Shadow AI is already inside UK workplaces
Shadow AI is what happens when employees use generative AI for work without the business having formally approved, bought or managed the tool. Deloitte’s inaugural GenAI Workforce Survey, reported by Reuters on 15-16 September 2026, suggests this is no longer a fringe behaviour in the UK. Two-thirds of respondents had tried tools such as ChatGPT, Claude, Gemini or Copilot, while 31% said they used generative AI without their employer’s knowledge. The same logic now applies on the desktop: Apple is tightening Full Disk Access because of AI agents, so unapproved assistants on company Macs deserve the same attention.
The spending figures make the issue harder for small businesses to ignore. Deloitte found that 17% of respondents paid for at least one AI tool themselves, equivalent to one in six UK workers personally paying for AI at work. Combined, that personal spending was nearly £1 billion a year.
For an SME owner, the key point is not that staff are doing something unusual. It is that AI adoption may already be happening outside your normal purchasing, IT and management processes. If you do not know which tools people are using, what information they put into them or what work depends on them, you do not have a clear picture of an increasingly ordinary part of day-to-day operations.
Why staff use unapproved AI tools
The simplest explanation is that the tools can be useful. Deloitte’s survey found an average time saving of 70 minutes a week among users. For a busy employee facing emails, documents, research, admin or repetitive drafting, that is enough to make experimenting with an AI assistant feel worthwhile even when the employer has not provided one.
Shadow AI can therefore grow without any formal technology project. One person creates a personal account, another pays for a subscription, and a useful prompt or workflow gets passed around informally. The business may see faster output without seeing the tool, the account, the cost or the information being shared with it.
That is why a blanket ban is often a poor starting point. The Deloitte figures show that staff are already willing to use and even fund these tools themselves. A more practical response is to understand where AI is helping, then bring the useful activity into a managed environment with clear rules about accounts, data and responsibility.
The practical risks for a small business
The main risk is not simply that an employee has opened an AI account. It is that business information can move into a consumer account without the company having agreed how that information should be handled. Client data may be pasted into prompts, files may be uploaded for analysis, and work may be produced in an account that the business neither owns nor administers.
There is also an audit and continuity problem. If an important workflow lives in one employee’s personal AI account, the business may have no usable record of how work was produced or which instructions were used. If that person leaves, the prompts, history, paid access and working method may leave with them as well.
For SMEs, contractual and data-protection exposure also matters. A company can have obligations to clients and other parties about how information is handled, even if an employee chose the tool independently. The practical question is therefore not whether AI is “allowed” in the abstract, but which information can be used with which approved tools, under which account, and who is responsible for checking the output.
What a one-page AI policy should contain
An AI policy does not need to become a long technical manual. For a small business, one clear page can be more useful than a document nobody reads. It should tell staff what they can do, what they cannot do, and where to go when a task does not fit the rule.
- Approved tools and accounts: name the services staff may use for work and require business-managed accounts where available.
- Data rules: state what client, personal, confidential or commercially sensitive information must not be entered into unapproved AI tools.
- Human checking: make clear that AI-generated work must be reviewed before it is sent, published or used to make a business decision.
- Record keeping and continuity: keep important prompts, workflows and outputs in places the business controls rather than only in a personal account.
- Escalation: give staff a simple route to ask whether a new tool or use case is acceptable before they use it with business information.
The policy should also match what the business can actually enforce. If staff are told not to use personal accounts but are given no approved alternative, shadow AI is likely to remain attractive. The useful test is whether an employee with a real task can understand the rule in a minute and knows which sanctioned tool to use instead.
Choose sanctioned tools instead of relying on bans
AI vendors are increasingly packaging products around business workflows rather than offering only a general chatbot. Anthropic’s release notes say Claude for Small Business launched on 15 September 2026 with 43 workflows and 27 connectors, including Shopify, Salesforce, Zoom, Xero, Gusto, Square, Stripe and Zapier. Anthropic also introduced a Salesforce-in-Claude beta with 37 pre-built sales skills.
That launch is one example of the direction vendors are taking, not a reason for every SME to choose that product. The useful lesson is that a sanctioned AI tool can be assessed against the systems your team already uses and the jobs they actually need to complete. An owner can compare whether a product supports the relevant workflows, can be managed centrally and fits the business’s rules for information handling and access.
Start with the shadow use already happening. Ask which tools staff pay for, which tasks they use them for and what would stop them moving to an approved option. You can then decide whether to standardise on one or more services, stop paying for duplicate personal subscriptions and document the workflows that are worth keeping inside the business.
Do not treat search traffic as a fixed part of the plan
AI is also changing the environment in which SMEs win website traffic. Google confirmed an early-stage Search Console AI contribution pilot on 14 September 2026, according to Search Engine Land, Search Engine Roundtable and Digiday. A limited set of publishers are being paid when their content is used in AI Overviews, AI Mode and Gemini, with participants seeing a monthly earnings figure and having the option to opt out.
The pilot is limited, so it should not be read as a general payment model for websites. It does, however, show Google testing a direct relationship between publisher content and AI-generated search experiences. For an SME that relies on organic visibility, that is another reason not to assume that search will keep sending traffic in exactly the same way.
There was a second reminder on 15 September 2026. Search Engine Roundtable reported a spike in Google Search ranking volatility that morning, but it had not been confirmed as a named core update. The sensible takeaway is not to guess at an update name; it is to recognise that rankings can move while the search product itself is also changing.
What to do this month
The immediate job is to make AI use visible. Ask staff which generative AI tools they use for work, whether they pay personally, which tasks they use them for and whether they enter client or company information. The aim is to build a factual picture of current behaviour rather than assuming either that nobody uses AI or that every use is risky.
Next, publish the one-page policy, decide which tools are sanctioned and move important workflows into business-controlled accounts where possible. Keep the rules proportionate: protect sensitive information, preserve continuity, require human review and make it easy for staff to ask before trying a new service. A policy that reflects real work is more likely to be followed than one built around a general prohibition.
Finally, treat AI adoption and search visibility as connected management issues rather than isolated technology topics. Deloitte’s figures show employees are already adopting AI from the bottom up, while Anthropic is packaging more structured SME workflows and Google is experimenting with how content contributes to AI search experiences. For a small business, the practical priority is control: know what your team uses, decide what the business supports, and keep your website and marketing plans flexible enough to respond when the platforms change.
Need help putting this into practice?
Talk to our Birmingham team — free consultation, no obligation, fixed quotes.



