Shadow AI
A while back I was trying to understand how an agency had lost one of its longest-standing clients. Financial services, eight years together, no obvious signs of trouble.
It took a few conversations to get to what had actually happened. A strategist on the team had been using her personal ChatGPT account to help structure competitive analyses. Free tier. She was good at her job, fast and thorough, and AI made her better at it. Nobody had told her not to, because there was no policy that covered it. The tool she was using processed inputs in a way that her 2019 NDA had never contemplated.
The client found out through their own legal team doing a routine audit. The NDA wasn't technically breached, but the conversation that followed was uncomfortable enough that the relationship didn't survive it.
Shadow AI is almost never the result of someone doing something they knew was wrong. It's people doing their jobs well, reaching for the most useful tools they have, inside an organisation that hasn't built the framework to tell them what's okay. The problem is completely invisible until something surfaces it, and by then it's usually too late.
The full picture is at scaleatspeed.com/ai.