Your Employees Are Using AI Anyway
The 15-minute Shadow-AI Audit for small businesses — find the AI tools already inside your workflow, draw a hard line around sensitive information, and give employees rules they can actually follow.
Shadow AI is not somebody installing a robot behind your back
It is usually much more ordinary: an employee opens an AI website, signs in with a personal account, pastes in some work, gets a useful answer and does it again tomorrow.
IBM defines shadow AI as AI used without formal approval or oversight. In practice, that can include public chatbots, AI note takers, browser extensions, coding assistants, image generators, transcription services, résumé tools and AI features quietly added to software your company already uses.
Obvious AI
- Chatbots used to write, summarize or research
- AI image and video generators
- AI coding assistants
- Dedicated AI research tools
- Standalone transcription services
The AI owners often miss
- Meeting bots automatically joining customer calls
- Browser extensions reading pages or email
- AI built into CRM, accounting or help-desk software
- Email plug-ins that draft replies from message history
- File-analysis tools employees discover on their own
NIST’s Generative AI Profile specifically recommends maintaining an inventory of organizational generative-AI systems and accounting for embedded AI inside other applications. For a 15-person company, that does not mean buying governance software. A spreadsheet with tool, user, purpose, data used, account type and approval status is already a major improvement.
Employees are moving faster than company policy
Nationwide commissioned Edelman Intelligence to survey 300 small-business owners and 300 mid-market business owners in July 2026. Small businesses were defined as companies with 1–50 employees and less than $10 million in annual revenue.
| 2026 Nationwide finding | Small business | Mid-market |
|---|---|---|
| Employees use public AI chatbots/writing tools | 54% | 65% |
| Employees believed to be using unauthorized AI tools | 39% | 30% |
| Written AI-use policy or guidelines | 35% | 36% |
| Employee responsible-use training | 35% | 39% |
| Rules governing company/customer information entered into AI | 28% | 26% |
| Procedure for verifying AI information used in business decisions | 28% | 21% |
| Designated person/team responsible for AI oversight | 20% | 21% |
The dangerous part is often the prompt, not the answer
A useful way to think about an unreviewed AI service is as an outside third party. The provider’s retention, training, access controls, account settings and contractual protections vary by product and plan. That is why “we use AI” tells you almost nothing about the actual risk.
NIST identifies data privacy, information security and intellectual-property concerns around generative AI. OWASP likewise lists sensitive-information disclosure among the major risks of LLM applications and specifically identifies personal information, financial information, confidential business information, credentials and legal documents as sensitive categories.
What employees should — and should not — put into AI
| Level | Information | Practical rule |
|---|---|---|
| Red | Passwords, API keys, authentication codes, private keys | Never enter into a public or unapproved AI system. |
| Red | Customer PII: Social Security numbers, driver’s-license data, bank details, card data, medical data, private addresses | Do not enter unless the company has specifically approved the system and the use case. |
| Red | Employee records: payroll, health information, discipline, background checks, performance records | Keep out of unapproved AI tools. |
| Red | Trade secrets and confidential business data: formulas, source code, unreleased products, proprietary processes | Use only within specifically authorized environments and workflows. |
| Red | Legal or privileged material | Do not upload casually. Confirm the tool and use are acceptable with counsel where needed. |
| Red | Nonpublic financial or deal information: acquisitions, forecasts, pricing strategy, bids, unpublished results | Treat as confidential company information. |
| Caution | Internal emails, proposals, customer correspondence, contracts, meeting notes | Remove names and sensitive details or use an approved business AI environment. |
| Caution | Business datasets and spreadsheets | Ask what fields are included before uploading the entire file. |
| Usually OK | Public information already published on your website | Generally low sensitivity, subject to normal accuracy/IP review. |
| Usually OK | Generic brainstorming, outlines, templates and non-confidential copy | Good candidates for approved AI use. |
“Chatbot” is not a security classification
There can be a substantial difference between an employee using a personal consumer account and a company-approved business or enterprise service with negotiated terms, administrative controls and defined data-handling settings.
Ask before approving a tool
- Is business data used to train provider models?
- How long are prompts, files and outputs retained?
- Can administrators control users and access?
- Does the provider support MFA or company sign-in?
- Can users delete data?
- What happens to uploaded files?
