Mist rising off still water at the edge of a dense treeline

Governance

Shadow AI is already in your firm. Here is the map.

Nobody filed a request. Nobody signed anything. The tools arrived one deadline at a time, and by now they are woven into how your firm actually works.

Ask a managing partner how many AI tools are in use across the firm and you will usually get a number between zero and three. Ask the staff anonymously and the number moves. In one dataset covering engagements at hundred person companies, browser telemetry showed between fourteen and twenty two distinct generative AI services in regular use. One or two of them had ever been approved by anyone.

That gap is what people mean by shadow AI. It is not a story about rule breaking. It is a story about a workforce that found a faster way to finish and did not think to ask, because nothing in the firm told them asking was required.

Why the number is always higher than leadership thinks

Three things drive the gap, and none of them involve bad intent.

  • The tools stopped being separate products. AI features now ship inside software your firm already licenses. A summarise button in a meeting tool, a drafting assistant in a document editor, a categorisation feature in an accounting platform. Nobody experiences using those as adopting an AI tool.
  • Adoption spreads sideways, not downward. One person finds something useful and tells a colleague. Within a quarter it is normal practice on that team and entirely invisible to the floor above.
  • Asking has a cost and using does not. A staff member who asks permission risks a no, a delay, or a conversation about why they need it. A staff member who just uses it faces none of that. The incentives are doing exactly what you would predict.

The exposure is not created by the tools. It is created by the fact that nobody can name them.

What is actually at risk

For a professional services firm the risk is rarely the tool itself. It is the data category that moved into it, and the obligations attached to that category.

In accounting, submitting client information to a third party platform can be treated as disclosure under the profession's confidentiality rules. Tax preparers carry additional statutory exposure. Firms handling financial data may fall under safeguards obligations they have not mapped against AI use at all. In law, the privilege question is not settled in a way anyone should want to test with their own matter.

Research published in 2025 found that forty six percent of US accounting firms had inadvertently entered confidential client information into public AI services. That figure is worth sitting with, because it describes firms that are, in every other respect, careful.

Separately, IBM's breach research found that sixty three percent of breached organisations had no AI governance policy in place, and that incidents involving shadow AI added an average of six hundred and seventy thousand dollars to the cost of the breach. The number is not a prediction for your firm. It is an indication of what the insurance market has started pricing.

Why blocking does not solve it

The instinct is to have IT block the domains. It is a reasonable first move and it is roughly a third of an answer.

Blocking covers managed devices. It does not cover personal phones, home machines, browser extensions, or the AI features embedded in software you deliberately pay for. More importantly, it does nothing about the reason the tool was reached for in the first place. The pressure that drove someone to paste a client memo into a free tool at nine at night does not disappear because the domain stopped resolving. It relocates.

Technical controls and process controls solve different halves of this problem. Most firms have one of them and believe they have both.

The map, in four moves

What replaces the guessing is a short, specific exercise. It takes about ninety minutes of leadership time.

1. Ask leadership what they believe

Write it down before you look. Which tools do you think are in use, who approved them, what data do you believe touches them. This becomes the comparison point, and the gap between this answer and the next one is the finding.

2. Ask the team anonymously

Five questions, two minutes, genuinely anonymous, sent under the owner's name. Anonymity is not a courtesy here, it is the mechanism. People do not tell the person who signs their pay that they pasted a client file into a chatbot. They will tell a form that cannot identify them, and they do.

3. Map data, not tools

A list of tools is not exposure. Exposure is which categories of information moved into which service, under whose account, and whether that vendor trains on what it receives. Client identifying data, financial records, health information, privileged material, internal working documents. Each one gets a row.

4. Separate this week from this quarter

Every review of this kind produces three things that can be fixed immediately at no cost, and one thing that requires real ownership. Naming which is which is most of the value, because the three easy ones get done and the hard one stops being ignored on the grounds that everything looks equally large.

The uncomfortable part. The exercise usually surfaces at least one thing the owner would rather not have learned. That is the point of running it now rather than learning it from a client, an underwriter, or a regulator, none of whom will present it as neutrally.

What good looks like ninety days later

Not zero AI use. A firm with zero AI use in 2026 has either a very unusual workforce or a reporting problem.

What good looks like is a named list of sanctioned tools, a written rule about which data may enter them, a signed acknowledgement from every member of staff, and a person whose job includes revisiting the list when it goes stale. That is the whole of it. It is a smaller piece of work than the anxiety around it suggests, and it converts a question you have been avoiding into a document you can hand to anyone who asks.

Where this goes next

The exposure review is described in full on shadow AI exposure. The document it usually leads to is covered under AI use policy. Related reading: the AI policy your insurer is about to ask about.

Find out what is actually in use.

Book a first call