CurrentTechnology

Your Employees Are Already Using AI. Do You Know How?

6 Mins read

Your employees may be using AI more often — and in more ways — than you realize.

That creates a growing challenge known as “shadow AI”: using artificial intelligence tools at work without an employer’s knowledge or approval. And the gap between perception and reality can be significant. One 2026 study from Okta found that while 90% of executives were confident they had visibility into the AI tools being used in their organizations, 52% of workers acknowledged using unapproved AI tools.

For small businesses, the stakes can be particularly high. Employees aren’t simply asking ChatGPT to rewrite emails anymore. AI tools can connect to company email, calendars, files, customer information, and other systems, while AI agents can increasingly take action on an employee’s behalf.

So how can small business owners benefit from employees’ enthusiasm for AI without losing visibility and control? I asked Chris Willis, Chief Design Officer + Futurist at Domo, what business owners should know about shadow AI — and what they can do about it.

The Hidden Risks of Shadow AI

Rieva Lesonsky: Many business owners may assume they know how employees are using AI at work. How widespread is “shadow AI” — employees using unapproved AI tools — and why should small businesses be paying attention to it now?

Chris Willis: Research and experience suggest shadow AI is becoming much more widespread, but it may be used unevenly across roles. IBM’s 2026 Cost of Data Breach Report found shadow AI involved in 43% of breaches, double from 20% a year earlier, and most of those companies had no AI policy of any kind.

The risk profile with shadow AI is also changing. A year ago, shadow AI meant someone using a chatbot to respond to an email. Now it means someone could connect AI to an inbox, Slack channel, calendar, and shared drive, and then let it run.

Small businesses tend to think of this as a big-company problem. But they may have it backward. A large company has a 24/7 security team that eventually notices. An 11-person company finds out when a customer does.

(A caveat: The majority of research available is about enterprises. Very little has been done on small businesses.)

Lesonsky: What’s the biggest risk when employees use tools like ChatGPT, Claude, or Gemini without their employer’s knowledge? Are you more concerned about sensitive data, inaccurate information, cybersecurity, compliance — or something else?

Willis: Sensitive data is the biggie, but for a different reason than you might expect. The common fear is that a chatbot will learn your secrets. That’s definitely a concern. But the more pressing problem is that your data now sits in an account you do not control, under terms nobody read, tied to an employee’s personal login. When that person leaves, the data stays. You’ve lost visibility. The other risks are real, but they all trace back to that key problem: The owner cannot see what happened.

Lesonsky: What are employees most likely to put into an AI tool that they shouldn’t? Can you give us some examples of seemingly harmless AI use that could actually expose a business to risk?

Willis: Businesses run on spreadsheets and PDFs. The most common items are mundane ones: Customer lists, employee records, pricing sheets, contracts, source code, and internal documents. It feels harmless because it’s routine. Cyberhaven’s 2026 report found that about 40% of employee interactions with AI tools involved sensitive data, and that the typical employee does it every three days.

Some examples that look benign:

  • A bookkeeper asks an AI to clean up a customer export, and the export includes names, emails, and card numbers.
  • A manager pastes a performance review to make it sound more professional, and it mentions a medical accommodation.
  • A salesperson uploads a signed contract to pull out the key dates, and the contract has a confidentiality clause forbidding exactly that.
  • A founder asks for help on a pitch deck and includes unreleased revenue, strategy, and leadership.

None of these people did anything intentionally malicious. They just wanted to do good work faster. That’s the challenge that makes shadow AI so hard — the behavior you want to stop and the behavior you want to encourage often look the same. And the tools to provide  comprehensive safeguards really don’t exist yet.

When AI Starts Taking Action

Lesonsky: AI agents can now do more than generate content — they can take actions and interact with other systems. Does agentic AI create a different level of risk for businesses, and what safeguards should be in place before employees use these tools?

Willis: Yes. The new risk is authority, not intelligence.

With an AI chatbot, a wrong answer costs you a bad paragraph. When AI acts, a wrong answer is an email to the wrong customer, an overpayment, an incorrect invoice or refund, or a record incorrectly changed in your accounting system. An agent does mostly what you asked, and if the data it worked from was stale or wrong, it takes a confident action on top of an erroneous fact. The model performed confidently, and your business paid for it.

Agents are useful because they follow instructions — even those found in content. But they don’t just follow our instructions. They will happily follow any instruction that makes it to the model.