- Are subcontractors or integrations involved?
Then ask about the workflow
- What information will employees put into it?
- What decisions will depend on its output?
- Will AI communicate directly with customers?
- Can it act inside email, CRM or financial systems?
- Who reviews AI output before it leaves the company?
- Who owns the account if the employee leaves?
- Who is responsible when it produces something wrong?
NIST recommends organizations review third-party generative-AI technologies, consider vendor contracts and data practices, and continuously monitor third-party systems once deployed.
Your data can stay private and the AI can still be wrong
Shadow AI is not only a leakage problem. An employee can use a perfectly legitimate tool, enter harmless information and still receive a confident answer that is incomplete, invented or simply based on the wrong assumption.
NIST calls this risk confabulation: confidently stated but erroneous or false content. Nationwide found only 28% of surveyed small businesses had procedures for verifying AI-generated information before it was used in business decisions.
Seven shadow-AI workflows worth checking first
| Workflow | What gets exposed | Better control |
|---|---|---|
| “Summarize this customer email” | Names, account details, complaints, deal information | Use approved AI or strip sensitive details first. |
| “Review this contract” | Pricing, terms, confidential negotiations, legal material | Use a reviewed system and establish a legal-data rule. |
| AI meeting bot | Entire conversations, voices and transcripts | Approve specific services and define meeting types where recording/AI is allowed. |
| “Fix this code” | Source code, credentials, internal hostnames, architecture | Use an approved coding environment and scan prompts for secrets. |
| “Analyze this spreadsheet” | Customer, employee, sales or financial data | Remove unnecessary fields or use an approved protected workspace. |
| AI résumé screening | Applicant personal data and potentially consequential decisions | Require human oversight and review legal/compliance implications. |
| AI-written customer answer | Potentially false claims, bad commitments or invented policies | Human review before external use, especially for high-stakes answers. |
A blanket ban can turn visible AI into invisible AI
If employees have a genuine productivity reason to use AI, a policy that simply says “AI prohibited” may not eliminate demand. It can push the same work onto personal phones, personal accounts and tools the owner cannot see.
This is also the direction suggested by NIST’s approach: acceptable-use rules, inventory, defined oversight and risk-based management rather than treating every AI use as identical.
You can find most of the obvious exposure before the next staff meeting ends
This is triage, not a full cybersecurity or legal audit. The purpose is to answer five questions fast: What are we using? What are we feeding it? What is approved? Who checks the output? Who owns this?
A small business does not need a 38-page AI governance manual
Sample Small-Business AI Use Policy
Approved tools: Employees may use only AI services approved by the company for business work. New tools, plug-ins, meeting bots and AI integrations should be approved before company information is submitted to them.
Sensitive information: Passwords, authentication secrets, sensitive personal information, private customer or employee records, confidential legal material, trade secrets, proprietary source code and other restricted business information may not be entered into unapproved AI services.
Company accounts: Where the company provides an approved business AI account, employees should use that account rather than a personal account for company work.
Human review: Employees are responsible for checking AI-generated facts, calculations, citations and recommendations. AI output that affects customers, finances, hiring, legal matters, safety or other significant decisions must receive appropriate human review.
External communications: Employees may not allow an AI tool to make commitments, publish content, communicate with customers or take consequential actions on behalf of the company unless that workflow has been specifically approved.
Questions and incidents: Employees should report accidental sensitive-data uploads, questionable output or uncertain uses promptly. Employees will not be penalized simply for asking whether a proposed AI use is permitted.
Ten controls that cover a surprising amount of ground
- Maintain a simple list of AI tools in use.
- Name at least one approved AI option.
- Require company accounts where practical.
- Publish a short list of prohibited data.
- Require approval before adding AI meeting bots or integrations.
- Require human verification of important output.
- Review provider data handling before sensitive use.
- Give one person ownership of AI policy.
- Create a way to report accidental uploads quickly.
- Re-run the tool inventory every quarter.
How exposed is your business?
Check every statement that is true today. The score is designed to surface governance gaps, not certify your security.
Check what applies
Your shadow-AI exposure score will appear here.
This quick audit is a management triage tool, not a cybersecurity, privacy, employment or legal compliance assessment. Requirements vary according to your industry, contracts, data and jurisdiction.
