Plainstart Back to the kit

Article

Shadow AI: How to Find Out Which AI Tools Your Staff Already Use

Shadow AI is not a scandal. It is a visibility problem. Your staff are probably using AI tools right now, without telling you, because no one told them the rules. This article explains how to find out what is happening, without making people defensive, and what to do with the answer.

What Shadow AI Actually Means

Shadow AI means AI tools being used at work without the knowledge or approval of the business owner or IT lead. It includes ChatGPT, Grammarly, Notion AI, Otter.ai, Midjourney, Perplexity, Google Gemini, and dozens of others. Some are free. Some are paid on a personal card. Some are built into software your team already uses.

It is called "shadow" because it happens out of sight, not because it is malicious.


Why It Happens

Staff do not hide AI use because they are trying to cause problems. They hide it, or simply never mention it, for a few straightforward reasons.

No policy exists. If you have never told people what is or is not acceptable, they fill the gap themselves. Using a free AI tool to draft a report feels no different to them than using Google.

They expect a ban. Some staff assume any official attention will result in a prohibition. Saying nothing feels safer than asking permission and being told no.

It feels like a personal productivity trick. People who use AI often see it the way they see keyboard shortcuts. It is how they get work done faster. It does not occur to them that it affects anything beyond their own desk.

The tools are frictionless. Most shadow AI requires no IT installation, no company email, and no visible cost. It disappears into normal browser use.

None of this means the tools are safe to use without oversight. Confidential data entered into a third-party AI tool may be stored, used for training, or exposed in a breach. That is the problem. The goal here is to see what is happening so you can manage the risk, not to catch anyone out.


Why Asking Directly Works, When Framed Without Blame

The instinct is to investigate quietly. Pull browser logs, check expense reports, ask IT. That is a reasonable second step. The first step, which many owners skip, is simply asking.

A direct question, framed correctly, gets honest answers more often than you might expect. People are not ashamed of using AI. They are cautious about how management will react. If you remove that concern, most will tell you exactly what they use.

The framing matters.

Blame-laden framing: "We need to know if anyone has been using unauthorised AI tools."

Neutral framing: "We are building an AI policy and we want to understand what tools people already find useful. There are no wrong answers and nothing gets anyone in trouble."

The second version signals that you are moving forward, not looking backward. It gives people a reason to be honest because honesty helps them. It also tends to surface tools you would not have thought to ask about.


Practical Ways to Find Out

1. Run a Short No-Blame Survey

Keep it anonymous if your team is small enough that people might worry about being identified. Five questions is enough.

Suggested questions:

  • Have you used any AI tools for work tasks in the last three months? Yes, no, not sure.
  • If yes, which tools? (Free text.)
  • What do you use them for? (Drafting, summarising, research, images, other.)
  • Do you use any tools your employer does not pay for?
  • Is there anything that would make you more or less comfortable using AI at work?

Send it via a Google Form, Typeform, or Microsoft Forms. Give people a week. The point is not a perfect response rate. Even partial responses tell you a lot.

2. Check Expense Claims and Subscriptions

Look at company card statements and expense reimbursements for the last six months. Filter for anything from OpenAI, Anthropic, Adobe Firefly, Jasper, Copy.ai, Runway, ElevenLabs, or any unfamiliar software name. People who use AI seriously often pay for premium tiers. If they are expensing it or asking for reimbursement, it is visible.

Also check your SaaS subscription list. Several tools your business already pays for, including Microsoft 365, Notion, Zoom, Salesforce, and HubSpot, now include AI features that may be active by default.

3. Look at Browser Extensions

Ask your IT lead, or check yourself on company devices, for browser extensions. AI writing assistants, summarisers, and grammar tools often live here. Grammarly is the most common example. There are many others. Extensions have access to everything typed in a browser, including client data, internal documents, and login pages. Knowing which ones are installed is basic hygiene.

If your team works from personal devices, you cannot audit extensions directly. The survey is your best tool there.

4. Ask What People Use at Home for Work Tasks

This is the question most owners forget. A staff member might use their own ChatGPT account at home to help write a proposal, then paste the result into a work document. No company device, no company account, no expense claim. Completely invisible unless you ask.

Add a question to your survey or a one-to-one conversation: "Is there anything you use at home that helps with your work, even if you would not call it a work tool?" You will get useful answers.

5. Have One-to-One Conversations

A survey gives you breadth. A short conversation gives you depth. Pick two or three staff who are likely early adopters, the people who tend to find new software first, and ask them directly. Tell them you are trying to get ahead of the AI question before putting any rules in place. Ask what they have found useful and what they would want a policy to allow.

People who have invested time learning a tool will tell you about it if they believe the conversation is about enabling rather than restricting.


What to Do With the Answer

Once you have a clearer picture, you have four practical steps.

Document what you find. Make a simple list: tool name, what it is used for, who uses it, whether it has access to company or client data. This is your baseline. You cannot manage what you have not recorded.

Separate low-risk from high-risk use. A tool that autocorrects spelling is different from a tool that processes client emails or summarises contracts. The first is low risk. The second needs scrutiny. The key question for any tool is: what data does it process, where does that data go, and what does the provider do with it?

Decide what to allow, what to restrict, and what to require. Not every tool needs to be banned. Some should be approved with conditions. A few may need to stop. Make those decisions explicitly rather than letting the default continue.

Write a usage policy and share it. This is the step that closes the loop. Staff cannot follow rules that do not exist. A clear, readable AI usage policy tells people what they can use, what they cannot, what data must never be entered into an AI tool, and who to ask when they are unsure. It removes the ambiguity that causes shadow AI in the first place.


A Note on Proportionality

The goal here is visibility, not punishment. If you discover that a member of staff has been using ChatGPT to draft their weekly reports for six months, the right response is a conversation and a policy, not a disciplinary process. The risk you are managing is data exposure and compliance, not personal honesty.

Be clear with your team that the audit is about putting proper structure in place, not about finding fault. Say it plainly, more than once. The more your staff trust that this is true, the more honest information you will get.


This article is general business guidance only. It is not legal, compliance, or professional advice. If you handle regulated data or operate in a sector with specific compliance requirements, take advice from a qualified professional before finalising any AI policy.


Start With a Free AI Usage Policy

Once you know which tools your team is using, the next step is a written policy. Plainstart offers a free AI Usage Policy at getplainstart.com/free-policy. It is plain language, written for small and medium businesses, and you can adapt it to your situation. No signup wall.

AI adoption, done properly.

Free download

The AI Usage Policy your team can actually follow

One page, plain language, ready to put in front of staff today. No cost, no catch.

Get the free policy