Froodl

The Hidden AI Problem: Shadow AI, Data Risk and Responsible AI at Work

Artificial intelligence tools are increasingly becoming part of everyday working practices. Employees may use them to draft documents, summarise information, assist with research, generate code, organise ideas or support routine administrative work.

These tools can be useful, but their adoption can also create questions around visibility, data handling, security and organisational responsibility.

One area receiving increasing attention is Shadow AI, where employees use AI tools or AI-enabled services without formal organisational approval, oversight or established governance processes.

Understanding how Shadow AI develops, the risks it may create and how organisations can respond is becoming an important part of responsible technology management.

What Is Shadow AI?

Shadow AI generally refers to the use of artificial intelligence tools within an organisation without the knowledge, approval or oversight of the relevant IT, security, compliance or management teams.

It can occur in many ordinary workplace situations.

An employee might use a public chatbot to improve a document. A developer may experiment with an AI coding assistant that has not been formally approved. A team could use an AI transcription platform without reviewing how information is stored or processed.

The individual may simply be trying to work more efficiently. However, the organisation may have limited visibility of what information is being shared, which systems are being used or how generated outputs are being applied.

The challenge is therefore not simply the use of AI. It is the unmanaged use of AI within business processes.

Why Shadow AI Can Create Data Risk

One of the main concerns around unmanaged AI use is data handling.

Employees may enter information into AI platforms without fully understanding how that information is processed, retained or used by the service provider.

Depending on the situation, this information could include:

  • Internal business documents

  • Customer information

  • Commercially sensitive material

  • Employee information

  • Source code

  • Research data

  • Strategic plans

  • Meeting notes

When organisations do not know which tools employees are using, it becomes more difficult to understand where organisational information is being processed.

This makes AI data protection and governance an important consideration when adopting AI tools at work.

Responsible AI Starts With Visibility

Organisations cannot manage technology effectively if they do not understand how it is being used.

A useful first step is developing greater visibility of AI use across teams and departments.

This does not necessarily mean preventing employees from experimenting with useful technologies. Instead, organisations can establish clear processes that help employees understand which tools are appropriate, what information can be shared and when additional approval may be required.

Clear internal guidance can also reduce uncertainty.

Employees should know:

Which AI Tools Are Approved

Providing guidance about accepted tools can make responsible adoption easier.

What Information Should Not Be Entered

Organisations can establish rules around confidential, personal or commercially sensitive information.

When Human Review Is Necessary

AI-generated content should not automatically be treated as accurate or suitable for every business purpose.

Who Is Responsible for AI Governance

Employees should know where to raise questions relating to AI tools, data handling, security or compliance.

Managing AI Risk Without Blocking Useful Adoption

An effective approach to AI governance requires balance.

Excessively restrictive policies may encourage employees to find unofficial alternatives, while having no clear controls can create unnecessary risk.

Organisations can instead focus on practical governance measures that support appropriate use.

These may include maintaining an inventory of approved AI tools, reviewing suppliers, establishing data-handling requirements, providing staff guidance and defining appropriate review processes.

The objective is to make responsible behaviour easier to understand and follow.

Human Oversight Still Matters

AI-generated outputs can contain errors, incomplete information or unsuitable recommendations.

For this reason, human judgement remains important.

Employees should understand when an AI-generated result needs verification and when decisions require additional professional, technical or managerial review.

Responsible AI is therefore not simply about selecting technology. It also involves establishing processes for how that technology is used, reviewed and governed.

Building Responsible AI Practices at Work

Responsible AI practices can become part of wider organisational processes rather than being treated as a separate technical issue.

Organisations may consider areas such as:

  • AI tool approval

  • Data classification

  • Access controls

  • Supplier assessment

  • Staff training

  • Documentation

  • Human review

  • Risk assessment

  • Governance responsibilities

These measures can help organisations create greater visibility around how AI is being used while supporting more informed adoption.

Join the LSET Live Webinar Tomorrow

The London School of Emerging Technology is holding a live online webinar exploring these issues in greater detail.

The Hidden AI Problem: Shadow AI, Data Risk and Responsible AI at Work

Date: 17 September 2026
Time: 2:30 PM to 3:30 PM UK Time
Format: Live online webinar

The session will explore how to:

Identify Shadow AI

Protect business and personal data

Manage AI risks

Build responsible AI practices

Stephen Peart, LSET Startup Advisor, will be speaking during the session.

Join Tomorrow’s Live Webinar

Webinar joining link:
Join the LSET Live Webinar

The session is relevant to professionals, teams and organisations interested in understanding how workplace AI use connects with data risk, governance and responsible technology practices.

Developing Skills in AI Engineering and Governance

Understanding responsible AI use is also connected with broader technical and governance skills.

Professionals interested in developing practical knowledge of modern AI systems can explore LSET's AI Engineer Course: Build Agentic AI & LLM Applications. The course focuses on areas related to AI engineering and contemporary AI application development.

For those interested in governance, risk and compliance, LSET also offers the AI for Risk Management, Governance & Compliance Course, which is more closely aligned with organisational risk, governance and compliance considerations.

Further information about programmes and learning opportunities is available through the London School of Emerging Technology website.

Conclusion

AI adoption in the workplace is not only a technology question. It also raises practical considerations around visibility, data handling, accountability and governance.

Shadow AI demonstrates why organisations need to understand how AI tools are being used across everyday workflows. Clear policies, appropriate oversight, staff awareness and responsible data practices can help organisations manage these issues more systematically.

For those interested in exploring the subject further, join the LSET live webinar tomorrow, 17 September 2026, from 2:30 PM to 3:30 PM UK time, for a focused discussion on Shadow AI, data risk and responsible AI at work.
Join the Live Webinar


0 comments

Log in to leave a comment.

Be the first to comment.