Shadow AI 20 June 2026 · Darren Sharples
Shadow AI use on a Friday afternoon

The phone calls that matter in my line of work almost never arrive on a Tuesday morning. They arrive on a Friday, somewhere between four and five, when the week has finally gone quiet enough for someone senior to notice something.

This one came from the managing director of a professional firm, and I could hear it in his voice before he finished his first sentence. That particular blend of anger and fear that arrives when the problem is already behind you and you are only just finding out.

One of his juniors, bright, hard-working, two years into the job, had been pasting client documents into a free AI chatbot for months. Contracts. Correspondence. The lot. Not out of malice. Out of ambition. She was drowning in work, the tool made her faster, and nobody had ever told her she could not. Because nobody had ever told anyone anything. The firm had no policy, no training and, until 16:47 that Friday, no idea.

"I want to sack her," he said.

I asked him to wait until Monday. Then I asked him a harder question: if a junior found a way to do her work faster, told nobody because nobody had ever discussed it, and carried on for months without a single person noticing, whose failure is that, really?

Shadow AI is almost never a story about a bad employee. It is a story about a silence, and the silence belongs to leadership.

The two roads from that Friday

Firms take one of two roads from this moment, and I have watched both play out.

The first road is the crackdown. The junior is disciplined or quietly managed out, an all-staff email bans AI, and everyone nods. Here is what actually happens next: the AI use does not stop. It goes underground, onto personal phones and home laptops, where no policy, no training and no IT department will ever see it again. The firm has not got safer. It has got quieter. Those are not the same thing, and the second one is worse.

The second road starts with an admission that costs a little pride: our people are already using this, so our job is to make them good at it. That firm runs an honest inventory of what is actually in use, with an amnesty rather than an inquisition. It trains people on the tools, role by role, including what must never go into them and why. It writes a policy people can actually follow, with a fast answer to "can I use this?". The junior who caused the Friday phone call usually becomes the most careful user in the building, because she understands the risk better than anyone.

The question to ask before your Friday arrives

Here is the uncomfortable truth from the research and from every room I train in: a large share of the professional workforce is already using AI at work, and a great deal of that use has never been sanctioned, logged or checked by anyone. Your firm is very unlikely to be the exception. The only real question is whether you find out on your own terms, calmly and on a date in the diary, or at 16:47 on a Friday with your stomach somewhere around your shoes.

The MD from that phone call chose the second road, the junior still works there, but she was the first to sign the AUP.

Darren Sharples is the founder of Safer Haven AI, an AI risk, training and safety consultancy based in Greater Manchester. The story above is shared with details changed to protect the firm.

Find out on your own terms

Our AI Risk Assessment surfaces the AI use already inside your firm, without the blame, and turns it into an inventory, a plan and trained, confident staff.

See how the assessment works