Shadow AI in a small business: how to find it without spying, and what to do next
✳By Hero Published Oct 9, 2026 · Updated Oct 9, 2026
The useful detailsShadow AI is any AI tool, account or feature people use for work without the organization knowing about it or approving it: a personal ChatGPT login, a free transcription bot on client calls, a browser extension that "summarizes this page". In a small business it's rarely malicious; it's people trying to get work done faster. You don't need monitoring software to find it. An anonymous amnesty survey, fifteen minutes in the admin consoles you already pay for, and a look at expense claims will surface a lot of it, and a clear approve, replace or stop decision for each tool fixes the risk without driving use further underground.
What is shadow AI?
Shadow AI is the AI version of "shadow IT": technology used for work outside the organization's view. IBM's Cost of a Data Breach Report 2025 defines it as the unregulated, unauthorized use of AI (IBM newsroom, July 30, 2025). It comes in four common forms:
Personal accounts used for work. Someone signs in to ChatGPT, Claude, Gemini or Copilot with a personal email and pastes in a client proposal.
Free AI websites and apps. Paraphrasers, PDF summarizers, image generators, "AI resume" tools, all with their own terms.
AI that connects to work accounts. Meeting note-takers that join calendar invites, email assistants, and plug-ins that ask to "read your files" through a Google or Microsoft sign-in.
AI features switched on inside approved software. A CRM, helpdesk or design tool adds an AI assistant in an update, and nobody decided whether to use it.
A coordinator pastes a messy client email thread into a free chatbot to draft the reply.
A manager signs up for a note-taking bot with a work Google account; it now joins every meeting on the calendar, including ones with clients.
Sales staff upload a price list to a personal AI account to build a quote faster.
Someone installs a writing extension that reads every web page and form they type into, including the CRM.
HR uses a free tool to "improve" a job posting and pastes in a candidate's résumé to compare.
None of these people think of themselves as taking a risk. That's the point of a non-punitive approach.
Shadow AI risks: why it matters for a small team
The risk isn't the AI itself. It's that information leaves the controls you rely on.
No contract, no control. A personal or free account sits outside any agreement you have with the vendor. Under PIPEDA, your organization stays accountable for personal information it hands to a third party for processing and needs contractual or other means to protect it (OPC). A staff member's personal login gives you neither.
Training and retention you didn't choose. Personal ChatGPT and Gemini accounts can use chats to improve models unless the person turns it off; see does AI train on your data? for each plan.
Access nobody is watching. An app someone connected to their work email or files keeps the permissions it was granted until someone reviews and revokes them.
Breach costs. In IBM's 2025 study of 600 breached organizations, one in five reported a breach due to shadow AI, and organizations with high levels of shadow AI saw breach costs about US$670,000 higher on average than those with little or none. Only 37% had policies to manage AI or detect shadow AI.
Step 1: the anonymous amnesty survey (10 questions)
Start with people, and make it safe to answer honestly. Send it from the owner or manager, say plainly that nobody will be disciplined for anything they report, and collect answers anonymously (Microsoft Forms and Google Forms can both be set up so names and email addresses aren't collected). Keep it open for a week.
Copy this text:
We want to make AI easier and safer to use at work, so we're finding out what people already use. This is anonymous and nobody will get in trouble for anything they tell us. Honest answers help us approve the right tools.
In the last month, which AI tools have you used for any work task, including free ones and ones on your phone?
For each, do you sign in with a personal account, a work account, or no account?
What do you mainly use it for? (Drafting, summarizing, research, data and spreadsheets, images, meeting notes, coding, other.)
Have you connected any AI tool to your work email, calendar, files or chat? Which ones?
Do you use any browser extensions or add-ons with AI features?
Which kinds of information have you put into an AI tool? (Public information only, internal documents, client details, employee details, financial figures, passwords or ID numbers, none of these.)
Have you paid for an AI tool yourself, or put one on a company card or expense claim?
Has an AI feature appeared inside software we already use (CRM, helpdesk, design, accounting)? Which?
Which AI tool would make the biggest difference to your work if we approved it?
What would make you more comfortable using AI at work: clearer rules, training, a better tool, or something else?
Question 6 is the one that sets priorities. Question 9 tells you what to approve so people don't drift back.
Step 2: shadow AI detection in 15 minutes with the admin consoles you already have
You don't need data loss prevention or a cloud access security broker for a first pass. If you use Microsoft 365 or Google Workspace, an administrator can see which third-party apps people have connected to work accounts.
Google Workspace (about 5 minutes). In the Admin console, go to Security → Access and data control → API controls → Manage Third-Party App Access. Under Accessed apps, select View list to see third-party apps that have accessed Google data, with the number of users and the Google services each requests (Gmail, Drive, Calendar). From the same screen you can mark an app Trusted, Limited or Blocked (Google Workspace Help). New authorizations can take 24 to 48 hours to appear.
