The shadow AI already running inside your business

Most small business owners I talk to think they haven't started using AI yet. Their staff started about eighteen months ago, without telling them, and that's the actual starting point for any honest conversation.

A bookkeeper at a 14-person accounting firm in Mississauga showed me her ChatGPT history last month. She had been using it almost every day for about a year and a half. Categorizing transactions she wasn’t sure about. Drafting client emails when she needed a softer tone. Summarizing the partner’s voice memos. Translating a recurring client’s invoices from Portuguese.

The firm did not know this was happening.

When I asked if she’d ever pasted a client’s bank statement into the chat, she got quiet and said “probably a few times.” When I asked if she’d ever pasted a SIN, she said no, very firmly, then said “well, once, but I edited it out first.” When I asked how the firm’s IT policy treats this, she laughed and said the firm did not have an IT policy.

She is not unusual. She is the median.

I have now had some version of this conversation with employees at roughly fifteen small businesses over the last six months. Most small businesses with knowledge workers have shadow AI use the owner does not know about, closer to 80 percent than 50.

That changes what a serious conversation about AI inside an SMB has to start with.

What shadow AI actually looks like

The cliché version is a rogue employee feeding sensitive data into ChatGPT. The reality is messier and more useful.

In the businesses I’ve looked inside, the shadow use clusters into four buckets.

The first is competent people getting through tedious work faster. The bookkeeper categorizing transactions, the paralegal summarizing a deposition, the estimator turning a client’s rambling voicemail into a clean specification. These people are not doing anything malicious. They figured out that a tool could shave four hours off their week, and they did not mention it because they correctly guessed the owner would not understand and would probably ban it.

The second is people covering for skills they don’t quite have. The junior salesperson who isn’t a strong writer using ChatGPT to draft every email. The new admin who isn’t confident in her English using it to clean up customer-facing replies. The tool is masking a training gap, and the owner has no idea the gap exists.

The third is workflow improvisation that has become load-bearing. Someone built a little routine eight months ago, doing it twenty times a day. If they got hit by a bus, nobody else in the company knows the routine exists or how to do it manually anymore. The firm is now dependent on a workflow that lives in a personal browser tab.

The fourth is the worst one. Confidential information pasted into free-tier consumer accounts, with no policy, no logging, and no idea what the vendor’s data retention says. Patient information, salary data, litigation strategy, client tax returns. It is happening in businesses where the owner believes nothing of the sort would ever happen, because they have never asked.

Why the owner usually doesn’t know

The honest reason is that asking creates a problem the owner doesn’t yet know how to solve.

If the owner asks “is anyone here using ChatGPT?” and the answer is yes, the next question is “for what?” and the question after that is “is that allowed?” Most owners haven’t thought through that policy, because it wasn’t a question that existed for them three years ago.

So the question doesn’t get asked. The staff, sensing that asking will produce a “no” by default, do not bring it up either. Both sides have a quiet agreement to let it stay invisible.

That works fine until the day a client notices an email from your firm sounds nothing like the person who supposedly wrote it. Or a transaction gets miscategorized in a way nobody can trace back, because the source was a free-tier chat window that doesn’t keep history past 30 days. Or your professional liability insurer sends a notice that policies now exclude AI-related claims unless certain controls are in place.

At that point the question gets asked. The answer comes in fast, and most of it is unpleasant.

What this means for AI projects you’re considering

Here is the part most consultants don’t tell SMB owners, and it took me too long to figure out myself.

The first thing a real AI engagement should do is not build anything new. It should be an honest inventory of what is already happening. Sit down with your staff individually, with explicit amnesty for whatever they’ve been doing, and find out where AI is already in your workflows. The bookkeeper at the firm in Mississauga had built a routine that saved her about six hours a week and nobody else in the firm knew. The owner was about to spend $18,000 on a transaction-categorization tool that would have done a worse version of what was already running for free.

That inventory tells you things no vendor demo can.

It tells you which workflows your staff already understand to be slow. They’ve voted with their feet. The boring spreadsheet everyone has been quietly automating for a year is the one to formalize. Not the one the owner wishes were faster. The one the team has already chosen.

It tells you where the data hygiene problems actually are. If three different employees are pasting client data into three different free accounts, you don’t have an AI strategy problem. You have a compliance problem that already exists and just hasn’t been acknowledged. The fix is not to ban the tool. It is to provide a sanctioned alternative that does the same job inside controls.

It tells you which of your staff are going to be your collaborators on the rollout. The people who have been quietly experimenting are the people who will run the eventual deployment well. They already know what works. They have, in many cases, more practical instinct about your business plus AI than any consultant walking through the door. Find them. Pay them more.

The uncomfortable part for owners

If you’re tempted to react to the discovery of shadow AI with a crackdown, wait a week before doing anything.

The instinct to ban is understandable. There are real risks, especially around client confidentiality and regulated data. But the practical effect of banning AI inside a small business in 2026 is not that AI stops happening. It’s that it goes one layer deeper underground. Staff use their phones instead of their laptops. They paste through personal email instead of the company browser. The information leakage gets worse, not better, because now nobody can ask for help when something feels off.

The owners who get the next year right are the ones who acknowledge what’s already happening, name what’s allowed and what isn’t, provide sanctioned tooling, and trust their staff to use it well within those rails. The ones who try to put it back in the box will have a much harder time.

Where this leaves a firm like mine

A year ago, our intake conversation with a new client was about the workflow they wanted to automate. Now, before that conversation, we ask permission to spend a day talking to their staff with confidentiality. About a third of the time, the day produces something the owner did not know they had. Once it was a fully working invoice triage routine being run by one accounts-payable clerk who had never told anyone. Once it was a sales associate using a custom GPT to qualify inbound leads before they hit the CRM. Once, less happily, it was a contract paralegal pasting opposing-counsel correspondence into a personal ChatGPT account on a phone in the parking lot.

In every one of those cases, the right first project shifted based on what we found. The build we eventually delivered was smaller and more directly tied to what the team already trusted.

This is not the engagement most firms want to sell. It produces an honest baseline, not a flashy day-one deliverable, and the businesses that start there end up doing AI work that actually sticks.

If you own a small business and you have not yet sat down with your staff and asked, with amnesty, where AI is already showing up in their week, that’s the most useful thing you can do this quarter. It costs nothing. It probably saves you a wrong-shaped project. And it tells you, before you spend a dollar, where the real work actually lives.


From argument to implementation

Apply the idea to one real workflow.

The Nano-Pilot ranks a small set of opportunities and makes the assumptions visible. If the workflow is already scoped, the Implementation Sprint is the build path.

Describe the workflow behind the argument.

Glen replies in writing with a fit assessment within two business days.

Send a written intake