Skip to content

UK businesses sitting on a Shadow AI 'data and privacy disaster'

Microsoft's research found 71% of UK employees using unapproved AI tools at work — and most of them untroubled by the risk. Without visibility of what is running, GDPR compliance becomes impossible to evidence.

Many UK businesses could be unwittingly sitting on a data and privacy disaster, as thousands of employees quietly introduce Shadow AI into systems nobody is tracking.

That is the warning from Certero after Microsoft’s research found that 71% of employees have used unapproved AI tools at work, with more than half of those — 51% — using them at least once a week (Microsoft / Censuswide, October 2025, surveying 2,003 UK employees).

Consumer applications such as ChatGPT and Claude are arriving in the workplace through individual subscriptions rather than IT-approved deployments, leaving organisations exposed on both privacy and security.

One of the more troubling findings in Microsoft’s “Rise of Shadow AI” report is how little the people introducing these tools worry about it. Only around a third of those surveyed said they were concerned about the privacy of customer or company data put into AI tools. Just 29% were concerned about the security risk it creates in company systems.

Is a lack of technical innovation part of the Shadow problem?

Asked why they use their own AI tools at work, 28% of Microsoft’s respondents said their employer does not provide an approved alternative.

That is a familiar pattern. Organisations slow to adapt to a new technology leave their teams to bring in their own, with no oversight at all.

Unauthorised tool use exploded over the last few years on the back of free-tier SaaS and cloud. AI has simply repeated the pattern at higher speed and with more sensitive data attached.

Understanding the risks of Shadow AI

The central concern is the lack of transparency over how data put into these tools is stored and used.

The Information Commissioner’s Office has already issued guidance on the risks of putting sensitive data into AI systems. It warns that “AI systems introduce new kinds of complexity not found in more traditional IT systems that you may be used to using”.

One of the difficulties the ICO raises is that common practice for processing personal data securely in data science and AI engineering is still being established. How one tool treats your data can differ entirely from how another treats it, and as an organisation you have no reliable way of knowing which.

That matters a great deal under GDPR, which requires transparent audit trails covering how you collect, store and use data.

Meeting that obligation is difficult enough when you know which AI tools are in use. It is impossible when you do not — which leaves you exposed to both the risk and the fine.

Getting control of your hybrid environment matters more than ever

Shadow AI has raised the stakes on unapproved technology generally.

Shadow IT has always been a concern, though mostly framed around cost and productivity. Security concerns were there too. Log4Shell in 2021 is the obvious reminder: a critical vulnerability allowing remote code execution, which began as a zero-day event and became a far bigger problem on devices nobody had patched because nobody knew they were there.

AI presents a different class of challenge. The tools are early, they are trained on what goes into them, and unapproved use is rising quickly.

So it is worth reviewing your asset management practice now, and specifically whether you have the means to see everything running across your environment — including the things nobody told you about.

Having a clear view of everything in use, whether you sanctioned it or not, is the only reliable way to protect against the risks AI introduces, or at minimum to control how these tools get adopted.

Microsoft UK & Ireland’s own conclusion from the research was blunt: enthusiasm alone is not enough, and organisations need to make sure the AI tools in use are built for the workplace rather than the living room — with the privacy and security controls an enterprise requires.

What visibility of Shadow AI actually looks like

The gap that lets Shadow AI persist is that most discovery only sees corporate identity. If someone signs up with a personal account in a browser tab, the identity provider never records it.

CerteroX SaaS Management closes that gap by converging three signals rather than relying on one: identity provider sync from Entra ID and Okta, connector sync pulling authoritative user and licence data from the vendor, and a browser extension that detects application domains, time-on-application and per-user attribution. The extension is what catches personal-account AI use.

AI tools are then classified from application feature tags in a catalogue of more than 35,000 applications rather than a fixed list, so newly launched tools are recognised without waiting for someone to add them. The Shadow AI dashboard ranks adoption risk across three tiers by the share of the organisation using each tool.

From there it becomes governable. OAuth grant discovery finds which third-party applications your users have consented to and scores each grant from 0 to 100 on data sensitivity, scope, consent and dormancy, with one-click revocation available directly or as an automated workflow action. CerteroX AI Management adds a status workflow — managed, blocked or ignored — plus risk assessment covering GDPR, HIPAA and SOC 2 exposure, per-application budgets, and a full audit trail across AI seat provisioning and revocation.

That is the difference between knowing you have a Shadow AI problem and being able to evidence what you did about it.

Book a demo to see the Shadow AI Dashboard with the OAuth grants already scored.

Related reading

Other posts covering the same ground.

From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.