Shadow AI is what happens when your team uses AI tools your business has not approved. This piece explains why bans increase hidden use in professional services firms, and what to look at instead of writing a stricter policy.
Two thirds of office workers have used AI at work while believing it was against the rules.
Not people who were unsure. People who thought there was a policy, and used it anyway.
A third said they would not tell their manager.
That finding comes from a PagerDuty survey of 1,250 office professionals, reported in June. Almost every write-up of it landed in the same place. Governance failure. Write a clearer policy. Run a training. Lock the tools down.
I read it the other way around.
The pressure is running the wrong direction
I research what I call the pressure to AI. What happens to people when adoption gets pushed on them before they have decided anything.
Nearly every incident I log runs downward. The board wants an AI strategy. A client asks what you are using. Someone buys a tool and mandates it in a Monday meeting. Pressure lands on a professional from above, and they comply, resist, or find some third way through.
This one runs upward.
Nobody told these people to use AI. They were told not to. They did it anyway, and they hid it.
That is a different problem than the one most firms think they have.
What people are actually protecting
The same survey asked why. About 30% pointed at restrictive policy or how coworkers would react. Another 29% said they were not clear what the rules were.
Eighty one percent believed leadership plays by a different set of rules than everyone else.
Seventy two percent believed they understood AI better than the people writing the governance.
Sit with that last one for a second. Your team has quietly decided they know more about this than you do. They may be wrong. It does not matter. They are acting on it.
Researchers at Duke ran four preregistered experiments with 4,439 people and found that using AI at work earns you negative evaluations of your competence and your motivation. Not the work. You.
The same study found the penalty disappears when the person evaluating you uses AI themselves.
Read those two findings next to the 81% who think leadership plays by different rules, and the hiding stops looking like dishonesty. It starts looking like a correct reading of the room.
So the person doing good work with AI has a straight choice. Say nothing and keep the reputation. Say something and take the hit.
Most people say nothing.
An attorney sanctioned in Hawaii for filing a fake AI citation put it plainly to a reporter. Nearly every lawyer he knows uses AI. It is only a problem if they get caught.
The penalty attached to being seen. Not to using it.
The part that should actually worry you
Here is what walks out the door while everyone is arguing about policy.
Forty three percent of respondents had pasted emails or work data into public AI tools. More than a third had pasted customer information. Thirty one percent had pasted financial records, confidential documents, or internal strategy.
Some of them do it on personal devices, specifically so there is no trace.
That is the cost of the ban. Not that people use AI. That they use it on hardware you do not manage, in accounts you cannot audit, with your client files in the prompt.
I work with law firms, financial practices, and consultancies here in Halifax and across Atlantic Canada. The exposure is the same everywhere. The firm that wrote the strictest policy usually has the least idea what is actually happening.
One caveat, because it matters
PagerDuty sells workplace AI and automation tooling. A vendor running a survey that finds widespread unmanaged AI use has an interest in the answer.
I still think the finding holds, because three other datasets point the same way. KPMG and the University of Melbourne surveyed more than 48,000 people across 47 countries and found 57% hide their AI use and present the work as their own. A Slingshot survey of 500 US workers in January found 45% keep it quiet. Microsoft and LinkedIn found 52% of people who use AI at work are reluctant to admit using it on their most important tasks.
Different firms. Different years. Different sample sizes, and one of those is small. Same shape.
But you should know who paid for the number before you quote it. Most of the articles about this one did not tell you.
What this changes
The question is not whether your team uses AI. Assume they do. Two thirds of them, at minimum, and the number climbs at larger firms.
The question is what happens to the first person who tells you.
If the honest answer is “a difficult conversation,” you already know why nobody is telling you.
Eight percent of organisations have a comprehensive approach to governing AI. Among small firms, 2% say theirs is robust.
The other 98% are not reckless. They are just running a business that changed faster than anyone could write it down.
I am not going to tell you the fix is a better policy. A policy is a sentence. What you actually need is to know what your people are already doing and why they decided not to mention it.
That is a harder question. It is also the only one with a useful answer in it.
Start there.
If you want a place to begin, the AI Reality Check is a free diagnostic that sorts where you and your team actually sit with AI adoption. It takes a few minutes and there is no pitch at the end. For how this plays out inside a law practice, the Koby Smutylo case study covers the version of this conversation I have most often. And if the vocabulary is the barrier, shadow AI and 66 other terms are defined in plain language in the glossary.