Your Employees Are Already Using AI: What Small Businesses Need to Check Now

Your Employees Are Already Using AI: What Small Businesses Need to Check Now

INCBOOK • AI AT WORK • 2026

Your Employees Are Using AI Anyway

The 15-minute Shadow-AI Audit for small businesses — find the AI tools already inside your workflow, draw a hard line around sensitive information, and give employees rules they can actually follow.

Updated October 5, 2026
I’ve watched this movie before with personal email, Dropbox, messaging apps and half a dozen other technologies. Somebody finds a tool that saves twenty minutes, starts using it quietly, and the company writes a policy six months later. AI is moving faster than any of those. Your salesperson does not think he is creating a cybersecurity problem when he pastes a customer email into a chatbot and asks it to clean up the response. Your office manager does not think she is creating a privacy issue when an AI meeting bot joins a call. They are trying to get work done. The problem is not that employees discovered AI. The problem is that nobody told them where the guardrails are.
54% of surveyed small businesses said employees use public AI chatbots or writing tools for work
39% of small-business owners believed employees were using unauthorized AI tools
28% of small businesses had rules on what company or customer data may be entered into AI
28% had procedures for verifying AI output before using it in business decisions
The real problem

Shadow AI is not somebody installing a robot behind your back

It is usually much more ordinary: an employee opens an AI website, signs in with a personal account, pastes in some work, gets a useful answer and does it again tomorrow.

IBM defines shadow AI as AI used without formal approval or oversight. In practice, that can include public chatbots, AI note takers, browser extensions, coding assistants, image generators, transcription services, résumé tools and AI features quietly added to software your company already uses.

The audit question is not “Does anyone here use ChatGPT?”
Ask instead: “What AI tools have you used for work in the last 30 days, and what kind of information did you give them?” That catches far more of the actual exposure.

Obvious AI

  • Chatbots used to write, summarize or research
  • AI image and video generators
  • AI coding assistants
  • Dedicated AI research tools
  • Standalone transcription services

The AI owners often miss

  • Meeting bots automatically joining customer calls
  • Browser extensions reading pages or email
  • AI built into CRM, accounting or help-desk software
  • Email plug-ins that draft replies from message history
  • File-analysis tools employees discover on their own

NIST’s Generative AI Profile specifically recommends maintaining an inventory of organizational generative-AI systems and accounting for embedded AI inside other applications. For a 15-person company, that does not mean buying governance software. A spreadsheet with tool, user, purpose, data used, account type and approval status is already a major improvement.

Why now

Employees are moving faster than company policy

Nationwide commissioned Edelman Intelligence to survey 300 small-business owners and 300 mid-market business owners in July 2026. Small businesses were defined as companies with 1–50 employees and less than $10 million in annual revenue.

2026 Nationwide finding Small business Mid-market
Employees use public AI chatbots/writing tools 54% 65%
Employees believed to be using unauthorized AI tools 39% 30%
Written AI-use policy or guidelines 35% 36%
Employee responsible-use training 35% 39%
Rules governing company/customer information entered into AI 28% 26%
Procedure for verifying AI information used in business decisions 28% 21%
Designated person/team responsible for AI oversight 20% 21%
The uncomfortable number
Among surveyed small businesses, public chatbot use was almost twice as common as having rules about what information employees were allowed to put into those tools.
What can leak

The dangerous part is often the prompt, not the answer

A useful way to think about an unreviewed AI service is as an outside third party. The provider’s retention, training, access controls, account settings and contractual protections vary by product and plan. That is why “we use AI” tells you almost nothing about the actual risk.

NIST identifies data privacy, information security and intellectual-property concerns around generative AI. OWASP likewise lists sensitive-information disclosure among the major risks of LLM applications and specifically identifies personal information, financial information, confidential business information, credentials and legal documents as sensitive categories.

