Shadow AI Is Already Inside the Firm, Even Without an AI Program

On June 22, 2026, Thomson Reuters released its 2026 Future of Professionals report with a warning that should concern every firm that says it has “no AI program.” The report found that one third of lawyers, accountants, and compliance professionals are using AI tools their organizations have not approved. Among professionals who believe their organization is moving too slowly on AI, the share rises to 41%.
The lesson is direct: banning AI does not stop AI use. It only makes the use invisible. Employees who are under pressure to work faster, summarize documents, draft client communications, analyze data, or prepare advice will look for tools that help them. If the company does not provide an approved path, some employees will create their own path, often with public tools that the organization cannot monitor, govern, or audit.
The question is no longer whether employees are using AI. The question is whether leadership can see it, govern it, and keep sensitive work inside controlled systems.
What Employees May Be Putting into Public AI Tools
Shadow AI becomes dangerous because the most useful business material is often the most sensitive. A lawyer asking for help with a contract may paste privileged language. An accountant may upload financial statements. A compliance officer may ask a public tool to summarize an investigation note. A manager may use AI to rewrite employee feedback or strategy documents. The employee may be trying to work responsibly, but the governance boundary has already been crossed.
The False Comfort of a Ban
A general “do not use AI” message is usually too weak to manage the risk. It may satisfy leadership for a moment, but it does not solve the operational problem. Employees still face deadlines, repetitive drafting, long documents, and pressure to produce more with fewer resources. If the approved environment does not give them modern tools, the unapproved environment will look attractive.
An outright ban also creates a reporting problem. If employees know AI use is forbidden, they are less likely to admit when they used it, less likely to ask whether a prompt was safe, and less likely to report a mistake. The company loses visibility exactly where it needs visibility most. In practice, prohibition without an alternative can increase risk by driving behavior underground.

If the company does not provide a safe AI path, what tools are employees already choosing for themselves?
The Better Answer: Approved Tools and Clear Boundaries
The reasonable response is not uncontrolled enthusiasm, and it is not denial. It is governed access. Companies should provide approved AI tools, define which information may never be entered, configure permissions, train employees on safe use, and create escalation paths when in doubt. The more useful the approved path becomes, the less attractive the shadow path will be.
For professional-services firms, the stakes are especially high. Legal, accounting, tax, audit, compliance, and advisory work often depends on confidentiality, privilege, regulatory duties, client trust, and documented professional judgment. If AI is used without governance, the risk is not only that sensitive information leaves the firm. The risk is that no one can prove what happened, who reviewed the output, whether the source was reliable, or whether the final advice remained professionally accountable.
DNLA Playbook for Reducing Shadow AI
- Provide an approved AI option. Give employees a safe tool before expecting them to stop using unsafe ones.
- Define prohibited information. Clearly list what must never be entered into public tools: client files, contracts, personal data, financials, legal material, credentials, and strategy documents.
- Set role-based permissions. Different teams need different access to data, documents, and AI capabilities.
- Train through real examples. Show employees what safe and unsafe prompts look like in their actual work.
- Create a no-blame reporting path. Employees should be able to ask questions or report accidental AI use before damage grows.
- Monitor adoption and risk. Track approved tool usage, policy exceptions, data-loss events, and recurring unsafe behaviors.
DNLA Take
Shadow AI is not a future risk. It is already inside organizations that have not built an AI program. Employees are using AI because the pressure to work faster is real, and because modern tools are already available outside the company’s control. Business owners who do not provide approved tools, clear rules, training, and permissions are not preventing AI use. They are outsourcing the decision to individual employees. That is the real danger. Sensitive business information does not stay protected because leadership says “do not use AI.” It stays protected when the company gives people a better, safer way to work.
Want the same rigor applied to your own AI system?
That's what a QAi Health Check is for.