Skip links
Shadow AI in Business: Protecting Sensitive Data

Shadow AI in Business: Protecting Sensitive Data

Shadow AI in business might look like this:

Sophie is a receptionist at a small business in Laval that specializes in legal services. Every day, she responds to dozens of client emails, schedules appointments, and prepares documents for lawyers. Between calls, she discovered ChatGPT—a magical tool, she thinks, that allows her to rephrase messages, write faster, and even summarize contracts to make them more understandable.

One morning, to respond to a client in a hurry, she copies a confidential excerpt from a contract in progress into the tool to create a clear summary. She also added some personal details about the client to provide context for the response. What she didn’t know was that once this information was sent to the tool, it was beyond the company’s control… and could even be used to train the model if the tool wasn’t configured correctly.

Sophie didn’t mean any harm. She simply wanted to do a good job and do it faster.

But this seemingly innocuous action raises an important question: how can an SME prevent this kind of situation without dampening the motivation or efficiency of its employees?

Shadow AI refers to the use of artificial intelligence tools (such as ChatGPT, Copilot, or others) without authorization or supervision from the organization. It is often the result of good intentions: saving time, improving the quality of responses, simplifying tasks.

And it is far from marginal: according to a study by IBM Canada (september 2025), 79% of Canadian office workers already use AI tools at work, but only 25% do so with solutions approved by their company.

In other words, three out of four employees are acting in the shadows, often without being fully aware of it.

 

Why do employees like Sophie use these tools?

Sophie is no exception. Many people in SMEs, whether in accounting, administration, or customer support, are exploring these tools on their own.

Why?

  • To improve the quality of communications: a good tone, fewer mistakes, clearer wording
  • To work faster: AI helps summarize, rephrase, and create standard responses
  • Because they haven’t received clear guidelines: when there are no rules or guidelines for use, people go with their instincts
  • Because the tool is accessible and free: all you need is a simple website

And above all, 97% of Canadian users say that AI improves their productivity. No wonder Sophie jumped on the bandwagon. What is more worrying is that, at the same time, only 36% of Canadian companies have officially deployed generative AI, according to a survey by Ipsos Canada (2024) , leaving room for unregulated use in many cases.

 

The real risks, even when intentions are good

1. Disclosing sensitive information

By including customer data or contract excerpts, Sophie is exposing the company to a breach of confidentiality, which could result in legal action or penalties.

2. Non-compliance with Bill 25

Since Bill 25 came into effect in Quebec, companies must ensure rigorous management of personal information. Sending this information to an external AI without explicit consent violates this law.

3. Unreliable or biased results

If Sophie does not carefully review what the AI has generated, she could send inaccurate or misinterpreted information, compromising the quality of service.

4. Reproduction of risky habits

If one person uses AI in this way without consequence, others may imitate them… and amplify the risks without realizing it.

How to turn the problem into a solution?

Rather than punishing Sophie, her employer has the opportunity to turn this misstep into a springboard toward a healthier and better-equipped digital culture.

1. Establish a clear policy on the use of AI.

  • Define what is and is not permitted (e.g., never include personal or confidential information).
  • Provide concrete examples of acceptable uses.
  • Explain the reasons (security, compliance, reputation)

2. Offer simple, human-centered training

  • This is good news, because 68% of Canadians say they would be interested in AI training if their employer offered it, according to a survey by HRD Canada. And nearly half believe it is the employer’s responsibility to provide it.
  • Organize a short training session or lunch & learn to explain the risks of shadow AI.
  • Use concrete examples like Sophie’s to make it tangible.
  • Provide a best practices guide (e.g., never copy sensitive information into an unauthorized tool).

3. Provide approved and secure tools.

  • Offer access to ChatGPT Enterprise, Claude Pro, or another tool with protected data.
  • Configure the tools so that no information is retained for training purposes.
  • Create email templates, standard responses, or documents directly in internal tools.

4. Create a climate of trust and supervised innovation.

And beware: 46% of Canadian employees say they would consider leaving their job for a company that is more advanced in AI (source : IBM Canada). The message is clear: offering reliable AI tools is not just a security issue, it is also a factor in staff retention.

  • Encourage employees to suggest uses for AI within a structured framework.
  • Set up a rapid validation process for tools or ideas.
  • Reward good initiatives by highlighting ingenuity while correcting any missteps.

A realistic solution for SMEs

You don’t need a complex IT department to manage AI. Here’s what an SME can do quickly:

ActionImpact
Draft an internal AI policyClarifies the rules for everyone
Organize a short training sessionRaises awareness without creating fear
Offer one or two approved toolsReduces the need to “work around the rules”
Appoint an internal reference Encourages safe innovation

Sophie wasn’t trying to break any rules. She just wanted to be efficient, professional, and useful. And it’s precisely because her intentions were good that her employer should reach out to her, not to punish her, but to educate her.

Every small business has its own Sophie. The challenge is not to undermine them, but to provide them with a clear framework, the right tools, and a culture that values responsible innovation. That’s how you turn an invisible threat into a powerful lever.

Are you looking to empower your team to use AI responsibly and effectively?

We can help you create your usage policy, train your employees, and identify the right tools. Write us or book a consultation—and let's make AI an ally, not a risk.