TL;DR

Nearly nine in ten UK executives think staff are running AI tools their employer never approved, and just over half worry confidential material is going into them. The research, from process-automation vendor Turbotic, covers more than 1,000 senior people who actually sign off AI projects.

Where the unapproved tools are

The department most often named is IT, at 36% — the function nominally responsible for controlling this. Customer service follows on 30%, then marketing at 28% and sales at 27%. That spread suggests the behaviour is not confined to technical staff experimenting; it tracks wherever there is repetitive drafting and lookup work.

Beyond data leakage, the worries stack up predictably: 38% cite regulatory or compliance exposure, 36% flag AI use nobody is supervising, and 35% fear unreliable output steering real business decisions.

The most revealing number is smaller. More than a quarter of these respondents — people with direct responsibility for AI deployment decisions — had not met the term “shadow AI” before this survey asked them about it. Awareness is trailing the practice inside the very group meant to be governing it.

Read the vendor’s interest, then read the finding

Turbotic sells AI oversight, so a survey establishing that oversight is absent is not disinterested work. Its chief executive Theodore Bergqvist argues that visibility and governance belong in the deployment itself rather than bolted on later, and that the duty sits with leadership rather than staff.

The finding survives the conflict of interest, though, because it fits what independent work already shows. Adoption in the UK is broad but shallow — reaching most jobs while few workers use it heavily, and 64% of firms here say pilots have already crossed into daily operations. Tools spread faster than the policies covering them, which is precisely how Wrexham council ended up putting Copilot on every desk with no digital budget.

Looking forward

For UK SMEs the practical exposure is contractual before it is regulatory. Client agreements increasingly specify where data may be processed, and a marketing assistant pasting a draft into a consumer chatbot can breach one without anyone noticing. Cheap first moves are an approved-tools list, a named owner, and a route for staff to request something rather than route around the rules. Enterprise buyers are already demanding that monitoring data stay in their own cloud; smaller firms will inherit that expectation through the supply chain.