lyuata.
Field notes · AI adoption · 8 September 2026

Shadow ChatGPT: Your Team Already Uses AI. Now What?

Shadow AI is your employees using AI tools you never approved, on personal accounts you cannot see, with company data you cannot get back. If you run a 10-100 person company and think this does not apply to you, the honest odds are against you: in a Gartner survey of cybersecurity leaders, 69 percent of organizations said they suspect or have evidence of employees using banned AI tools. The fix is not a ban, because bans push usage further into the dark. The fix is three moves: surface the real usage without punishing anyone, give people an approved tool on company accounts that is genuinely good enough, and write the one-page policy that makes the boundary clear. This note walks through each.

How big is the problem, really?

Bigger than most leadership teams believe, and the gap is the dangerous part. The same statistics roundup reports that only 34 percent of AI tool usage happens through approved enterprise accounts, and 67 percent of employees do not even know whether their company has an AI policy. Read those two numbers together: two thirds of the usage is invisible to you, and two thirds of your people have no idea where the line is, because nobody drew one.

None of this is malice. Someone pastes a customer complaint into a free chatbot to draft a reply. Someone summarizes a contract before a call. They are being resourceful with the best tool they know. The problem is structural: personal accounts, free tiers, and no visibility.

Why doesn't a ban work?

Because the productivity gain is real and people know it. NeuralTrust's shadow AI guide collects the evidence: in a Software AG survey, 46 percent of employees said they would keep using AI tools even after an organizational ban, and IBM's 2025 Cost of a Data Breach Report found shadow AI was a factor in 20 percent of breaches, adding an average of 670,000 dollars to breach costs. A ban does not remove the risk in those numbers. It removes your visibility into the risk, while roughly half your team carries on quietly.

The same guide's core recommendation matches what I see in practice: governed access beats prohibition. Make the sanctioned path the easy path, and most of the shadow disappears on its own.

What should you actually do?

Move one: surface the real usage, amnesty first. Run a one-hour session where people show the AI tasks they already do. No discipline, no shaming, genuine curiosity. You will learn more about your actual workflows in that hour than from any tooling audit, and you will usually find the three or four use cases worth doing properly.

Move two: provide an approved tool on company accounts. Pick one general assistant on a business plan, where the license says your data is not used for training, and create accounts with company email. This single move converts most invisible usage into visible usage, because people never wanted to hide; they wanted the tool.

Move three: draw the line on one page. Approved tools, data that never goes in, company accounts only, a named owner, a review date. I wrote the full template in The One-Page AI Usage Policy Your Company Actually Needs; it is a three-minute read for a new hire and it ends the ambiguity that the 67 percent number above represents.

Quality risks ride along with the data risks, by the way: unvetted AI output confidently gets things wrong in ways that are hard to spot, a failure family I cataloged in Your AI Agent Has the Same Red Flags as Your Ex. The training hour from move one is where proofing and fact-checking habits get built.

What about the data that already left?

Assume some has. A proportionate response for a small company: ask the team, under the same amnesty, what kinds of data went into which tools; rotate any credentials or API keys that were ever pasted into a chat; and where a vendor offers data deletion controls on personal accounts, have people use them. Then move on. The point of the exercise is not forensic perfection, it is stopping the ongoing leak, and moves one to three do that.

This is also, concretely, what my AI Adoption Sprint does for companies of 10-100 people: the usage mapping, the compliant tool selection and setup, and the one-page policy plus team training, in 2 days + follow-up for EUR 1,800 fixed.

FAQ

Should we monitor employees' AI usage technically? At enterprise scale, network-level AI discovery tools exist and make sense. At 10-100 people, culture beats surveillance: an approved tool people actually like, a clear page of rules, and a manager who asks "what are you using AI for?" in one-on-ones will surface more truth than a proxy log.

What if someone already pasted something confidential? Treat the first wave as a training gap, not a fireable offense. Punishing early confessions guarantees you never hear the truth again. Rotate what can be rotated, document what happened, and fix the path that made the unsafe option the convenient one.

Is a free ChatGPT account really riskier than a paid one? The meaningful difference is the account and plan, not the price alone. Business plans typically come with contractual commitments about data handling and admin controls that consumer accounts lack. What matters is that the license says your data is not used for training and that the company controls the account.

We are too small for a policy. Are we? If your team is bigger than one person, someone is already making AI decisions on your behalf, informally. The one-pager takes an afternoon and mostly consists of decisions you would want made deliberately anyway.

who wrote this

I'm Lyubomir Atanasov, product lead of an AI agent observability platform at Progress and previously PM for ML in high-risk credit decisioning at Experian. I run a fixed-price advisory practice on exactly the problems these notes cover.

Field notes

Agent trust, in your inbox

Occasional field notes on making AI agents provably work in production. No pitch, unsubscribe anytime.

Double opt-in via Buttondown.