SHADOW AI & EMPLOYEE AWARENESS
Don’t Fight Shadow AI. Turn On the Light.
Organizations cannot expect employees to manage AI risks they have never been taught to recognize.
During a recent consulting conversation with a large private firm about its AI transformation, a simple question arose: How risky is it for employees to use personal AI accounts for company work? The answer was: it depends. What appeared to be a straightforward question quickly led us through model training, data retention, feedback buttons, and consumer terms. Even a careful, well-intentioned user found those boundaries difficult to understand.
That conversation captured why Shadow AI is often misunderstood. Most employees who use an unapproved AI tool are not trying to evade security, violate policy, or expose company information. They are trying to summarize a document, improve an email, analyze a spreadsheet, debug code, prepare a presentation, or finish another legitimate piece of work.
The tool is available immediately. It appears simple. A personal subscription may cost only $20 a month. The employee sees a familiar chat window and a useful answer. What remains largely invisible is the data-processing relationship behind that window.
Earlier EMLI Insights examined Shadow AI as a governance problem and considered the legal and commercial consequences of giving protected information to consumer AI. This article addresses the question that comes before both: Do employees understand what happens when they use these tools?
The employee sees a tool. The company inherits a data relationship.
Consumer AI services do not all handle information in the same way. Even within one provider, the answer can change according to the product, account type, privacy settings, feature used, feedback submitted, and contract governing the service.
Consider two popular services. OpenAI states that data sharing for model improvement is enabled by default for ChatGPT Free, Plus, and Pro users in personal workspaces, although users can turn it off. Anthropic requires users of Claude Free, Pro, and Max to choose whether new and resumed chats may be used to improve Claude. If a Claude consumer permits model improvement, Anthropic states that the applicable information may be retained for five years.
That is already more nuance than most employees encounter in workplace training. But training is only one issue. Storage, deletion, safety review, authorized human access, legal processing, and feedback are separate questions.
A particularly easy detail to miss is the familiar thumbs-up or thumbs-down button. Both OpenAI and Anthropic state that when a consumer voluntarily provides feedback, the entire conversation associated with that feedback may be used—not merely the single answer being rated. An employee may therefore disable ordinary model training, paste company information into a thread, and later unknowingly create a separate disclosure path by rating a response.
A consumer subscription may increase capability or usage limits. It does not automatically provide the contracts, administrative controls, logging, retention choices, and organizational oversight associated with a managed business service.
Questions every AI-using employee should be able to answer
Do not assume that employees who are comfortable using AI understand all the risks, settings, and terms behind the tools they use. Before deciding how to respond to Shadow AI, leaders should ask what their employees actually know—and what the organization has taught them.
- Do you know if your AI tool can use your conversations to help train future AI models?
- Do you know that a personal AI subscription does not give you the same protections as a company-managed account?
- Do you know that when you opened a personal AI account, you—not your company—accepted the provider’s terms?
- Do you know that clicking 👍 or 👎 on just one chat response may make your entire conversation available for review?
- Do you know how long your AI provider may keep your questions, files, and conversations?
- Do you know that an AI tool may use your internet address, known as an IP address, to estimate the location where your request came from?
- Do you know that turning off training does not delete your conversations or mean that they can never be reviewed?
- Do you know what company information you should never enter into a personal AI account?
- Do you know what an AI tool may be able to see or use when you connect it to your email, files, browser, or other work systems?
- Do you know that deleting a chat from your screen may not immediately remove it from the AI provider’s systems?
- Do any of the AI tools you use contain both personal and work conversations?
- Do you know that mixing personal and work conversations in one AI account could cause parts of your private chat history to be reviewed in a lawsuit or investigation?
- If something went wrong, could you tell your company what you shared, which AI tool received it, and which account settings were turned on?
If employees cannot answer these questions confidently, the organization may not have an employee-compliance problem. It may have an employee-awareness problem.