The easiest employee rule: If you would be uncomfortable emailing the information to an outside vendor you have never vetted, do not paste it into an unapproved AI tool.
The data traffic light

What employees should — and should not — put into AI

Level Information Practical rule
Red Passwords, API keys, authentication codes, private keys Never enter into a public or unapproved AI system.
Red Customer PII: Social Security numbers, driver’s-license data, bank details, card data, medical data, private addresses Do not enter unless the company has specifically approved the system and the use case.
Red Employee records: payroll, health information, discipline, background checks, performance records Keep out of unapproved AI tools.
Red Trade secrets and confidential business data: formulas, source code, unreleased products, proprietary processes Use only within specifically authorized environments and workflows.
Red Legal or privileged material Do not upload casually. Confirm the tool and use are acceptable with counsel where needed.
Red Nonpublic financial or deal information: acquisitions, forecasts, pricing strategy, bids, unpublished results Treat as confidential company information.
Caution Internal emails, proposals, customer correspondence, contracts, meeting notes Remove names and sensitive details or use an approved business AI environment.
Caution Business datasets and spreadsheets Ask what fields are included before uploading the entire file.
Usually OK Public information already published on your website Generally low sensitivity, subject to normal accuracy/IP review.
Usually OK Generic brainstorming, outlines, templates and non-confidential copy Good candidates for approved AI use.
“But I removed the customer’s name” is not always enough.
A contract, complaint, medical narrative, sales record or internal incident report may still identify a person or company from context. When the underlying material is sensitive, anonymization needs more thought than deleting the first line.
Not all AI is equal

“Chatbot” is not a security classification

There can be a substantial difference between an employee using a personal consumer account and a company-approved business or enterprise service with negotiated terms, administrative controls and defined data-handling settings.

Ask before approving a tool

  • Is business data used to train provider models?
  • How long are prompts, files and outputs retained?
  • Can administrators control users and access?
  • Does the provider support MFA or company sign-in?
  • Can users delete data?
  • What happens to uploaded files?
  • Are subcontractors or integrations involved?

Then ask about the workflow

  • What information will employees put into it?
  • What decisions will depend on its output?
  • Will AI communicate directly with customers?
  • Can it act inside email, CRM or financial systems?
  • Who reviews AI output before it leaves the company?
  • Who owns the account if the employee leaves?
  • Who is responsible when it produces something wrong?

NIST recommends organizations review third-party generative-AI technologies, consider vendor contracts and data practices, and continuously monitor third-party systems once deployed.

The second risk

Your data can stay private and the AI can still be wrong

Shadow AI is not only a leakage problem. An employee can use a perfectly legitimate tool, enter harmless information and still receive a confident answer that is incomplete, invented or simply based on the wrong assumption.

NIST calls this risk confabulation: confidently stated but erroneous or false content. Nationwide found only 28% of surveyed small businesses had procedures for verifying AI-generated information before it was used in business decisions.

A policy needs an output rule as well as an input rule.
AI can draft. AI can summarize. AI can suggest. The employee remains responsible for checking facts, calculations, citations, legal claims, customer promises and other consequential output before use.
Common trouble spots

Seven shadow-AI workflows worth checking first

Workflow What gets exposed Better control
“Summarize this customer email” Names, account details, complaints, deal information Use approved AI or strip sensitive details first.
“Review this contract” Pricing, terms, confidential negotiations, legal material Use a reviewed system and establish a legal-data rule.
AI meeting bot Entire conversations, voices and transcripts Approve specific services and define meeting types where recording/AI is allowed.
“Fix this code” Source code, credentials, internal hostnames, architecture Use an approved coding environment and scan prompts for secrets.
“Analyze this spreadsheet” Customer, employee, sales or financial data Remove unnecessary fields or use an approved protected workspace.
AI résumé screening Applicant personal data and potentially consequential decisions Require human oversight and review legal/compliance implications.
AI-written customer answer Potentially false claims, bad commitments or invented policies Human review before external use, especially for high-stakes answers.
The wrong response

A blanket ban can turn visible AI into invisible AI

If employees have a genuine productivity reason to use AI, a policy that simply says “AI prohibited” may not eliminate demand. It can push the same work onto personal phones, personal accounts and tools the owner cannot see.