If they’ve inherited the permissions of whoever set them up (in a small business, that is often the owner, who has access to everything), that can be a huge risk.

Simon Willison calls this the “lethal trifecta.” It’s when a model has access to your private data, exposure to untrusted content, and the ability to communicate with external systems. Many exploits look for this combination of vulnerabilities.

Before anyone connects an agent to a live system, I would insist on four things:

  • Give the agent its own login with the least access it needs, never the owner’s credentials.
  • Write a short list of actions that require a human to approve before they happen, starting with anything that moves money, contacts a customer, or deletes data.
  • Keep a record of what the agent did somewhere a person will read it.
  • Make sure you can turn it off in seconds without calling a vendor.

You cannot build trust into a system directly. You can build visibility, predictability, and control, and trust emerges.

Finding the AI You Can’t See

Lesonsky: Small businesses don’t have large IT or cybersecurity departments. What’s a realistic way for an owner to determine which AI tools employees are already using and where the biggest vulnerabilities may be?

Willis: There’s no magic bullet. You have to investigate and audit thoroughly.

I’d start with an anonymous three-question survey: What AI tools do you use for work, what do you use them for, and what stops you from using the tools we already pay for?

People are more likely to answer honestly when there is no penalty, and the question is framed as “help me buy the right tools” rather than “confess.” Then check two places you already control. Your company card statements will show AI subscriptions. The third-party app connections in your Google Workspace or Microsoft 365 admin console will show which AI services employees have authorized to read their email and files.

To find the biggest vulnerabilities, follow the data, not the tools. Name the key pieces of information that would hurt most if they showed up somewhere they shouldn’t: health data, customer payment data, employee records, contracts, pricing, and anything under a regulatory purview. Then ask who touches that data daily and what they use AI for. The overlap is your risk map. It fits on one page, and you can build it in an afternoon.

Creating an AI Policy Employees Will Actually Follow

Lesonsky: How can business owners establish AI policies that aren’t so restrictive that employees simply continue using the tools secretly? What should a practical small business AI policy include?

Willis: Given how convenient AI tools are, a ban would not stop AI use. It would just stop you from hearing about it.

A better strategy starts with “yes.” Offer approved accounts on good tools. Pay for the business version that keeps your data excluded from training. Demand administrative control for greater visibility and governance. Communicate plainly that these are the tools you use for real work.

Now’s a great time to begin developing your AI policy for your business. Start by answering four questions:

  • Which tools are approved, and how do I get a new one considered?
  • Which data never goes into any AI tool, with clear, specific examples rather than broad categories?
  • What must a human review before it goes out?
  • What happens when someone makes a mistake, framed so people report it fast instead of hiding it?

Effective policy becomes something people depend on rather than something they’re afraid to ask about.

Lesonsky: If a small business owner has no AI policy today, what are the three things you would tell them to do this week?

Willis: First, find out what is happening. Send the anonymous survey and check your admin console for connected apps. You cannot write a sensible policy for a company you can’t see.

Second, give people an approved option. Pick one tool, buy the business version, and announce it. This one step removes most of the reason shadow AI exists.

Third, write two lists: The data that never goes into an AI tool, and the actions an AI never takes without a person approving. Plain language, one page, shared with everyone. You can refine the policy for months. It’ll be a living document. But you can begin protecting your business this week.

Rieva Lesonsky is the founder of Small Business Currents, a content company focusing on small businesses and entrepreneurship. You can find her on Twitter @Rieva, Bluesky @Rieva.bsky.social, and LinkedIn. Or email her at Rieva@SmallBusinessCurrents.com.

Photo courtesy Getty Images for Unsplash+

Related posts
CurrentTrends

How Small Businesses Can Win Holiday Shoppers Without Outspending Big Brands

8 Mins read
Holiday shoppers may be watching their budgets more closely this year, but that doesn’t mean small businesses have to compete by offering…
CurrentMoney

What Lenders Want Now: Strong Cash Flow, Healthy Margins and Financial Discipline

4 Mins read
Small business financing isn’t necessarily becoming easier — but financially stronger businesses appear to be getting access to better financing options. Biz2Credit’s…
CurrentSales

Amazon Seller Assistant: What Agentic AI Changes for Sellers

6 Mins read
Amazon Seller Assistant is no longer limited to answering seller questions or directing users to relevant resources. With its agentic AI upgrade,…