There is a term for this that sounds more sinister than it is: shadow AI. It means employees using AI tools that the company never officially approved.
Not stolen software. Not anything dramatic. Usually it is someone pasting a messy spreadsheet into a chat window at 4pm because they want to go home.
I talked about this on our podcast with my friend Josh, who works at an accounting firm. I asked him who at his firm was using AI. His answer was that out of about eleven people, three of them were, plus the owner more recently.
That ratio has held up in nearly every company I have talked to. There are always one or two people quietly using it. And I mean always.
The part that should get your attention
The people using it are not hiding because they're doing something wrong. They are hiding because nobody told them whether it was right.
There is no policy. There is no approved tool. There is no conversation. So a reasonable employee with a deadline makes a reasonable judgment call, and now your company has an AI usage practice that nobody designed, nobody documented, and nobody can see.
Josh put it plainly when I asked what was holding the rest of his firm back. The three of them who use it, he said, "tend to be a little more look at the new shiny object, let's play around with it," while so much of the work "is very cut and dry, very systematized." And then the part that stuck with me: "if you are busy and don't have the time to like look into new tools, it is hard to find the space to do that."
He wasn't describing carelessness. He was describing an ordinary gap between the people who happen to poke at new tools and the people who are heads-down doing the work.
That gap isn't a character difference. It is an information difference.
Why the silence is the real risk
If somebody is using AI well, in the open, you can learn from them. Their workflow becomes everyone's workflow.
If somebody is using AI well in silence, three things happen instead.
The knowledge stays trapped with one person. The rest of the team keeps doing it the slow way. And nobody has ever checked what data is going where.
That last one is where it gets expensive. Josh made this point about his own work: he can redact client information all day, but at some point there will be a file he uploads without catching everything. He is a careful person who thinks hard about this. He still assumes he will eventually slip.
Now think about the employee who has never once thought about it. Not because they do not care. Because it never came up.
What to actually do
The instinct is to write a policy banning it. Resist that. A ban does not stop shadow AI, it just pushes it further into the shadows and guarantees you never find out what's happening.
Three better moves.
Ask, without consequences attached. Not a survey. A conversation where the honest answer is safe. You cannot manage what people won't tell you.
Approve something. Anything. One tool, one account, one set of rules about what can go into it. The absence of an approved option is what created the shadow in the first place. If you want a shape to copy for the higher-stakes work, the approve-and-audit pattern is where I would start.
Find your one or two. They already exist. They already know things. Give them a way to teach the rest of the team instead of leaving them to be quietly more productive on their own.
The reframe
Shadow AI isn't an infraction. It is a signal.
It tells you exactly where people feel enough pressure to look for help, and it tells you that your organization hasn't yet given them a legitimate way to ask for it. Both of those are useful things to know.
Someone on your team already went looking. The only question left is whether you find out from them or from a data incident.
So: who are your one or two, and when did you last ask them what they are doing?
Josh and I talk about this kind of thing regularly on J&C Unscripted.