Ask a business owner whether their company uses AI and you tend to get one of two answers. Either “not yet, we’re looking at it,” or “a little, here and there.”
Both answers are usually wrong. The accurate answer, at most companies I talk to, is: yes, daily, by more people than you think, in tools you didn’t approve, with data you’d rather not have leave the building.
This is what people call shadow AI. It isn’t a hypothetical. The U.S. Chamber of Commerce puts generative AI use among small businesses at 58 percent and climbing. A 2026 Founder Reports survey of more than 2,000 U.S. workers found 44 percent say their employer has no clear AI policy or they aren’t sure one exists. At companies with fewer than ten employees, that number is 59 percent.
So the tools are in the building and the rules are not. That gap is the whole problem.
This isn’t a discipline problem
The instinct, when an owner first hears this, is to assume somebody broke a rule. Usually nobody did, because there was no rule to break.
Here’s what the research actually shows about motive. PagerDuty’s 2026 Shadow AI Survey of 1,250 office professionals found 66 percent had used AI tools at work despite believing those tools weren’t permitted. More than a third admitted putting customer data into public AI models while doing it. And when asked whether they’d disclose their AI use or keep quiet to avoid being told no, 39 percent said they’d rather not tell anyone.
Read that last one again. Your best people are hiding the thing that’s making them faster, because they’ve correctly guessed that raising their hand gets them a no.
The reason is simple, and it’s the same reason shadow IT happened fifteen years ago with Dropbox and personal Gmail. The approved toolset is slower than the unapproved one. Research collected by NeuralTrust found 27 percent of employees on unsanctioned tools say the unapproved option simply works better. When the official path is worse, people route around it. That’s not a character flaw. That’s someone trying to get their work done.
Banning it doesn’t work, and you probably knew that
Every owner considers the ban. It’s the cheapest looking option: one email, problem solved.
It isn’t solved. A Software AG survey found 46 percent of employees would keep using AI tools even after an organizational ban. All a ban buys you is the same usage with worse visibility, because now the people doing it have a reason to be quiet about it.
There’s also a real cost to being blind here. IBM’s Cost of a Data Breach research found shadow AI added an average of $670,000 to breach costs, and showed up in one out of every five of the 600 breaches studied. Verizon’s 2026 Data Breach Investigations Report found shadow AI detections rose fourfold in a single year, making it the third most common non-malicious insider action turning up in breach investigations.
Non-malicious. That word matters. Nobody in these numbers was trying to hurt the company.
For a small business the exposure is specific and it’s usually about client trust, not hackers. A staffer at a law firm pasting case details into a consumer chatbot. A bookkeeper uploading a client’s tax documents to summarize them. An office manager dropping an employee roster into a tool to reformat it. Every one of those is a person doing a reasonable thing with a tool nobody told them was off limits.
What to do instead
The goal is not to stop AI use. The goal is to make the sanctioned path faster than the secret one, so people choose it on their own. Four things get you most of the way there, and none of them require a big project.
- Find out what’s actually in use. Before you write a single rule, ask. Not as an audit, as a survey: what are you using, what for, does it help. You’ll learn two things. Which tools are already load bearing, and which of your people have quietly figured out something worth spreading. Expect to be surprised at how many tools there are. Productiv’s 2026 analysis found the average enterprise has 14 distinct AI tools in use while IT knows about four or five.
- Approve something good, and pay for it. Most shadow AI is people on free consumer accounts, which is exactly the tier where your data is least protected. Picking one or two business-tier tools and putting them on the company card removes the reason to freelance. This is the single highest leverage move on the list and it usually costs less than one bad afternoon of cleanup.
- Write one page. Not a policy binder. One page that answers three questions: what’s approved, what should never be pasted into any AI tool, and who to ask when it’s unclear. On the never list, keep it concrete. Social security numbers, dates of birth, bank and payment details, health information, employee records, and anything covered by a client confidentiality agreement. People follow rules they can remember.
- Train, then check back. A one-time announcement decays fast. Lenovo’s 2026 workforce research found a large share of employees get no AI training at all, and many who do describe it as irregular or ineffective. An hour a quarter, with real examples from your own work, beats a slide deck nobody opens.
The part most people miss
Governance sounds like the brakes. In practice it’s what lets you go faster.
Right now your company is running an uncontrolled experiment. People are using AI, you don’t know where, and none of what they’ve learned is being shared. The person who figured out how to cut two hours off the weekly reporting cycle is doing it alone, in a browser tab, and when they leave, it leaves with them.
Bringing that into the open does two things at once. It closes the risk, and it turns a pile of private workarounds into something the whole company can use. Same activity. Very different outcome.
Start by asking. You’ll be surprised what’s already happening.
Ryvin helps small and mid sized companies put AI to work in the way their business actually runs, from setting the ground rules to building the systems and staying on as they change. If you want a straight read on what’s already in use at your company and what to do about it, get in touch at hello@ryvin.us.
Sources
- PagerDuty, 2026 Shadow AI Survey (conducted by Wakefield Research)
- Founder Reports and U.S. Chamber of Commerce figures, via defend-id, “Employee AI Use Policy: A 2026 Guide for Small Business”
- IBM Cost of a Data Breach and Verizon DBIR figures, compiled at Axis Intelligence
- Lenovo Work Reborn Research Series 2026, via Help Net Security
- Software AG and Productiv figures, via NeuralTrust
- Terdawn DeBoe, “Your Employees Are Using AI Without Telling You. Now What?”, Forbes
- ISACA and Optro governance visibility data