Why are staff using AI tools the firm has not approved?

Because it works, at least well enough, and because nobody gave them anything else. A fee earner with a proposal due, a stack of meeting notes to write up and a client chasing an update finds that a free chat assistant on their phone produces a passable first draft in seconds. They are not trying to break rules. In most firms there are no rules to break.

This is what people mean by shadow AI: staff using consumer tools on firm work, outside any policy, on personal accounts the firm cannot see. It is not a fringe behaviour confined to a few enthusiasts. The people most tempted are usually the capable, busy ones who care about getting the work out, which is exactly the group a firm least wants to alienate.

The honest reading is that shadow AI is a symptom. It tells you where the work is slow enough that people went looking for help on their own.

What does it actually put at risk?

The risks are real, and they are not mainly about the technology. They are about what goes in, what comes out and whether anyone knows either happened.

  • Client confidentiality. A fee earner who pastes a draft letter, a set of accounts or a witness statement into a consumer tool has shared client material with a third party the client never agreed to. Depending on the account type and its settings, that content may be retained or used to improve the service. The fee earner usually has no idea which.
  • Personal data. Much client work contains personal data, and sending it to an unapproved processor raises questions under UK GDPR that the firm cannot answer, because it does not know the transfer happened. Our guide to data protection and AI on client work covers the principles.
  • Unchecked output. Consumer tools produce fluent text that can be confidently wrong. If a paragraph drafted in one goes to a client without proper review, the firm is answerable for it as if a person wrote it.
  • No record. When something does go wrong, the firm cannot work out what was used, what was shared or what the tool changed, because none of it touched a firm system.
  • Professional obligations. Regulated firms owe duties of confidentiality and competent supervision. Regulators such as the SRA, ICAEW and RICS expect firms to know how client work is done. Work done in tools the firm does not know about sits awkwardly with that.

Why does banning it rarely work?

A ban is the obvious response and it is almost always the wrong one. It fails for four reasons.

First, it cannot be enforced. Blocking a website on the office network does nothing about the phone in someone's pocket or the laptop at home. The behaviour moves somewhere even less visible.

Second, it removes the conversation. Once use is forbidden, nobody admits to it. The firm loses the one source of information that matters: which tasks people found slow enough to take the risk.

Third, it does nothing about the pressure. The proposal is still due and the notes still need writing. A ban asks people to go back to the slow way without offering anything faster. Some will comply and resent it. Others will quietly carry on.

Fourth, it signals that the firm has no answer. Staff notice when leadership responds to a new tool by forbidding it rather than understanding it, and the more capable ones draw conclusions about where the firm is heading.

None of this means anything goes. It means the rules need to be ones people can follow while still getting the work done.

What works better than a ban?

A better response has four parts, roughly in this order.

  1. Find out. Ask openly, without blame, which tools people use and for what. The answers are a map of your slowest processes.
  2. Offer an approved route. Give staff a sanctioned tool on a business agreement, with clear terms about how firm and client content is handled. People will usually choose the approved option if it is at least as convenient as the unofficial one.
  3. Write the rules down. A short policy that says what may go into an AI tool, what may not, and who reviews output before it reaches a client. Writing an AI policy sets out what that document should cover.
  4. Fix the job itself. This is the step most firms skip, and it is the one that removes the pressure.

Why is fixing the process the step that matters?

A policy and an approved licence make the use safer. They do not make the work faster in any lasting way. A fee earner with a sanctioned assistant is still copying information between documents, still rewriting the same sections every time and still formatting the result by hand. They have simply swapped one chat window for another.

The reason staff reached for a consumer tool in the first place was a specific job that took too long: a report, a bid, a set of notes, a compliance pack. If that job is rebuilt so that it draws on the firm's own documents and templates, runs inside the tools the team already uses and routes every client-facing output to a named reviewer, the reason for the workaround goes away. There is nothing left to do in a personal account.

That is the difference between governing AI use and designing it in. Governance is necessary. Design is what actually changes behaviour. We make the broader point in a tool is not a process, and what Copilot is actually good for looks at where licensed tools help and where they stop.

Where should a partner start this week?

Do not start with a memo forbidding anything. Start with a question to the team about what they are using and why. Then look at the answers and pick the task that comes up most often. That task is where the hours are going and where the risk is concentrated. The audit helps put a figure on it and names the single process to tackle first.