arrow_back

Back

Shadow AI: What risks are hiding in the shadows?

06 October 2026
schedule

4 min read

Add as a preferred source on GoogleAdd as a preferred source on Google

Employees are increasingly turning to unauthorised AI tools at work - and the data protection and compliance risks for employers are significant. Here's what HR teams need to know.

What is shadow AI?

Artificial intelligence (AI) is transforming how people work. From summarising documents to drafting communications, AI tools promise speed and efficiency and are being embraced by employees. But there is a growing problem: many of the AI tools staff are using have not been approved, assessed, or even noticed by their employers.

This is "shadow AI": the use of AI applications outside an organisation's approved systems. As the National Cyber Security Centre (NCSC) highlighted in a recent blog post, the practice is remarkably widespread, with one study finding that nearly three-quarters of employees (71%) reported using AI tools not sanctioned by their employer. For HR and compliance professionals, this trend raises serious questions about data protection, confidentiality and compliance.

What are the risks?

The NCSC identifies several key risks that are directly relevant to the workplace:

  • Data leakage and loss of control. When employees input sensitive information into consumer AI services - whether personal data, commercially confidential material or employee records - the organisation may lose visibility and control over that data. The information could be stored, retained or used to train the AI model. 
  • Lack of organisational oversight. Shadow AI, by its nature, operates below the radar. If the organisation does not know a tool is being used, it cannot assess the risks, apply appropriate safeguards or demonstrate compliance with data protection legislation. 
  • New attack surfaces. AI tools (particularly more advanced "agentic" systems) are complex software with potential security vulnerabilities. If an attacker exploits a vulnerability, they could gain access to the data in the tool. 

Why should HR teams be especially concerned?

HR functions handle some of the most sensitive personal data in any organisation: health information, disciplinary records, performance assessments, salary details and diversity data. The risks of shadow AI in this context are amplified.

An employee using an unapproved AI chatbot to help draft a performance review, a disciplinary outcome letter or a redundancy selection matrix could result in highly confidential personal data being shared with a third-party provider without any lawful basis or safeguards in place. Employees also tend to use personal devices and personal logins to access these tools, which creates a risk that company data will leave the organisation when the employee does.

This kind of processing breaches several core principles of the UK GDPR and Data Protection Act 2018, including the requirements for lawfulness, fairness and transparency. As we've noted previously, the risks of shadow AI are universal and jurisdiction agnostic, and governance is a key mitigation tool. 

What should HR and compliance teams do?

The good news is that practical steps can significantly reduce these risks:

  • Review and update AI usage policies. Set out which tools are approved, what data may be shared and the consequences of non-compliance.
  • Invest in employee awareness and training. AI literacy training can help staff understand the opportunities and the risks. 
  • Work with IT and legal teams to establish an approved AI framework. As the NCSC recommends, the goal should be to reduce risk rather than assume it can be eliminated - and that starts with giving employees access to AI tools that meet their needs within a secure, governed environment. 
  • Foster a positive, open culture. The NCSC emphasises that organisations which encourage open communication about cyber security are much less likely to see employees turn to shadow AI. Punitive approaches tend to drive the behaviour further underground.

Key takeaways

Shadow AI is not a future risk - it is happening now, across organisations of every size and sector. For HR and compliance teams, the priority is clear: understand what tools employees are using, put proportionate governance in place and ensure that sensitive personal data is not being shared with unvetted third parties.

Lewis Silkin's data, privacy & cyber and employment teams regularly advise organisations on AI governance, workplace data protection and regulatory compliance. If you would like to discuss any of the issues raised in this article, please get in touch.

Shadow AI: What risks are hiding in the shadows?