KJM Consulting

๐˜๐จ๐ฎ๐ซ ๐ญ๐ž๐š๐ฆ ๐ก๐š๐ฌ ๐š๐ง ๐€๐ˆ ๐ฌ๐ญ๐ซ๐š๐ญ๐ž๐ ๐ฒ โ€“ do ๐ฒ๐จ๐ฎ? ๐๐š๐ซ๐ญ ๐Ÿ โ€“ ๐’๐ญ๐จ๐ฉ ๐’๐ก๐š๐๐จ๐ฐ ๐€๐ˆ
AI Governance

๐˜๐จ๐ฎ๐ซ ๐ญ๐ž๐š๐ฆ ๐ก๐š๐ฌ ๐š๐ง ๐€๐ˆ ๐ฌ๐ญ๐ซ๐š๐ญ๐ž๐ ๐ฒ โ€“ do ๐ฒ๐จ๐ฎ? ๐๐š๐ซ๐ญ ๐Ÿ โ€“ ๐’๐ญ๐จ๐ฉ ๐’๐ก๐š๐๐จ๐ฐ ๐€๐ˆ

If your organisation hasnโ€™t approved AI tools, itโ€™s almost certainly using AI anyway. In this article, Martin Adams explores the rise of โ€œshadow AIโ€, why banning it doesnโ€™t work, and the practical first steps leaders should take to make AI use safe, compliant and fit for real work.

Published on LinkedIn โ€ข 5 Jul 2026
Read on LinkedIn
If you havenโ€™t approved and implemented an AI tool for your organisation, you almost certainly already have people using AI anyway.
Not because theyโ€™re reckless, because theyโ€™re busy. Someone is copying a chunk of a client email thread into a free tool to summarise it. Someone is turning meeting notes into actions. Someone is rewriting a tricky message, so it lands better.
I have personally seen someone paste customer personal data into a free AI tool just to reformat it, completely unaware they were one step away from a serious data breach.
ย 
The catch is this: itโ€™s not actually just about which tool. Itโ€™s the licence, the tenant, where data is processed, whatโ€™s retained, and what happens to content behind the scenes. Thatโ€™s where the real risk sits – especially when dealing with client and staff information.
ย 
Your first move should not be โ€œban itโ€ or ignore it. It should be to โ€œmake it safeโ€.
ย 
Start with a clear policy that answers three things in plain English:
  • What tools are approved
  • What must never be pasted into an AI tool (be specific โ€“ for example, even an approved tool may still be off-limits for identifiable health data)
  • What people should do when theyโ€™re unsure (who do they ask, and how quickly will they respond?)
ย 
The first question to ask yourself:
At your organisation is AI:
  1. Approved
  2. Ignored
  3. Officially banned but happening