Business practice
Shadow AI exposure.
Know exactly what your team is putting into AI tools, what client data went with it, and what to do about it this week.
You have not asked your team what they are using. Not because you do not care, but because you are not sure you want the answer.
The tools arrived without a decision. Someone tried one on a deadline, it worked, and it spread. Nobody filed a request, nobody signed anything, and the first time it becomes a subject is when a form asks whether your firm has a written policy. You suspect the honest answer and you would rather not put it in writing.
Two weeks from now that is no longer where you sit. You know which tools are in use, who is using them, and which categories of client data have passed through them. You have a short list you can act on immediately and one longer item that needs real work. The uncertainty is gone, and what replaces it is a decision you get to make on purpose.
The approach
Ask, map, then act.
Ask anonymously.
Nobody tells the owner they pasted a client file into a chatbot. They will tell an anonymous survey, and they do. The gap between what leadership believes and what the team reports is the finding, and it is almost always wider than expected.
Map the data.
A tool list is not exposure. Exposure is which categories of information moved into which tool, under whose account, and whether that vendor trains on what it receives. That mapping turns a vague worry into a specific, finite list.
Act this week.
Every exposure review ends with three things you can do immediately at no cost, and one thing that will still be there in six months if nobody owns it. Knowing the difference is most of the value.
The situation, in numbers
This is not a rare problem.
46%
Of US accounting firms have entered confidential client information into public AI services
63%
Of breached organisations had no AI governance policy in place
670k
Average dollars added to breach cost where shadow AI was involved
Sources: KPMG AI Adoption Across Finance Functions, 2025. IBM Cost of a Data Breach, 2025. Figures are industry research, not client results.
Recognise this
You already know the answer to one of these.
- You could not name every AI tool in use in your firm today.
- Nobody has ever formally approved a tool, and several are clearly in use.
- Your insurance renewal or a client questionnaire has asked about AI, and the answer was uncomfortable.
- Someone on your team is visibly faster than they were last year and you have not asked why.
- You have thought about raising it in a meeting and decided the timing was never right.
The work
Four steps, about ninety minutes of your time.
The leadership conversation
Thirty minutes with the person who signs. Six questions covering what you believe is in use, what data touches it, who approved it, what happens when a key person is out, where work gets redone, and what you bought this year that nobody opens.
The anonymous team survey
Five questions, two minutes to answer, sent under your name. Anonymity is the point. This is where the accurate picture comes from, and it is the half of the exercise that cannot be replaced by an assumption.
The exposure map
One page, back within seventy two hours. Tools in use against tools approved. Data categories at risk. The specific places where a client confidentiality obligation and a free tool are currently in the same sentence.
The short list
Three actions you can take this week without spending anything, and one item that needs real ownership. Useful whether or not the conversation goes any further, which is how a diagnostic should be built.
Related reading.
All insights
Governance
Shadow AI is already in your firm. Here is the map.
The median hundred person company shows between fourteen and twenty two distinct generative AI services in its browser telemetry. One or two of them are approved. The gap is not a technology problem and it is not solved by blocking domains, because the work that drove people to those tools does not go away when
Governance
The AI policy your insurer is about to ask about
Cyber and professional liability renewals added a question this year, and most firms cannot answer it yet. A defensible answer is shorter than people expect, but it has four specific parts, and a policy missing any one of them will not survive the follow up question from an
Questions
Asked before, answered plainly.
No, and the exercise is designed so that it cannot. The survey is anonymous and results are reported in aggregate, never by individual. The framing to your team is that leadership is deciding which tools to support, which is true. People who fear discipline give you inaccurate answers, and inaccurate answers make the whole exercise worthless.
Then you found it before someone else did, which is the entire reason to look. Serious findings come with immediate containment steps in the same report. Nothing is disclosed to anyone outside your firm, and the report belongs to you. What you do with it, including nothing, is your call.
The report is useful on its own and it is yours to keep either way. Three of the four recommendations are things your team can do without us, and we tell you that in writing. If the fourth one is worth engaging on, we will say so and describe what that would look like. If it is not, we will say that instead.
Blocking handles the managed devices you know about. It does not handle personal phones, home machines, browser extensions, or the features quietly added inside software you already license. It also does nothing about the underlying reason people reached for the tool. Technical controls and process controls solve different halves of the problem, and firms usually have only one of them.
Thirty minutes on a call, and about five minutes to forward a survey link to your team. Their part takes two minutes each. Everything after that is on our side, and the report comes back within seventy two hours.