The biggest AI risk in your company is not the model you are evaluating. It is the one your staff are already using, on their own accounts, without telling you. They are pasting customer lists into a chatbot to draft a follow-up, dropping a contract into a summarizer, asking a coding assistant to debug a file that carries your keys. This is shadow AI, and it does not show up on the org chart, the security review, or the budget. It shows up later, when the data is already gone.

The instinct is to write a policy and feel covered. A policy helps, but it is the paperwork, not the control. The control is changing what people actually do, because the exposure is behavioral, and a memo does not change behavior on its own.

It is already happening, at a scale most owners underestimate

Start with how common this is, because the number is the argument. In Microsoft and LinkedIn’s 2024 Work Trend Index, a survey of 31,000 people across 31 countries, 75 percent of knowledge workers said they use AI at work, and 78 percent of those users are bringing their own tools rather than waiting for one their employer provides. The report’s own phrase for it is “bring your own AI.” People are not asking permission. They are solving today’s task with whatever is open in another tab.

The leakage follows directly. In a 2026 survey of 1,250 office professionals by Wakefield Research for PagerDuty, 43 percent said they had entered work correspondence into a public tool like ChatGPT, Claude, or Gemini, and 34 percent had entered customer data or information. Most striking, two thirds of the people who used AI at work did so even though they believed it was against company policy. (That sample was drawn from large firms, so read the exact figures as a directional read on white-collar behavior rather than a measurement of your shop.) A separate vendor survey put unsanctioned use at 49 percent (BlackFog, which sells data-loss tooling, so weigh the incentive). The instruments disagree on the decimal. They agree on the shape: a large fraction of staff, at every kind of company, are routing work through tools nobody vetted.

The exposure is concrete, not hypothetical

What actually goes wrong has three flavors, and none of them are exotic.

The first is data leakage. When an employee pastes text into a consumer tool, that text leaves your control and lands in a vendor’s systems under whatever terms the free tier set. The textbook case is Samsung: in April 2023, engineers pasted proprietary source code and internal meeting notes into ChatGPT to get help, and within weeks the company banned generative AI on its devices and rushed to build an internal alternative. A global manufacturer with a real security function still had three separate leaks in about twenty days. The point is not that Samsung was careless. It is that capable people leak data when the tool is faster than the rule.

The second is intellectual property and confidentiality. Your contracts, your pricing, your unreleased plans, your code are assets precisely because they are not public. A summarizer that trains on its inputs, or simply logs them, turns a private asset into someone else’s data. You may also be breaking a confidentiality clause you signed with your own client, who never agreed to have their material sitting in a third party’s logs.

The third is the bill when it goes wrong. IBM’s 2025 Cost of a Data Breach report found that one in five organizations reported a breach tied to shadow AI, and that breaches involving high levels of shadow AI cost about 670,000 dollars more on average than those without. Of the organizations that suffered an AI-related breach, 97 percent had no AI access controls in place. The cost is real, and it is concentrated in exactly the companies that never set up the guardrails.

Here is the part that does not wait for a new statute. Canada’s federal AI bill, AIDA, died on the order paper in January 2025 and has not been reintroduced. It would be easy to read that as “no AI rules, relax.” That reading is wrong, because the law that governs the actual risk has been in force the whole time.

That law is PIPEDA, Canada’s private-sector privacy act. The moment a staffer pastes a customer’s personal information into an unvetted tool, your PIPEDA obligations travel with it. The Office of the Privacy Commissioner has been explicit, in its 2023 principles for generative AI, that organizations should “only use generative AI tools that respect privacy laws and best practices,” and that accountability for a decision “rests with the organization, and not with any kind of automated system.” You cannot promise a customer that their data is handled lawfully when it is sitting in a vendor’s logs you never assessed. And this is not theoretical enforcement: in May 2026 the OPC and three provincial regulators found that OpenAI had failed to obtain valid consent and failed transparency requirements in how it built ChatGPT. The regulator is reading these tools closely.

The marketing edge has its own rule. If your team uses AI to write outreach, CASL still applies unchanged: every commercial electronic message needs consent, sender identification, and a working unsubscribe, no matter what drafted it. An AI that generates a thousand “personalized” cold emails does not generate a thousand consents. The tool is new. The duty is old, and it is yours.

What to actually do about the behavior

The fix is not a longer policy. It is to make the safe path the easy path, because shadow AI is what happens when the sanctioned option is slower than the unsanctioned one.

Get visibility first. You cannot manage what you cannot see, so ask, without blame, what people are using and what they paste into it. The honest inventory is usually larger than the owner expects, and it is the only real baseline.

Then give them a real tool, not a ban. A ban does not end the behavior; it drives it onto personal phones where you have zero visibility. Stand up one approved option with terms that keep your data out of training and your obligations intact, and make it genuinely good enough that the consumer tab loses its appeal.

Train for the specific move that hurts you. The lesson is one sentence: never paste customer personal information, credentials, contracts, or unreleased work into a tool that is not on the approved list. People follow a rule they understand and that does not slow them down.

And fix the incentive underneath. Staff reach for shadow AI because they are under pressure to move fast and the official path is friction. If using the sanctioned tool is the path of least resistance, and if asking gets a fast yes instead of a slow no, compliance stops being a fight. (If you want the policy scaffold that pairs with this, the annotated AI usage policy is the companion piece, and the compliance-shaped hole is the larger case for why the documentation outlasts the law.)

None of this is glamorous. It is visibility, one good tool, a clear rule, and an incentive that points the right way. It is the quiet discipline, not the statute of the week, and it is the part you actually control.

So the question is not whether your company has a shadow AI problem. At these numbers, it does. The question is the one you can answer today by asking: what are your own people pasting, into which tool, right now, and would you be comfortable if your largest customer saw it?