AI security & privacy · Guide
Shadow AI in professional firms: how to find it and replace it
Shadow AI in professional firms is staff using AI tools the firm has not approved, such as personal ChatGPT accounts, browser extensions and AI note-takers. It puts client information outside the firm's control. The fix is to find what staff use and why, give them an approved tool for the same jobs, then restrict the rest.
- By
- Elias
- Published
- Last reviewed
- Reading time
- 7 min read
What is shadow AI?
Shadow AI is any AI tool used for firm work without the firm’s approval or oversight. In a law or accounting firm it usually looks ordinary: a lawyer pasting a clause into a personal ChatGPT account, an accountant uploading a client meeting recording to a free transcription site, or an AI note-taker joining a Teams call because someone accepted its invitation.
It is a branch of shadow IT with one important difference. An unapproved file-sharing app stores what staff give it. An AI tool reads the content, generates new material from it and, depending on its settings, may keep it or use it to improve its models.
Common forms in professional firms:
- Personal or free accounts on ChatGPT, Claude, Gemini and similar tools, used for client work.
- AI meeting note-takers and transcription services that join calls or process recordings.
- Browser extensions that can read the page, the inbox or documents open in the browser.
- AI apps a staff member has allowed into their Microsoft 365 or Google Workspace account.
- AI features switched on inside software the firm already uses, such as PDF editors.
Why does shadow AI happen in law and accounting firms?
Shadow AI happens because staff are trying to get work done and the firm has not given them an approved way to use AI. The tools are free, run in a browser, need no IT involvement and genuinely save time on drafting, summarising and email. When the firm says nothing, staff assume it is fine. When the firm bans AI without offering an alternative, use tends to move to personal phones, where it is harder to see.
Professional firms add their own pressures: deadlines at BAS and tax time, partners who want first drafts faster, and graduates who arrive already used to AI tools. None of this is misconduct. It is demand the firm has not yet met, and the tasks people use shadow AI for are the best brief you will get for choosing an approved tool.
What are the risks for client information?
The core risk is that client information leaves the firm’s control with no record of where it went. With a personal account, the firm cannot see what was entered, cannot choose where it is stored (its data residency), cannot set how long it is kept and cannot delete it when the person leaves. Consumer ChatGPT plans, for example, can use conversations to improve OpenAI’s models unless the user turns that off in their own data controls, and the firm has no way to check whether they did.
The professional consequences follow from that:
- Privacy. The OAIC’s guidance on commercially available AI products recommends, as best practice, that organisations do not enter personal information, and particularly sensitive information, into publicly available AI chatbots.
- Legal professional obligations. The December 2024 statement on the use of AI in Australian legal practice from the Victorian, NSW and WA legal regulators says lawyers cannot safely enter confidential, sensitive or privileged client information into public AI chatbots such as ChatGPT.
- Breach assessment. If client personal information goes somewhere it should not, the firm may need to assess it under the Notifiable Data Breaches scheme.
- Quality. Output from an unmanaged tool can be relied on without anyone checking it, and nobody knows it was AI-generated.
How do you find shadow AI in your firm?
Start by asking, then check the systems you already have. A no-blame staff survey finds the tools and, more usefully, the tasks; Microsoft 365 settings and, where licensed, Microsoft Defender for Cloud Apps show what the survey missed.
- Ask staff. Send a short survey: which AI tools do you use, for what tasks, on which device, and with what kind of information? Promise no consequences for honest answers.
- Review app consents in Microsoft 365. By default, Microsoft Entra ID lets users consent to apps that request permissions not needing administrator approval, such as access to their own mailbox. Your IT provider can list the enterprise applications staff have consented to, which is where AI email assistants and note-takers that connect to Microsoft 365 appear.
- Run cloud discovery if you have it. Cloud discovery in Microsoft Defender for Cloud Apps compares traffic logs against a catalogue of more than 31,000 cloud apps and scores each against more than 90 risk factors, showing which apps are in use and by whom. It draws on Microsoft Defender for Endpoint on firm devices, a log collector or supported secure web gateway, or firewall logs you upload. It is licensed standalone or in plans such as Microsoft 365 E5, and Microsoft 365 Business Premium is not in its listed plans, so check your licences first.
- Check your firewall or web filter. Without Defender for Cloud Apps, your IT provider can usually report on visits to AI sites from the firewall or DNS filter the firm already runs.
- Look at meetings and extensions. Check recent client meeting invitations for note-taker bots, and ask IT to list browser extensions installed on firm devices.
- Watch sign-ups after launch. Once you run ChatGPT Business, workspace discovery lets staff who sign up with a firm email ask to join. A staff member’s personal ChatGPT workspace stays separate, and Business admins cannot make them merge or delete it, so the policy still has to cover personal accounts.
How do you replace shadow AI instead of banning it?
Replace it by giving staff an approved tool that does the same jobs, set up with the firm’s controls, and only then restricting what is left. Bans that come first push use out of sight. Restrictions that come after a good alternative are needed for fewer tools and meet less resistance.
- Match tools to the tasks from your survey. If staff mainly use AI to draft emails, summarise documents and take meeting notes, choose approved tools that do those three jobs well.
- Set them up properly. Configure single sign-on, MFA, apps and data controls before anyone logs in. Our checklist to set up ChatGPT Business securely covers each setting.
- Publish the rules. An AI acceptable use policy names the approved tools, says what information may go into each, and explains how to request a new one.
- Move people across. Help staff rebuild their useful prompts in the approved tool, then ask them to delete firm material from personal accounts and confirm they have done so.
- Then restrict what remains. In Defender for Cloud Apps, tag risky apps as Monitored so staff see a warning they can click through, linking to a page that lists your approved tools, or as Unsanctioned to block them on devices running Microsoft Defender for Endpoint. Blocking needs the right licences and Defender’s network protection switched on, and Microsoft notes a block can take up to three hours to reach devices. In Entra ID, limit user consent to apps from verified publishers, as Microsoft recommends, and turn on the admin consent workflow so staff can request anything else.
- Review each quarter. Re-run the survey or discovery report, update the approved-tools register and ask staff what they still cannot do with the approved tools.
Before step 1, partners need to agree what they want AI used for and who owns the decision. Our list of six questions partners should ask before staff use AI is a short agenda for that meeting.
Example: a 30-person accounting firm on Microsoft 365
Illustrative scenario: before tax time, a 30-person accounting firm runs a staff survey. It finds that most people draft client emails in personal ChatGPT accounts, one team uses a free AI note-taker in client meetings, and two people have installed a browser extension that summarises web pages. The firm sets up ChatGPT Business with single sign-on through Microsoft Entra ID, restricts app consent to verified publishers with an admin consent workflow, approves one note-taking tool after checking where it stores recordings, and removes the extension. The new policy bans tax file numbers and bank details from every AI tool. Three months later, the practice manager re-runs the survey to see what is still unmet.
When should the replacement be private AI?
When staff are using shadow AI on client documents the firm will not put into any public tool, the replacement is private AI rather than a business plan. Pylon Digital’s Private AI and knowledge assistants service is built for firms that cannot put client data into public tools: staff chat, plus answers drawn from the firm’s own precedents, policies and procedures.
Who can help you bring shadow AI under control?
Pylon Digital’s AI Setup service covers the whole replacement: choosing and configuring ChatGPT, Claude, Copilot or Gemini business plans with single sign-on and admin controls, writing the usage policy and onboarding your team. It starts with a free 45-minute discovery call.
This is general information, not legal advice.