Microsoft 365 (about 5 minutes). In the Microsoft Entra admin center, open Identity → Applications → Enterprise apps, which lists the applications in your tenant, including third-party apps people have granted access with their work accounts. Then check Consent and permissions → User consent settings. By default, users can consent to apps for permissions that don't need admin approval, such as access to their own mailbox; Microsoft recommends allowing user consent only for apps from verified publishers. Changing the setting only affects future consents, so existing grants have to be reviewed and revoked separately (Microsoft Learn).
Money (about 5 minutes). Search the last six months of company card statements and expense claims for AI vendors and "AI" in merchant names. Small monthly charges to OpenAI, Anthropic, transcription services or writing tools are the giveaway.
Write every find into one list with the survey answers. If you want a fuller inventory with owners and renewal dates, our guide to reducing AI tool sprawl has a table to copy.
It's tempting to respond with a ban or with surveillance. Both tend to push use onto personal phones where you can't see it at all.
Don't announce a ban before you have an approved alternative. People will keep the habit and stop telling you.
Don't quietly read people's chats or browsing. In Ontario, employers with 25 or more employees on January 1 must have a written policy stating whether and how they electronically monitor employees and for what purposes, and give staff a copy (Ontario ESA guide). Reviewing app lists and expense claims is ordinary administration; monitoring individuals' activity should be in that policy first.
Don't punish the people who told you. If the amnesty turns into discipline, the next survey comes back empty.
Step 3: decide approve, replace or stop
Every tool on the list gets one of three decisions within two weeks of the survey closing.
Decision
When
What you do
Approve
The tool is useful, a business plan exists, and the vendor's terms pass your checks
Move users to the business plan on work accounts, set the training and retention settings, add it to the approved list
Replace
The need is real but the tool isn't acceptable (personal account, no contract, unclear terms)
Point people to an approved tool that does the same job, show them how, then remove the old one
Stop
The use itself is too risky (client or employee data in a free tool, a bot recording client calls without consent)
Stop it now, revoke any connected-app access, and explain why in plain words
For tools you're unsure about, run the 20-question vendor questionnaire in our AI risk assessment template before deciding.
Revoke what you stop. In Google Workspace, set the app to Blocked in API controls. In Microsoft 365, remove the app's granted permissions in Entra. Ask people to disconnect the app from personal accounts too, and to delete the uploads they can.
Write a short shadow AI policy
A shadow AI policy doesn't need to be long. Four lines inside your existing AI use policy cover it:
Approved tools only for work information, on work accounts. The approved list lives in one place.
One way to ask for something new: a short request saying what task, which tool and what information. Answered within a week.
Never connect AI tools to work email, calendars or files without approval.
No blame for telling us. If you've used something unapproved, say so and we'll help you move to an approved option.
Then repeat the survey every six months. The first round finds the backlog; later rounds catch new tools early.
FAQ: shadow AI
What is shadow AI, in one sentence?
Shadow AI is AI tools, accounts or features used for work without the organization knowing about or approving them.
Is shadow AI only a problem for large companies?
No. Small teams often have more of it, because there's no IT department approving tools and people find their own. The fix is simpler too: one survey, one admin check and a short approved list.
Can we detect shadow AI without buying security software?
Mostly, yes. Google Workspace and Microsoft 365 admin consoles list connected third-party apps, and card statements show paid tools. What they can't see is someone using a free website on a personal phone, which is why the anonymous survey comes first.
Should we just ban ChatGPT and similar tools?
A ban without an approved alternative usually moves use to personal devices. Approve one business-grade tool with clear rules, then stop the uses that remain risky.
Is reviewing connected apps a form of employee monitoring?
Reviewing which apps have access to company accounts is administering your own systems. Watching what individual employees type or browse is monitoring; in Ontario, if you have 25 or more employees, your written electronic monitoring policy has to describe it.
Where Hero fits
Hero's AI security assessment, from C$1,500, runs this process with you: an anonymous staff survey, a review of the AI-related settings and connected apps in Microsoft 365 or Google Workspace with access you approve and can remove, and a ranked list of what to approve, replace or stop. We can then write the policy and run AI security training for staff, from C$2,500. If you want a quick sense of where you stand first, try the free AI Readiness Score.
Sources checked (October 9, 2026): IBM newsroom, Cost of a Data Breach Report 2025 release (July 30, 2025) · Google Workspace Help, Control which third-party & internal apps access Google Workspace data (updated October 7, 2026) · Microsoft Learn, Configure how users consent to applications · OPC, Guidelines for processing personal data across borders · Ontario, Your guide to the Employment Standards Act: written policy on electronic monitoring of employees.
A CLEAR NEXT STEP STARTS HERE
Find out what your team already puts into AI.
A free 30-minute call is the start. We’ll tell you honestly whether an AI security assessment, training, or a one-page policy is the right first step.