One company can unknowingly operate under many different rules
In a governed enterprise service, the organization can evaluate terms, configure controls, manage identities, establish retention rules, and obtain appropriate evidence. With Shadow AI, those decisions are fragmented across individual employees.
One employee may use a free personal account with model improvement enabled. Another may use a paid personal account with it disabled. A third may submit feedback on a conversation. A fourth may share a chat link. A fifth may connect personal AI to a company drive. Each believes they are using the same general category of tool, but company information may be entering materially different processing and retention arrangements.
Security, legal, privacy, and compliance teams may have no aggregate answer to basic questions: What did we send? To whom? Under which terms? For how long? Who could access it? Can we retrieve it? Can we prove its deletion?
This is why an AI policy cannot consist solely of a list of approved and prohibited products. The provider’s name is not enough. The relevant unit of governance is the combination of use case, information, account, feature, configuration, authority, and contract.
Chat exposure is only the first layer
The risks discussed so far concern chat tools, where an employee deliberately places information into a conversation. Agentic AI changes the equation.
An agent may be connected to email, documents, source repositories, browsers, calendars, messaging platforms, credentials, and business applications. Depending on its tools and permissions, it may be able not only to read information but also to modify files, execute commands, send messages, make external requests, or initiate transactions.
The distinction is fundamental:
When governing chat tools, ask: “What information did the employee disclose?”
When governing agents, ask: “What information and authority did the employee delegate?”
The exposure increases again when employees import skills, plugins, extensions, or instruction packages from sources the organization has not evaluated. A skill may look like a convenient set of prompts, but it can contain operational instructions, dependencies, and executable components. It can inherit the access available to the agent and its surrounding environment.
OpenClaw illustrates the broader issue. Its own security guidance says the model or agent should not be treated as a trusted principal. Effective boundaries must come from authentication, tool policy, sandboxing, configuration, and execution approvals. Its documentation recommends sandboxed operation for untrusted inputs and risky tools. Those are decisions that require technical judgment—yet an employee may install a useful-looking skill with no reason to realize that a software supply-chain decision has just been made.
The danger is not unique to OpenClaw. The same pattern can emerge wherever an agent combines three conditions: access to valuable data, exposure to untrusted instructions or content, and the ability to communicate or act outside the protected environment.
Employees cannot manage risks that remain invisible
A conventional security message—“Do not paste confidential information into public AI”—is necessary, but incomplete. Employees also need to understand account boundaries, provider settings, feedback behavior, connected sources, imported skills, permission scope, and the difference between assistance and delegated action.
That education should be practical. Show employees where to find relevant settings. Demonstrate what a feedback submission can include. Explain why a personal paid account is not an enterprise environment. Give recognizable examples of sensitive information from their actual work. Teach them to inspect permissions before connecting a source or installing a skill. Give them a fast, nonpunitive way to report accidental disclosure or questionable agent behavior.
Awareness cannot carry the entire burden. Organizations must still provide useful approved alternatives, proportionate controls, vetted integrations, restricted permissions, monitoring, and accountable ownership. But those measures work better when employees understand the reasons behind them and can recognize risks before a control intervenes.
A ban tells employees where not to work. Awareness helps them decide how to work safely when the next model, feature, agent, or skill appears—often before the company has written a policy for it.
Turn on the light
Shadow AI is frequently described as an employee-behavior problem. That description is incomplete. Most employees are making individually reasonable decisions with incomplete information. They see speed, convenience, and better output. The organization sees data transfer, contractual exposure, fragmented retention, invisible integrations, and delegated authority—but may never have explained those consequences in terms employees can use.
The response should not begin with mandates and restrictions. It should begin with visibility: visibility for the organization into unmet needs and actual usage, and visibility for employees into what happens behind the chat window.
Do not fight the shadow. Turn on the light.
References: OpenAI personal-workspace data controls; OpenAI data use and feedback; OpenAI privacy policy; Anthropic consumer terms and retention update; Anthropic model-training and feedback guidance; Anthropic location guidance; OpenAI civil user-data request policy; OpenClaw security policy; and OpenClaw skills documentation.