Compliance & governance
Shadow AI: your staff already use it. Here is what UK firms should do
The AI adoption question in most UK firms is not whether to start. It is that your team already started, quietly, with tools you never approved. Here is what shadow AI looks like, what it risks, and the short path to governing it.
By Jason Long · June 2026 · 6 min read
The short version
- Around 7 in 10 UK employees already use unapproved AI tools at work. In law firms it includes the majority of fee-earners.
- A 2026 English court ruling confirmed unapproved AI use can waive legal privilege. The risk is no longer theoretical.
- The fix is a weekend, not a project: an AI register, a one-page policy, and a governance audit to surface what is really in use.
Ask a managing partner whether their firm uses AI and you will often hear "not yet, we're being careful". Ask the team anonymously and a different picture appears: surveys consistently put unapproved AI use at around 7 in 10 UK employees, and in legal practice the numbers are starker still, with a majority of lawyers admitting to using free chatbots for client work.
That gap between what leadership believes and what staff actually do has a name: shadow AI. And in 2026 it stopped being a quiet IT-policy issue.
Why 2026 changed the stakes
In February 2026 an English court ruling confirmed that unapproved AI use can waive legal privilege. Paste privileged material into a tool that retains or trains on it, and the protection your client relies on may be gone. The SRA is preparing generative-AI guidance, ICAEW has issued AI-in-tax guidance, and the Data (Use and Access) Act 2025 is now in force.
The direction is unmistakable: regulators no longer ask whether firms use AI. They ask whether firms can show how it is governed. "We didn't know staff were using it" is an admission, not a defence.
What shadow AI actually looks like
- A fee-earner pasting a contract clause into free ChatGPT to "get a first read".
- An accounts assistant summarising a client's numbers in a chatbot to draft the email faster.
- A manager uploading a spreadsheet of staff data to an AI tool to "spot patterns".
- Browser extensions and note-takers quietly sending meeting audio to third-party servers.
None of this is malicious. All of it is invisible until something leaks, a client asks, or a regulator does.
The three-step fix
Governing shadow AI is genuinely not a six-month programme. Three artefacts do most of the work:
- 1. An AI register. A living list of every AI tool in use, who uses it, and what data it touches. You cannot govern what you have not listed.
- 2. A one-page policy. Which tools are approved, what data must never go in, and when a human reviews. We publish a free UK AI policy template, and a guide to writing the one-page version.
- 3. A governance audit. An outside pass that surfaces what is actually in use (staff tell an outsider things they do not tell IT), checks your position against UK GDPR, the EU AI Act and your sector rules, and names the gaps with a fix for each.
The uncomfortable question to ask this week
"If a client's data turned up in a public AI tool tomorrow, could we show a regulator which tools we approved, what rules staff were given, and when we last checked?" If the answer is no, that is the gap, and it is closable in days.
Sector notes
Law firms carry the sharpest risk because of privilege and SRA confidentiality duties; our guide to SRA-compliant AI covers what fee-earners can safely use. Accountancy practices face ICAEW expectations and client-confidentiality duties with heavy spreadsheet exposure. Regulated advice firms answer to the FCA's Consumer Duty, where unreviewed AI output to clients is the live risk. The full regulatory map is in our UK AI compliance guide.
Where to start
If you want the register, the policy and the gap-check done with you rather than by you, the governance check is built into our 90-minute AI readiness audit, alongside the more cheerful half of the exercise: the three places AI should be saving your team hours. And if the answer involves building something, an agent that does the routine work inside your own systems, that is what Build & Run is for.
Shadow AI is what happens when your team adopts the future faster than your governance does. The good news: catching up takes a weekend, not a transformation programme.
Frequently asked
What is shadow AI?
Shadow AI is staff using AI tools the business has not approved, most often free chatbots like ChatGPT, to do real work: drafting client emails, summarising documents, checking numbers. It is usually well-intentioned and almost always invisible to management.
What is an AI governance audit?
A structured check of which AI tools are actually in use across your team, what company or client data goes into them, and whether your policy and controls would satisfy a client or regulator who asked. It ends with the gaps named and a fix for each, not a report that sits in a drawer.
Is shadow AI actually risky for a small firm?
Yes, and disproportionately so. Free AI tools may retain and train on what staff paste in. For regulated firms the stakes are higher: confidential client data in an unapproved tool can breach SRA, FCA or ICAEW obligations, and following a 2026 English ruling, can waive legal privilege.
Should we just ban AI tools?
Bans do not work; they push usage further underground and you lose the productivity upside. The evidence-based approach is to approve a safe set of tools, set data rules in a one-page policy, and review usage quarterly.
Related insights
Want this sorted, properly?
Our 90-minute audit leaves you with a one-page action list: three things AI should be doing, what it will cost and what it will save. Keep the report either way.