Here is an uncomfortable truth most SME owners eventually face: your staff are already using ChatGPT and similar tools with company information, whether or not you approved it. This is "shadow AI" — unsanctioned AI use — and it is a data and compliance risk you already have, not one you might acquire. The answer is not a ban, which rarely works. It is visibility, a workable policy, and basic guardrails. This guide shows you how to get all three, step by step.
What is shadow AI and why should an SME care?
Shadow AI is the use of AI tools by staff without company approval or oversight — typically pasting work data into public chatbots. SMEs should care because it can expose confidential or personal data, breach client contracts, and create EU AI Act gaps, all without leadership even knowing it is happening.
The risk is not hypothetical. When an employee pastes a client list, a contract or personal data into a public AI tool, that information leaves your control, and you may have breached confidentiality obligations or data protection rules without realising. Because it is unsanctioned, none of it appears in your official systems or your AI register — which means it is invisible precisely where compliance and security reviews look. The first job, therefore, is to bring it into the light.
Should you just ban AI tools instead?
Usually not. Outright bans tend to fail — staff use AI because it helps them work faster, so a ban often drives the behaviour further underground rather than stopping it. A clear policy with safe, approved options works far better than prohibition, which is difficult to enforce and costs you the productivity benefits.
Banning AI is tempting but rarely effective. Your team adopted these tools because they genuinely help; take them away with no alternative and people either quietly carry on or lose the productivity you would rather keep. The realistic goal is not zero AI use — it is governed AI use: staff know what is allowed, what is not, and which approved tools to use for sensitive work. That converts a hidden risk into a managed capability.
How do you get shadow AI under control? A step-by-step guide
In five steps: find out what your team is actually using, assess the data risk, write a short usable AI policy, provide safe approved tools, and train staff on the rules. Done in order, this turns unsanctioned AI use into governed, compliant use within weeks — without killing productivity.
The five-step process
- Get visibility. Ask your team, without blame, which AI tools they use and for what. An honest inventory is impossible if people fear punishment, so frame it as improving how you work, not catching them out.
- Assess the risk. For each tool and use, ask what data goes into it and whether that data is confidential, personal or contractually protected. This tells you where the real exposure is.
- Write a usable AI policy. Keep it short and practical: what is allowed, what is never allowed (e.g. pasting client or personal data into public tools), and who to ask when unsure. A policy nobody reads protects nobody.
- Provide safe options. Give staff approved tools or accounts configured for business use, so the easy path is also the compliant one. People follow rules that do not slow them down.
- Train and document. Run a short session on the policy, record who attended, and revisit it when tools change. This doubles as your Article 4 AI literacy evidence.
Follow those five and you move from invisible risk to documented, governed use — and you generate the AI register and literacy records the EU AI Act expects along the way.
What should the AI usage policy actually say?
A good SME AI usage policy sets out approved tools, an absolute rule against putting confidential, personal or client data into unapproved public tools, guidance on checking AI output before use, and a contact for questions. It should be one or two pages that staff will actually read and follow.
The best policy is short enough to be read and clear enough to be followed. The non-negotiable line for most SMEs is data: no confidential, personal or client-contract-protected information into public AI tools, full stop. Around that, cover which tools are approved, the expectation that AI output is checked by a human before it is relied on, and where to go with questions. We provide a fuller template and walkthrough in our AI usage policy for SMEs post, and the broader obligations in EU AI Act Compliance for SMEs.
How does this connect to the EU AI Act?
Directly. Getting shadow AI under control produces exactly what the Act expects from a deployer: an AI register, AI literacy training under Article 4, and documented governance. Tackling shadow AI is not just a security fix — it is a large part of your AI Act compliance, done at the same time.
The pleasant surprise is that the work overlaps. The AI register you build to see shadow AI is the register the Act wants. The training you run to set the rules is your Article 4 literacy evidence. The policy you write is core governance documentation. So bringing shadow AI into the open is not a separate chore on top of compliance — it is compliance, arriving through the door of a problem you already needed to solve. Keeping all of it current is the ongoing part, which is what our Compliance Guard service maintains.
How do you know if you have a shadow AI problem?
Assume you do. If your team has internet access and deadlines, some of them are using AI tools you have not approved. Signs include unusually polished drafts appearing quickly, staff mentioning AI tools casually, or simply the absence of any policy — which guarantees unsanctioned use is going unrecorded.
Very few SMEs have zero shadow AI; the realistic question is how much, not whether. Tell-tale signs are indirect because the use is hidden by nature: work produced faster than usual, references to tools you never rolled out, or a general vagueness when you ask how something was done. The surest sign of all is the absence of a policy — if you have never told staff what is and is not allowed, you can be confident some of them are guessing, and some of those guesses involve company data in public tools. Rather than hunt for evidence, it is more productive to assume the problem exists and move straight to bringing it into the open.
What makes an AI tool safe for staff to use?
A tool is safer for business use when it does not train on your inputs by default, offers business or enterprise terms with data protection, and is on your approved list with clear guidance. The safest setup pairs approved tools with a firm rule never to enter confidential or personal data into consumer versions.
Not all AI use is equally risky, and part of governing it well is steering staff toward safer options. Business and enterprise tiers of mainstream AI tools typically offer stronger data terms — including not using your inputs to train models — than the free consumer versions. Approving specific tools, configuring them for business use, and telling staff which to use for what removes the main temptation to reach for an unmanaged public tool. Combined with the absolute data rule, this gives people a compliant path that is also the easy one — the single most reliable way to change behaviour. The register of what you have approved, and the training that communicates it, feed straight into your EU AI Act Compliance for SMEs position.
Frequently asked questions
What are the risks of employees using ChatGPT with company data?
The main risks are exposing confidential or personal data outside your control, breaching client confidentiality or data protection obligations, and creating EU AI Act compliance gaps — all potentially happening without leadership's knowledge because the use is unsanctioned.
Should I ban staff from using AI tools?
Usually not. Bans tend to push AI use underground rather than stop it, and they cost you the productivity benefits. A short, clear usage policy paired with approved, safe tools governs the behaviour far more effectively than prohibition.
What should an AI usage policy template include?
Approved tools, an absolute rule against putting confidential, personal or client data into unapproved public tools, a requirement to check AI output before relying on it, and a contact for questions. Keep it to one or two pages staff will actually read.
How does managing shadow AI help with EU AI Act compliance?
It produces the same artefacts the Act requires from a deployer: an AI register, Article 4 AI literacy training and documented governance. Addressing shadow AI therefore delivers a large part of your AI Act compliance at the same time.
See where your business stands
The free EU AI Act self-assessment gives you a plain-English read on your position in five minutes.