Employees using ChatGPT without permission? A 7-step guide for small businesses
What is shadow AI?
Shadow AI is the use of AI tools at work (ChatGPT, Claude, Gemini, Copilot, AI note-takers, browser extensions) without the knowledge, approval or guidance of the business. It is extremely common: in a March 2026 survey of 784 executives and knowledge workers across seven countries, 52% of workers admitted using unapproved AI tools, while 90% of executives believed they had visibility over AI use. A separate survey of over 2,000 UK employees found 71% had used unapproved consumer AI tools at work.
Shadow AI is rarely a sign of careless staff. It usually means people found something useful and nobody told them how to use it safely.
Why banning ChatGPT usually backfires
When a tool saves someone an hour a day, a ban doesn't stop the use. It moves it to personal phones and home accounts, where you have no visibility at all. Organisations that manage the risk well tend to provide approved alternatives rather than blanket bans. A short, announced pause while you choose tools can be reasonable; a permanent ban rarely is.
The 7 steps
1. Announce a no-blame amnesty
Before asking anything, make it safe to answer honestly. The key sentence:
"Nobody is in trouble for anything they have done with AI tools up to today. We never had rules, so nobody could break them."
2. Run a 5-minute anonymous survey
Ask which tools people use, whether they use personal or company accounts, how often, for which tasks, whether customer data or internal documents have been pasted in, whether AI note-takers are used in meetings, and how much time AI saves them. The last question matters: it shows where the value is, not just the risk.
3. Create a data traffic light
| Colour | Rule | Examples |
|---|---|---|
| Green | Any approved tool | Public website text, general questions, anonymised examples |
| Yellow | Approved tools with a work account only | Internal processes, draft marketing, price lists |
| Red | Never, unless a tool is approved for that exact use | Customer or staff personal data, health data, passwords, contracts, confidential client material, salaries |
Teach the anonymisation habit: instead of pasting a named customer's complaint, describe the situation without names and ask for a reply. You get the same quality with none of the risk.
4. Choose approved tools (and know what changes on a business plan)
The same AI assistant can come with different terms on a free personal account and a business plan. Check five things: whether your data is used for training, how long it is retained, whether the company controls the accounts, whether a data processing agreement is available, and which admin controls exist. Simple rule: work data goes into work accounts.
5. Write a one-page AI policy
Five rules cover most situations:
- Use approved tools with your work account.
- Follow the traffic light.
- You are responsible for the output: check facts, numbers and names.
- Be honest about AI use where it matters, and follow client agreements.
- When in doubt, ask, and report mistakes early without fear of punishment.
6. Train the team in 45 minutes
Explain why, walk through the traffic light with your own examples, demonstrate anonymisation live, discuss two or three hard cases, and let enthusiastic users share tips. Appoint an AI champion who answers questions and keeps the tool register up to date. In the EU, the AI Act includes an AI literacy obligation for organisations that deploy AI systems, so keep a record of the training.
7. Review every quarter
AI tools change constantly. Spend 30 minutes every three months checking the tool register, vendor terms, incidents and new use cases, and keep a simple incident plan for when "something red went in".
What if customer data has already been pasted into ChatGPT?
Thank the person for telling you. Identify the type of data and tool, delete the conversation where possible, switch off training on data in the settings if available, change any shared passwords immediately, and move the person to an approved tool. If personal data is involved, assess whether you have reporting obligations under data protection law (under GDPR, notifiable breaches generally must be reported to the authority within 72 hours) and get advice if unsure.
Frequently asked questions
Can we use AI to screen job applicants?
Be careful. AI used for recruitment is treated as high-risk under the EU AI Act, and some jurisdictions such as New York City regulate automated employment decision tools. A safe default for small businesses: AI may help write job ads, but a human reads every application and AI doesn't rank or reject candidates.
Should we tell clients we use AI?
If a client asks, answer honestly and explain your review process. Check contracts for AI clauses; some clients forbid AI use or require disclosure.
Are AI meeting note-takers OK?
Only with an approved tool and when everyone in the meeting has been told and agrees. Recording consent rules vary by country and state.
The Shadow AI Playbook includes the amnesty email, the survey, a traffic light worksheet, a 10-question tool check, a copy-paste one-page AI policy, 8 hard cases, a training agenda and an incident plan.
Get notified at launch
Sources
- Okta / Apprize360 survey, March 2026, reported by The Register.
- Censuswide survey for Microsoft, summarised by Nasstar.