Give employees a legal lane, not just a fence. Name the approved tool or tools. State what information may be used. State what information may not be used. Explain when human review is required. Give employees somebody to ask when the answer is not obvious.

This is also the direction suggested by NIST’s approach: acceptable-use rules, inventory, defined oversight and risk-based management rather than treating every AI use as identical.

The 15-minute audit

You can find most of the obvious exposure before the next staff meeting ends

This is triage, not a full cybersecurity or legal audit. The purpose is to answer five questions fast: What are we using? What are we feeding it? What is approved? Who checks the output? Who owns this?

Minute 0–3
Inventory the tools
Ask employees which chatbots, meeting bots, browser add-ons, coding tools, image tools and AI features they have used for work in the last 30 days.
Minute 3–6
Inventory the data
For each tool, write down what goes in: public copy, email, contracts, customer data, spreadsheets, source code, meeting audio or something else.
Minute 6–9
Draw the red line
Immediately pause unapproved use involving credentials, sensitive personal data, legal material, customer records, proprietary code or trade secrets.
Minute 9–12
Choose the lane
Name approved tools and use cases. Decide whether employees must use company accounts and which tasks require management approval.
Minute 12–15
Assign ownership
Pick one person to maintain the list, approve new tools, answer questions and review the policy every few months.
Use a no-blame first sweep.
If the first announcement sounds like an investigation, employees will tell you about the approved tools and forget the others. Tell them the goal is to understand what saves them time so the business can approve safer ways to keep doing it.
One-page policy

A small business does not need a 38-page AI governance manual

Sample Small-Business AI Use Policy

Approved tools: Employees may use only AI services approved by the company for business work. New tools, plug-ins, meeting bots and AI integrations should be approved before company information is submitted to them.

Sensitive information: Passwords, authentication secrets, sensitive personal information, private customer or employee records, confidential legal material, trade secrets, proprietary source code and other restricted business information may not be entered into unapproved AI services.

Company accounts: Where the company provides an approved business AI account, employees should use that account rather than a personal account for company work.

Human review: Employees are responsible for checking AI-generated facts, calculations, citations and recommendations. AI output that affects customers, finances, hiring, legal matters, safety or other significant decisions must receive appropriate human review.

External communications: Employees may not allow an AI tool to make commitments, publish content, communicate with customers or take consequential actions on behalf of the company unless that workflow has been specifically approved.

Questions and incidents: Employees should report accidental sensitive-data uploads, questionable output or uncertain uses promptly. Employees will not be penalized simply for asking whether a proposed AI use is permitted.

Certain industries need more.
Healthcare, financial services, legal practices, government contractors and businesses handling regulated or contractually restricted information may need stricter controls. For example, the American Bar Association has specifically warned lawyers to evaluate confidentiality risks before placing client information into generative-AI tools.
The owner checklist

Ten controls that cover a surprising amount of ground

  • Maintain a simple list of AI tools in use.
  • Name at least one approved AI option.
  • Require company accounts where practical.
  • Publish a short list of prohibited data.
  • Require approval before adding AI meeting bots or integrations.
  • Require human verification of important output.
  • Review provider data handling before sensitive use.
  • Give one person ownership of AI policy.
  • Create a way to report accidental uploads quickly.
  • Re-run the tool inventory every quarter.
Research basis: Nationwide 2026 Cybersecurity Survey, fielded by Edelman Intelligence; NIST Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1); NIST AI Risk Management Framework resources; CISA generative-AI safety guidance; OWASP GenAI Security Project, Sensitive Information Disclosure; IBM research and guidance on shadow AI; U.S. Small Business Administration guidance on AI for small business; American Bar Association Formal Opinion 512 regarding generative AI and client confidentiality.
Interactive Shadow-AI Audit

How exposed is your business?

Check every statement that is true today. The score is designed to surface governance gaps, not certify your security.

Audit timer
15:00

Check what applies

Your shadow-AI exposure score will appear here.

This quick audit is a management triage tool, not a cybersecurity, privacy, employment or legal compliance assessment. Requirements vary according to your industry, contracts, data and jurisdiction.