Client files, payroll data, source code and contracts entered into tools your organisation never assessed, on terms nobody read, where the provider may retain the content or train on it.










Client files, payroll data, source code and contracts entered into tools your organisation never assessed, on terms nobody read, where the provider may retain the content or train on it.
If personal data is involved you remain the controller for processing you never authorised, and you are expected to know where AI is used and on what lawful basis.
Invented figures, invented citations and confidently wrong summaries reaching clients unchecked, because no approved tool means no agreed process for verifying what comes out.
The hardest risk to price. If you cannot show what was entered, you cannot prove a client's data was not, which turns a routine due-diligence question into an open one.
Nine common examples
Nine places it turns up, with the question a director tends to ask about each.




Which AI services accounts have authenticated to, and whether they used a work identity or a personal one.
Third-party AI apps that have been granted standing access to Microsoft 365 mail, files or calendars, and what scope each holds.
Requests leaving the network to AI domains, which catches tools used without any sign-in at all. Microsoft documents this approach for shadow AI discovery in Entra Global Secure Access.
Browser extension inventories, plus data loss prevention alerts that show sensitive content moving toward an AI destination.
If staff enter customer or employee data into a tool you never assessed, responsibility for that processing still sits with your organisation, not with the member of staff and not with the tool.
The ICO's guidance on AI and data protection expects organisations to understand where AI is used and on what lawful basis. That is difficult to evidence while the tools remain invisible.
A policy written without knowing what is already happening usually prohibits the tools people rely on most, which pushes the same work onto personal devices where nothing is visible.

Build the inventory: which AI tools are in use, on which accounts, and by roughly how many people.

Establish what has gone in: file types, whether anything personal or commercially sensitive is involved, and whether the provider retains it.

Sort findings by what would actually hurt, so the first fixes are the ones that matter rather than the ones that are easiest.

Approve a shortlist of tools, restrict the rest, and put it in a policy people can follow.

FAQ
Answers to the questions UK businesses ask us most about Shadow AI.
Shadow AI is the use of AI tools for work without the approval or oversight of the organisation's IT or security function. It usually means consumer chatbots, browser extensions, meeting notetakers or AI features inside other apps, often on personal accounts.
Shadow AI discovery is the process of identifying every AI tool in use across an organisation, including unapproved ones, and establishing what data has been entered into them. It answers which tools are in use and what went into them, before any decision about blocking or approving.
Shadow IT is usually an unapproved application holding data. Shadow AI is data leaving the organisation inside a prompt, an upload or an integration, where it may be retained or used for training. Shadow AI needs nothing installed, so it rarely appears in expenses or software inventories.
From five signal sources your systems already produce: identity and sign-in logs, OAuth apps holding permissions on Microsoft 365, network and DNS traffic to AI domains, browser extension inventories, and data loss prevention alerts. Microsoft documents the network-level approach for shadow AI discovery in Entra Global Secure Access.
Four: data exposure when company or client information is entered into unassessed tools, regulatory exposure because you remain the controller for that processing, unreliable output reaching clients unchecked, and the absence of an audit trail, which makes the first three difficult to prove either way.
Blocking rarely works. In Microsoft's UK research, 41% used unapproved AI because it was familiar from personal life and 28% because no approved alternative existed. A ban removes neither reason, and the work moves to personal devices where nothing is logged.
Establish what went where, whether the tool retains or trains on it, and what remains within your control: deleting conversations and accounts, revoking app permissions, and deciding whether anything meets the threshold for reporting to the ICO.
Not automatically, but it makes compliance difficult to evidence. If personal data has been entered into a tool your organisation never assessed, you remain the controller for that processing, and the ICO expects you to know where AI is used and on what lawful basis.
More so, not less. Smaller teams adopt tools quickly because there is no procurement process in the way. Microsoft and LinkedIn's Work Trend Index 2024 found 78% of AI users bring their own AI tools to work, rising to 80% at small and medium-sized companies.
Discovery is included in the free Intouch Tech cyber review, which covers AI use alongside the rest of your security posture. Ongoing AI governance, which keeps the visibility in place rather than taking a snapshot, starts at £12.50 per user per month.
Mon-Fri 8am-5pm · 24/7 for managed clients
Response within 1 business day, guaranteed
UK-based team, since 2012