In the spring of 2023, weeks after Samsung let its engineers start using ChatGPT, three of them pasted in confidential material: source code, an internal test sequence, and the notes from a private meeting they wanted summarized. By May the company had banned public AI tools on its own machines.

That gets told as a cautionary tale about a giant tech company. It is really a story about an ordinary Tuesday afternoon. Someone had a document, a deadline, and a tool that turns an hour of work into a minute. None of that pressure is unique to chip makers. In firms the size of yours it is more common, not less, because there is no security team watching. Microsoft’s 2024 survey of work and AI found that most people who use AI at work bring their own tool to do it, and the rate runs highest at small and midsize companies.

So the useful question is not whether your people are using AI you never approved. They are. The question is what leaves the building when they do, and whether you would know.

The threat already has a login

A decade ago, two Oxford researchers writing in Harvard Business Review made a point that still holds. The breaches that hurt most rarely come from a stranger forcing the door. They come from someone who already has legitimate access: an employee, a contractor, a vendor you connected to your systems. The retailer Target lost card numbers for tens of millions of customers that way, through credentials taken from the company that serviced its refrigeration. Upton and Creese called it the danger from within.

Shadow AI is the same shape of problem with a new way out. The person moving your data is a trusted associate trying to do good work faster, and the door they use is an ordinary browser tab. That is what makes it hard to catch with the tools most firms already own.

The three exits your client data takes

In the firms we see, client data tends to leave through three exits. Only the first one is obvious.

The paste. Someone copies a paragraph of a client’s contract, a patient summary, or a draft reply to a regulator, and drops it into a free chatbot for a rewrite. Cisco’s 2024 privacy study found that nearly half of organizations admitted entering non-public company information into these tools, and a larger share had fed in details about internal processes. The work comes back faster and better written. The copy now also sits on a server you do not control, possibly used to train a model you will never see.

The embedded feature. This one few partners have gone looking for. The software your firm already pays for, the practice management suite, the CRM, the meeting recorder, has quietly added an AI feature, often switched on by default. A note-taker joins a privileged call and keeps the transcript. A “summarize this thread” button sends a client’s email history off to a model. Nobody sat down and decided to adopt AI. It arrived in an update.

The sub-processor. Your vetted vendor, the one who signed your confidentiality terms, hands your data to an AI provider of its own. You evaluated the vendor. You never evaluated the company behind the vendor. This is the Target pattern again, one link further down the chain, and it is the exit a tool watching your own network cannot see at all.

Put the three together in a single matter. Say a small litigation firm is up against a filing deadline. A paralegal pastes three pages of a client’s deposition into a free chatbot to tighten a summary. The firm’s document system, updated last month, now offers to draft the response and sends the matter file off to its AI provider to do it. And the e-discovery tool the firm has trusted for years has quietly added an AI feature that routes documents through a model no one there has heard of. Nobody broke a rule they were warned about. The same confidential file now sits in three places the firm cannot account for, and any one of them could surface later in a malpractice claim or a bar inquiry.

Client data leaves through three exits. Most firms watch the first one and miss the two that run through software and vendors they already trust.
Client data leaves through three exits. Most firms watch the first one and miss the two that run through software and vendors they already trust.

Why this is a strategy question, not an IT one

The instinct after reading this far is to treat it as a technical clean-up: block the chatbot sites, buy a tool that watches for leaks, send round a reminder. Those steps help a little. They also misread what is actually at risk.

Strip away the software and an AI vendor is a supplier, and supplier power is one of the older questions in strategy. The questions you would ask of any supplier apply here with unusual force: how much does it hold over you, and how hard would it be to leave? A vendor that keeps your prompts, trains on your inputs, or buries its real data terms inside a sub-processor list is a supplier with a lot of quiet power over the one asset a professional-services firm cannot rebuild. Your clients do not pay you for documents. They pay you because they trust you with things they would never put in an email. That trust is the practice. A careless paste spends it, and no amount of time saved buys it back.

Your clients don't pay you for documents. They pay you because they trust you with what they would never put in an email.

Why a ban won’t hold

The instinct after that is to ban the tools outright. Firms try. It rarely holds. A ban does not remove the deadline or the temptation; it moves the work onto a personal phone, where you have no visibility and no policy at all. Samsung banned public AI and then, within a couple of years, moved toward sanctioned internal tools instead, because the demand never went away. The once-a-year security training slide goes the same way, forgotten by March. None of it was built for a risk that walks in with a valid login.

What works better is giving the work somewhere safe to go.

The safe path you can stand up in a few weeks

The reassuring part is that the fix is mostly procurement and clarity, not a security department. A firm of twenty people can put the essentials in place in a few weeks.

Give people a better tool than the free tab. The paid business tier of the major AI tools comes with terms the free one does not, and the gap is the whole point.

Free / consumer tier Business / enterprise tier
Your inputs used to train the model Often, by default Contractually no
Data retention Open-ended, on their servers Limited and configurable
Data processing agreement or BAA Not available Available
Admin oversight None Central controls and logs

When the sanctioned tool is also the more capable one, the shadow version loses its pull.

Write the policy on one page. Not a manual. A single page that answers the three questions people actually have: which tool am I allowed to use, what must never go into it, and who do I ask when I am not sure. People follow rules they can remember.

Ask your existing vendors five questions, in writing. Does using your product send our data to a third-party AI provider, and which one? Is our data used to train any model? Can we turn the AI features off? Where is the data stored, and for how long? Will you sign a data processing agreement, or a business associate agreement if we handle health information? The answers sort your vendors quickly, and the silence from one who will not answer tells you something too. This is the same discipline as evaluating an AI vendor before you buy, applied to the tools you already own.

Train on the real situation, not the generic one. The useful five minutes is not a phishing reel. It is showing the associate the safe tool, the line they must not cross with a client’s matter, and the plain reason it matters to them: their license, their client, their name on the work.

For regulated work the duty is already written down. The American Bar Association’s 2024 ethics opinion on generative AI ties a lawyer’s use of these tools directly to the duty of confidentiality, which means an unmanaged paste can cross from careless into an actual rules problem. For anyone touching health information, nothing should reach a model without a business associate agreement in place first. In regulated work the rules already exist; what is usually missing is enforcement. If you use an outside IT provider or MSP, this is squarely their job: hand them the vendor questions and the policy to put into practice.

What to do this quarter

If you do nothing else this quarter, do three things, in order. Find out what is already in use, and do it without blame, because people hide tools they expect to be punished for. Stand up one sanctioned, capable option so there is somewhere good to send the work. Then put the vendor questions and the one-page policy in writing. None of it needs a big budget or a new hire. It needs deciding that a client’s trust is worth an afternoon of attention now, rather than a phone call you do not want to make later.

The firms that handle this well decide one thing up front: what will never go into an AI tool they don’t control.