Intelligence Assessment — a real look at what could run itself.

Book your free assessment See our services
4) To go live: copy everything from
Let's talk 👋
Vannah● Eleven Bridges AI · online×