In late 2023, I was leading a small consulting organization and convinced that AI was about to change everything. Not eventually. Imminently.
When ChatGPT Team launched on January 10, 2024, I did what a responsible leader should do; I asked our IT and Cybersecurity team to investigate and bring back a recommendation. They did. It was thorough, considered, and not what i wanted to hear: if you must use something, use MS Copilot because it’s already in the ecosystem — but our recommendation is to avoid AI altogether. The risks are too significant.
They weren’t wrong. But that answer wasn’t what I was looking for, so I worked around it.
I had been “testing” – by which I mean “using” – a paid version of ChatGPT. I was consuming everything I could find — including a book called The AI-Driven Leader, by Geoff Woods that I still recommend to anyone who will listen. I was experimenting with prompts, finding genuine value, getting faster and sharper at things that used to take me hours. I was, by every measure, an enthusiastic and engaged early adopter.
I was also, I would later realize, a shadow AI cautionary tale.
I had developed what felt like a responsible workaround. Before uploading anything, I would run a find-and-replace — swapping identifying names for [CLIENT], [NAME] or [ORG]. I had read the terms of service. I had turned off the setting that allowed my conversations to be used to improve the model. I was careful.
One day I uploaded a file I hadn’t cleaned.
The panic I felt in that moment was visceral and immediate. The document turned out to be relatively innocuous: an HR policy containing an organizational identifier and a generic contact email. No financial information. No consequential personal information. By any objective measure, it was a near-miss rather than a confirmed breach.
The near-miss was enough to make me stop using the tool for a while. When I started again — because of course I started again — I found myself asking a much bigger question: what about the rest of my team? Who else was using AI, and what personal systems had they invented to make it feel safe?
That is the shadow AI problem: not malicious behaviour, but invisible workarounds created by unmet demand, unclear rules, and no safe path to use the tools well.
What the near miss revealed
What I had built was a personal system. It was careful, considered, genuinely well-intentioned but entirely dependent on me remembering every step, every time, under every condition, including the ones where I was moving fast or distracted or simply human.
The setting I changed was not meaningless. I was using a paid personal ChatGPT account. I had reviewed the terms, used the privacy controls available to me, and believed I had reduced the risk. But paid did not mean enterprise-grade, and it did not make my account organization-approved. It did not establish what information I was permitted to enter, how AI-assisted work should be reviewed, where outputs should be stored, or what would happen to the accumulated context if I left the organization.
Just me, a paid subscription, and a find-and-replace habit that worked – until it didn’t.
This is not a story about carelessness. It is a story about what happens when capable, informed, well-meaning people try to fill an organizational gap with individual effort. The workaround may function for a while, but the organization has no visibility into the risk, no consistency in how the tools are used, and no reliable way to learn from the experimentation already happening.
What shadow AI looks like in practice
Shadow AI is broader than an employee occasionally asking a personal chatbot to improve an email. It includes personal accounts used for organizational work, unapproved tools connected to company information, copied client or employee context, AI-generated work product that is never identified or reviewed, prompts and outputs stored outside organizational systems, and useful methods that disappear when the individual leaves.
According to a September 2025 study commissioned by IBM, almost 4 in 5 of Canadian full-time office workers surveyed said they used AI at work, but only 1 in 4 relied on enterprise-grade tools. The rest are using AI without full enterprise oversight — either mixing personal and employer tools or going entirely off the grid with personal apps. The study surveyed 4,000 office workers across Canada, the United States, Mexico and Brazil who were familiar with AI tools (IBM Canada, 2025).
And that data is already nine months old. Given the pace at which AI adoption is accelerating, the real number today is almost certainly higher.
For HR and people functions, the exposure is particularly sharp because the work sits close to sensitive organizational information. I remember the first annual performance-management cycle where I used AI to support drafting. It helped me strengthen the coaching side of the feedback: acknowledging what was working, framing suggestions constructively, and identifying opportunities to improve without softening the message. The result was faster drafting, clearer structure, and more balanced comments.
What I had not fully considered was the broader organizational exposure. If I was using a personal AI account to help shape performance feedback, others could be using similar tools to work through compensation considerations, performance patterns, or individual employee situations. Without shared rules or visibility, the organization had no way of knowing what information was being entered, how the outputs were being used, or where that context would ultimately live.
