When AI Outpaces Policy: Shadow AI in the Workplace
By Lisa McConnell, Founder of Steeped Leadership, LLC
The race is on for artificial intelligence (AI) automation and efficiency improvements in the workplace. Although we hear daily news stories about big-name companies racing to adopt AI strategies—aiming to innovate, improve efficiencies, and even shift to more AI-driven operations to reduce headcounts—that’s not the case everywhere. Quietly, and away from the flashy, newsworthy headlines, many employers I’ve spoken with are taking a “wait and see” approach to AI adoption. Others are outright banning AI use by deploying firewalls and web-filtering software to block access to open AI platforms. However, that does little to prevent AI use in the workplace, especially when there are no written policies or company-wide communications about the organization’s expectations for AI usage.
This is where the use of shadow AI becomes commonplace. It isn’t just employers who see the potential benefits of AI—employees who are continually pushed to accomplish more, or who are simply trying to work smarter rather than harder, are turning to AI tools to streamline their day-to-day work. I’ve had more conversations than I can count where an employee struggling with a particular task chose to turn to ChatGPT on their phone for answers rather than seeking help from a supervisor or manager. When an organization lacks clear policies about what AI usage is acceptable and what isn’t, that silence can easily be misconstrued as approval.
When employees with access to sensitive, confidential, or proprietary business information start inputting that data into an unapproved and unvetted AI platform, companies face serious compliance risks—such as violations of privacy laws governing customer or employee information—and potential loss of competitive advantage, data breaches, and other legal exposure. When employees use personal devices to access AI tools, it also reduces the organization’s ability to trace the origin of any resulting data breaches.
If an organization has not updated its employee handbook in five years (or more), it’s undoubtedly unprepared to address the new risks AI has brought to the workplace. Even policies from just a year ago are likely outdated. Leaning solely on a policy to address AI usage is not enough, and this is not an issue a company should delegate entirely to the Human Resources (HR) department to figure out. To ensure a thoughtful and thorough approach to where AI should—or should not—be used within a business, collaboration among operations leaders, HR, technical, communications, and legal professionals is essential. This ensures that all key elements of AI usage are explored.
Beyond written policies, employees need regular training and communication to ensure a consistent and uniform approach across the organization. If your organization is not doing this now, you need to start. Understand that simply banning AI tools is not enough. Leaders must either teach employees the safe and ethical use of AI or clearly explain the limits, boundaries, and reasons behind those boundaries. The goal is not to stop innovation; it’s to create ethical guardrails that allow employees and businesses to thrive while using AI responsibly. Otherwise, you may never know what information of yours is lurking in the shadows of the internet due to employees’ seemingly innocent shadow AI usage.