Here is a question worth asking at your next management meeting: which AI tools are our employees using, and what are they putting into them? If the honest answer is that nobody knows, your company is typical. It is also exposed. In a global survey released this month, 64 percent of employees admitted using AI tools their employer never approved. They are drafting customer emails, summarizing contracts, analyzing sales data and screening resumes with free chatbots on company time, usually with good intentions and no idea what could go wrong. Security professionals call this shadow AI, and it has quietly become one of the most common unmanaged risks in American business. The encouraging part is that the single most effective response costs almost nothing: a short written policy.
Shadow AI Is Ordinary Behavior, Not Rogue Behavior

Shadow AI means employees using AI tools without their employer’s approval or oversight. It is worth being clear about who does this, because it is not the careless few. It is your best people. The paralegal who stays late, the sales manager chasing quota and the HR coordinator buried in applications all reach for the same free tools everyone else uses at home, because those tools genuinely make the work faster. Nobody told them not to, and nobody offered an approved alternative, so they made a reasonable decision in an instruction vacuum. That is what makes shadow AI different from most compliance problems. You are not fighting misconduct. You are filling a silence, and silence is the one thing management fully controls.
The Information Flows One Way
The first risk is what goes into the tools. A prompt typed into a free public chatbot leaves your company’s control the moment the employee hits enter. Depending on the provider and the account settings, it may be stored indefinitely, reviewed by the provider’s staff or used to train future models, and there is no reliable way to claw it back. Samsung discovered this in 2023 when engineers pasted proprietary source code into ChatGPT to debug it, and the company responded by banning generative AI tools outright. For your business, the legal stakes compound quickly. Trade secret law protects only information you took reasonable measures to keep secret, and a pattern of employees feeding customer lists or pricing formulas to public chatbots is precisely the evidence an adversary would use to argue those measures did not exist. Nondisclosure agreements with customers and partners do not have an exception for helpful chatbots. And if the pasted material includes personal information about customers, patients or employees, a growing body of state privacy law is implicated as well. According to IBM’s most recent Cost of a Data Breach Report, one in five breached organizations was compromised through shadow AI, and those breaches cost an average of $670,000 more than others, in part because they disproportionately exposed customer personal information.
The Machines Are Confident When They Are Wrong
The second risk is what comes out. Generative AI produces polished, authoritative prose whether or not the underlying content is true, and it never lowers its voice when it is guessing. My own profession furnished the famous cautionary tale: in Mata v. Avianca, a federal judge sanctioned lawyers who filed a brief citing six cases that ChatGPT had simply invented, fake quotations included. Businesses make the same mistake with lower visibility and similar consequences. An AI-drafted proposal that misstates your product’s specifications becomes a warranty problem. A confident but wrong summary of a regulation becomes a compliance failure. Marketing copy that fabricates a claim about a competitor becomes a defamation demand letter. A resume screening tool that quietly filters by proxies for age or ethnicity becomes an employment discrimination claim. In every case the error carries your company’s name, because a chatbot cannot be sued and your business can. Regulators are moving in the same direction. In New Jersey, pending legislation such as A4730 would treat the undisclosed use of AI in consumer interactions as an unlawful practice under the Consumer Fraud Act, with its familiar arsenal of civil penalties and treble damages. How your business uses AI is itself becoming regulated conduct.
A One-Page Policy Beats an Unwritten Rule
Faced with all this, some companies ban AI. Samsung’s experience shows why that rarely ends the story: the work pressure that created shadow AI does not disappear, it just moves to personal phones where you have even less visibility. The better answer is a short written policy, and it does not need to be elaborate to be effective. It should tell employees which tools are approved, because people follow a marked path when one exists. It should say plainly what never goes into any AI tool: customer and employee personal information, anything covered by a confidentiality agreement, trade secrets, financial records and the like. It should require a human being to review AI-generated work before it goes to a customer, a court, a regulator or anyone else outside the company. It should address when AI use must be disclosed, an area where the law is actively developing. And it should name the person to ask when a situation is unclear, because employees who cannot ask will improvise.
A policy of this kind earns its keep twice. Day to day, it channels employee behavior before problems occur, and the data consistently shows that organizations with AI governance in place suffer fewer and cheaper incidents than the majority still operating without any. When something goes wrong anyway, the policy becomes your best exhibit. It is the reasonable measure that preserves trade secret protection, the standard that justifies discipline and the document your insurer, your enterprise customers and eventually a regulator will ask to see. Your employees started using AI without waiting for your permission. Writing the rules this quarter is far cheaper than explaining next year why there were none.
You may also enjoy:

- The Uneven Impact of Generative AI on Young Workers
- Misclassifying Workers
- NJ Pushes Transparency in Employment Practices
- Non-Competes: Sword and Shield
and, if you lke what you’ve read, please subscribe below or in the right hand column.