AI
Governance
๐๐จ๐ฎ๐ซ ๐ญ๐๐๐ฆ ๐ก๐๐ฌ ๐๐ง ๐๐ ๐ฌ๐ญ๐ซ๐๐ญ๐๐ ๐ฒ โ do ๐ฒ๐จ๐ฎ? ๐๐๐ซ๐ญ ๐ โ ๐๐ญ๐จ๐ฉ ๐๐ก๐๐๐จ๐ฐ ๐๐
If your organisation hasnโt approved AI tools, itโs almost certainly using AI anyway. In this article, Martin Adams explores the rise of โshadow AIโ, why banning it doesnโt work, and the practical first steps leaders should take to make AI use safe, compliant and fit for real work.
Published on LinkedIn
โข
5 Jul 2026
Read on LinkedIn
If you havenโt approved and implemented an AI tool for your organisation, you almost certainly already have people using AI anyway.
Not because theyโre reckless, because theyโre busy. Someone is copying a chunk of a client email thread into a free tool to summarise it. Someone is turning meeting notes into actions. Someone is rewriting a tricky message, so it lands better.
I have personally seen someone paste customer personal data into a free AI tool just to reformat it, completely unaware they were one step away from a serious data breach.
ย
The catch is this: itโs not actually just about which tool. Itโs the licence, the tenant, where data is processed, whatโs retained, and what happens to content behind the scenes. Thatโs where the real risk sits – especially when dealing with client and staff information.
ย
Your first move should not be โban itโ or ignore it. It should be to โmake it safeโ.
ย
Start with a clear policy that answers three things in plain English:
What tools are approved
What must never be pasted into an AI tool (be specific โ for example, even an approved tool may still be off-limits for identifiable health data)
What people should do when theyโre unsure (who do they ask, and how quickly will they respond?)
ย
The first question to ask yourself:
At your organisation is AI:
Approved
Ignored
Officially banned but happening
Tagged AI, Governance