A run of recent UK survey data has put a number on something most business owners have suspected for a while: staff are using AI tools nobody signed off on, and they’re doing it constantly. One widely-cited Microsoft UK survey found 71% of employees have used unapproved consumer AI tools at work, and 51% keep doing so every week. Separate research puts UK senior leaders’ own usage of unapproved tools even higher than their staff’s — 62% of leaders versus 31% of employees below decision-maker level. This is “shadow AI”: AI use that happens entirely outside whatever policy, procurement, or security process a business thinks it has.
For an SME without a dedicated IT or security function, this isn’t a hypothetical governance topic — it’s almost certainly already happening inside your business right now, whether or not you’ve noticed.
Why the gap is wider than owners think
The most striking finding across this research isn’t the usage number itself — it’s the confidence mismatch. Executives report high confidence in their visibility over what AI tools their organisation uses, while the reality on the ground tells a very different story. Most employees who use unapproved tools know there’s some risk involved — the majority acknowledge these tools carry security or privacy concerns — and use them anyway, often because a deadline is easier to hit with a free AI tool than without one.
That combination — high usage, moderate awareness of risk, and low leadership visibility — is exactly the environment where a mistake becomes likely: someone pastes a client contract into a free chatbot to summarise it, or uploads a spreadsheet of customer data to get a quick analysis, without ever considering where that data goes afterwards.
What to actually do about it this week
Banning AI tools outright rarely works and usually just pushes the behaviour further out of sight. A more realistic starting point is naming which tools are actually approved for use with company or customer data, and making that list genuinely useful enough that staff don’t feel the need to go around it. If your team is already relying on AI to hit deadlines, the answer isn’t less AI — it’s giving them an approved, secure way to do the same thing.
It’s also worth having one plain conversation with your team: what are people already using, and for what? You’ll likely learn more from that ten-minute conversation than from any policy document. From there, a short, written policy — even three or four lines on what can and can’t be pasted into an AI tool — closes most of the practical risk without turning into a bureaucratic exercise.
If you want to move from ad hoc tool use to something that’s actually secure and fit for purpose, this is precisely where a partner like ApplyAI earns its keep — helping SMEs pick the right tools and put sensible guardrails around them, rather than either banning AI or leaving it to chance.
The takeaway
If you assume your staff aren’t using AI tools you haven’t approved, the data says you’re very likely wrong — and the more senior you are, the more likely that blind spot applies to you too. Spend ten minutes this week finding out what your team is actually using, and put one short, sensible policy in place around it rather than leaving it to guesswork.
Worth remembering too: this isn’t really an “AI problem” so much as a familiar management problem wearing new clothes. Staff have always found workarounds when the approved tool is slower or clunkier than the unapproved alternative — the fix has always been to make the sanctioned option genuinely good enough that going around it isn’t worth the effort, and AI tooling is no different.