The risk is not limited to whether a vendor uses the information to train a model. It also includes inappropriate disclosure, inaccurate output, biased recommendations, undocumented decisions, unclear intellectual-property ownership, inconsistent review, and organizational knowledge accumulating in accounts the organization cannot see or manage.
Shadow AI is a governance signal
Cybersecurity and privacy teams are right to take shadow AI seriously. But treating it only as a security failure misses what else it is telling you.
People are experimenting because they see value. They are trying to recover time, improve the quality of their work, work through a frustrating process, or compensate for a capacity gap. Their experiments may be showing leaders exactly where the organization has repetitive work, unclear information, overloaded employees, slow decision-making or unmet demand for better tools.
That does not make every use appropriate. It does mean the response cannot stop at prohibition. A blanket ban may reduce some immediate exposure, but it can also push useful experimentation further out of view. When employees have demand and no workable path, they create one. I did.
The leadership task is to make informal use visible enough to govern. That means protecting sensitive information while also learning where employees are finding value, which use cases deserve support, and what approved pathways would allow the organization to experiment without relying on personal judgment alone.
Start with visibility, not surveillance
A useful first step does not have to be a large technology project. It starts with an honest conversation about what is already happening. Ask:
1. What are people using? Identify the AI tools and account types already being used for organizational work, including tools that have never been formally approved.
2. What information are they entering? Distinguish harmless public information from client, employee, financial, confidential, proprietary or otherwise sensitive data.
3. What work product is being created? Understand whether AI is helping draft emails, analyze information, screen candidates, prepare client deliverables, interpret policy, recommend decisions or perform other higher-risk work.
4. Who reviews the output? Define where human judgment is required, who is accountable for accuracy and fairness, and which decisions should never be delegated to a tool.
5. Where does the context live? Decide where prompts, source material, outputs and reusable methods should be stored so that valuable organizational learning does not remain trapped in personal accounts.
6. What should be prohibited, controlled or encouraged? Give employees rules they can apply in real situations, not a general warning to “be careful.”
7. What safe path will you provide? Choose appropriate enterprise-grade tools and supported use cases so responsible experimentation has somewhere to go.
The goal is not to catch people doing something wrong. It is to replace invisible individual workarounds with shared organizational judgment. That requires governance, but it also requires curiosity. What problem was the employee trying to solve? What value did they find? What friction caused them to work around the approved system in the first place?
Those answers help leaders classify risk, create practical guidance, enable safer experimentation, and decide where enterprise investment is justified. They also reveal where the organization may already have the beginnings of a useful AI adoption strategy — built from real work rather than hypothetical use cases.
The leadership question
Shadow AI is not only a cybersecurity problem. It is a governance signal.
It tells you that adoption is already underway, whether the organization has formally decided to adopt it or not. It tells you that employees have needs the current operating environment is not meeting. And it tells you that individual diligence, no matter how thoughtful, cannot carry organizational accountability.
The question is not whether you can stop every employee from experimenting. The question is whether you will push that experimentation further underground or create enough clarity to safeguard it, learn from it, and grow it responsibly.
Process quality and automation readiness matter too, but they are the next conversation. Before you automate anything, you first need to know what your people are already doing with AI — and whether your organization has given them a safe way to do it well.
Where Blue Monarch starts
At Blue Monarch, we help small and medium-sized organizations make AI experimentation visible, assess the risks and opportunities it is creating, and build practical governance that employees can use.
Our upcoming webinar, “Before You Automate Anything,” is a practical conversation for Canadian leaders who want to understand where AI may already be showing up in their organizations and what needs to be in place before they scale it.
References
IBM Canada. (2025, September 3). IBM study: Shadow AI use surges as Canadian workers outpace employers in AI adoption. IBM Canada Newsroom
OpenAI. (2023, April 25). New ways to manage your data in ChatGPT. https://openai.com/index/new-ways-to-manage-your-data-in-chatgpt/
OpenAI. (2024, January 10). Introducing ChatGPT Team. https://openai.com/index/introducing-chatgpt-team/