← Back to ResourcesGovernance

Your Employees Already Use AI at Work. Nobody is Turning it Into A Plan.

Shadow AI is already running inside most companies — here's how to address it and steer it into a benefit for the entire organization.

An employee using an AI assistant on a personal laptop

Ask a room of Denver business owners whether their company uses AI and about half will say no, not yet. Ask their employees the same question and you get a different answer.

MIT's NANDA initiative found that workers at more than 90% of the companies it studied were using personal AI tools for their jobs, while only about 40% of those companies had officially provided access to anything. The space between those two numbers has a name. Shadow AI.

This is not a discipline problem. It is what happens when capable people find a tool that makes their week easier and nobody has told them whether they are allowed to use it.

What shadow AI actually looks like

It is rarely dramatic. It looks like this:

  • A salesperson pastes a client's pricing sheet into a personal account to draft a follow-up email.
  • A bookkeeper uploads an aging report and asks which accounts to chase first.
  • Someone in HR drafts an offer letter with a free tool and does not mention it, because why would they.
  • Three people write prompts for the same monthly report, get three different formats, and none of them saves the prompt anywhere.

None of that is malicious. Most of it is good judgment applied without guidance. The employee saw a way to finish something faster and took it.

The problem is not that the work got done with AI. The problem is that the business has no idea any of it happened.

Why smart teams do this without telling you

First, the tools are free and require no approval. Anyone with a browser has access to capable AI in under a minute, with no purchase order and no IT ticket.

Second, the pressure is real. Small and mid-size teams run lean. If someone can cut two hours off a task, they are going to cut two hours off that task.

Third, and most importantly, nobody has said yes. When there is no policy, asking permission creates a risk that did not exist before, because the answer might be no. Silence from leadership reads as tolerance, so people keep quiet and keep going.

"In most scenarios, the employees using AI most effectively are the ones least likely to bring it up."

The four risks that actually matter

Data leaves without a record. Client lists, contracts, financials, and employee information get pasted into accounts your company does not control and cannot audit. In a personal account, you have no visibility into what was shared, no retention settings, and no way to answer a client who asks.

Quality goes inconsistent. Two proposals go out the same week at two different standards, because one person has a good process and the other does not. Clients notice the drift before you do.

The knowledge stays personal. Your most effective AI user has built a workflow that lives in their head and their chat history. When they leave, it leaves with them, and you are back where you started.

Compliance is getting more concrete. Colorado's rewritten AI law, SB 26-189, takes effect for decisions made on or after January 1, 2027. If any tool influences decisions about people in areas like hiring, lending, housing, or healthcare, you will need to know it is in use and be able to document it. You cannot govern a tool you do not know about.

Five questions to ask your team this week

You do not need a consultant to run this part. You need twenty minutes and a genuine promise that nobody is in trouble.

  1. Which AI tools have you tried for work in the last month?
  2. What tasks did you use them for?
  3. What information did you put into them?
  4. Is that a personal account or a company one?
  5. What would you use AI for if you knew you were allowed?

Ask these with amnesty attached and stated out loud. If people think there is a penalty at the end of the conversation, you will get a clean answer that tells you nothing. Question five is the one to key in on. It surfaces your real use cases, ranked by the people who do the work.

Uncovering use cases for AI adoption in your organization is not a venture you have to approach alone. At H1, we want to help you and your team navigate the changes brought about by AI. Book a free discovery call here.

A policy nobody reads versus guardrails people follow

Most AI policies fail for the same reason most employee handbooks fail. They are written to protect the company in a dispute, not to help an employee make a decision on a Tuesday afternoon.

A policy says "employees must use approved AI tools in accordance with company data standards." Nobody has ever changed their behavior because of that sentence.

Guardrails answer the questions people are actually asking. Can I put a client's name in here? What about a contract? Do I need somebody to check this before it goes out? Which account am I supposed to use?

Specificity in guardrails trumps a comprehensive, catch-all rulebook. A one-page set of rules your team can recall from memory will outperform a twelve-page document nobody opens.

Four rules to start with

You can draft a workable version of this in an afternoon.

  • Approved tools and accounts. Name the tools people should use and provide company accounts. This single step moves most of your risk, because business tiers give you administrative control and different data handling than free personal accounts.
  • What never goes in. Be concrete. Name the actual categories: client financials, personally identifiable information, signed contracts, anything under NDA.
  • What gets reviewed before it leaves the building. Anything client-facing, anything with a number in it, anything that becomes a commitment.
  • Who owns the decision. One named person who answers questions about new tools, so silence stops being the default.

That is the whole starting point. It is not sophisticated and it does not need to be. It needs to exist.

The cost comparison is not close

Businesses hesitate on AI governance because it feels like an expense with no return. But compare it to the alternative. The cost of writing guardrails is a few hours of leadership time and one working session. The cost of not writing them is unknown, because by definition you cannot see the exposure you have already accumulated.

There is also an upside that gets missed. Once people know what is allowed, they stop hiding the good work. The salesperson who built a genuinely excellent follow-up process shares it, and now six people use it. That is when AI stops being a private productivity trick and starts being a business capability.

Start with the rules, then the tools

Every engagement we run at H1 begins with an AI Vision and Guardrails session, and this is why. Not because governance is exciting, but because everything after it fails without it. Training on tools people are not sure they can use produces polite attendance and no change. Pilot programs that run without shared rules stall at the first question about client data.

Direction first, then capability, then implementation. In that order, the work compounds.

If you are not sure what your team is already doing, start with the five questions. If the answers surprise you, that is useful information, and it is the beginning of a real AI strategy rather than a hopeful one.

H1 AI Consulting works with small and mid-size businesses to establish AI strategy, training, and implementation. A 30-minute discovery call is usually enough to tell you where you stand and how we can help. Book your free AI discovery call here.