Shadow AI is staff using unapproved AI tools on company data. It is now the most common ungoverned risk inside Texas small businesses, and 43% of breached organizations reported a shadow AI incident in IBM’s 2026 breach study.
The short version. Your people are already using AI. Most of them are doing it from personal accounts you cannot see, on a plan tier that treats their prompts as training data by default. Blocking the domain moves the behavior to a phone. What works is a written rule about data, a discovery pass on your own tenant, and a sanctioned tool that is easier to use than the shadow one. Start with AI enablement, not with a ban.
There’s a version of this conversation we have almost every month. A Houston controller asks whether Copilot is worth $30 a seat. Twenty minutes later, somebody else in the room mentions that the estimating team has been using ChatGPT since spring. Nobody approved it. Nobody logged it. Nobody knows what went into it.
That gap is the whole subject of this post. Not whether AI is a good idea, and not which license to buy. Just the plainer question of what is already leaving your building, who is legally on the hook when it does, and what you can do about it in the next 30 days without starting a fight with your best people. That’s the whole question.
What Is Shadow AI, and How Is It Different From Shadow IT?
Shadow AI is any use of an artificial intelligence tool on company work without the company’s knowledge or approval. It covers personal ChatGPT accounts, browser extensions, meeting note-takers, and AI features quietly switched on inside software you already pay for. Shadow IT was mostly about unapproved apps. Shadow AI is about unapproved data movement.
The distinction matters more than it sounds. When an employee signed up for a rogue file-sharing account a decade ago, the risk was a copy of your data sitting somewhere you did not control. We wrote about that pattern years ago in shadow IT and the risk lurking on your company’s devices, and the shape of it was containable. You found the account. You migrated the files. You closed it.
AI does not work that way. A prompt is not a file. It is a copy of whatever your employee thought was relevant, stripped of its context and its access controls, pasted into a system that may use it to improve a model. You cannot migrate a prompt back. There’s no folder to close. It’s already out.

What Are Texas Employees Actually Pasting Into ChatGPT?
Start with the measurements. Cyberhaven Labs, which instruments real data movement rather than surveying people, found in its 2026 AI Adoption and Risk Report that 39.7% of all data movements into AI tools involve sensitive data, and that 32.3% of ChatGPT usage runs through personal accounts.
Netskope reached the same place from a different direction. Its Cloud and Threat Report 2026, published in January, found that nearly half of people using generative AI at work, 47%, are doing it through personal accounts rather than an account the business can see, log or revoke. Prompt volume grew sixfold in a year, from 3,000 to 18,000 per month at the average organization. The most common policy violation was source code, followed by regulated data, intellectual property, and credentials. In that order.
And this skews small. Microsoft and LinkedIn’s 2024 Work Trend Index, built on 31,000 knowledge workers across 31 markets, found 78% of AI users bring their own tools to work. At small and mid-sized companies the figure was 80%. Fewer approvals. Fewer controls. More improvisation.
Here is what that looks like in an actual Texas business, by department. None of these are hypothetical categories. They’re the ones that show up when we run a discovery pass. Every single time.
| Who | What tends to get pasted | What it can trip |
|---|---|---|
| Estimating and preconstruction | Bid packages, subcontractor pricing, scope letters | Confidentiality clauses in the prime contract |
| Accounting and AP | Vendor invoices, bank letters, payroll registers | Employee data, banking detail, wire fraud exposure |
| HR | Resumes, disciplinary notes, benefits questions | Sensitive personal data under Texas privacy law |
| Clinical and practice admin | Patient summaries, denial letters, coding questions | HIPAA, with no signed business associate agreement |
| Engineering and energy services | Drawings, well data, specifications, technical reports | Export control and customer confidentiality |
| Sales and marketing | Client lists, pricing models, proposal language | Trade secret status and NDA terms |
| Anybody in a meeting | The entire transcript, via a note-taker bot nobody vetted | All of the above at once |
The meeting bot is the one people underrate. Samsung learned it the hard way in 2023, when engineers pasted internal source code into ChatGPT and, in a separate incident, fed a recording of a confidential internal meeting into it to generate notes. Twenty days, three incidents. Samsung banned generative AI on company devices shortly after.
Why Deleting the Chat Does Not Delete the Risk
Most employees believe the conversation disappears when they clear it. That belief is doing a lot of load-bearing work, and it is wrong in two separate ways. Both of them matter.
The first is training. On consumer ChatGPT plans, including Free and Plus, data sharing for model improvement is on by default and has to be switched off manually under Data Controls in each individual user’s own settings, which is a per-person action nobody at your company can see or verify centrally. Business, Enterprise, Edu and the API do not train on customer content by default. That single distinction is most of the difference between governed and ungoverned use, and it is invisible from the outside. The window looks identical either way.
The second is retention. In May 2025 a federal court ordered OpenAI to preserve output logs that would otherwise have been deleted, including conversations users had already removed, as part of the New York Times copyright litigation. OpenAI publicly objected and appealed. Judge Ona Wang lifted the broad preservation obligation in an order filed October 9, 2025. But logs captured while the order was live still exist, and accounts specifically flagged in the case are still covered.
Read that again with your own business in it. A chat your bookkeeper deleted in June 2025 may sit in a litigation preservation set today. She used the free tier. No malice. No warning.
| Plan tier | Trained on by default | Admin visibility | HIPAA BAA available |
|---|---|---|---|
| ChatGPT Free and Plus, personal account | Yes, unless the user opts out | None | No |
| ChatGPT Business | No | Workspace admin controls and logs | No |
| ChatGPT Enterprise | No | Full admin, SSO, retention controls | Not on standard ChatGPT tiers |
| OpenAI API with zero data retention | No | Whatever your integration logs | Yes, by agreement |
| Microsoft 365 Copilot | No | Purview, audit log, sensitivity labels | Covered under the Microsoft agreement |
That last row is why the fix is usually a license rather than a lecture. If your staff already live in Microsoft 365, a governed tool sits one decision away. We priced the whole thing honestly in what Microsoft 365 Copilot actually costs a Texas SMB, including the readiness work most quotes leave out.

What a Shadow AI Incident Actually Costs
IBM’s 2026 Cost of a Data Breach report studied 602 breached organizations between March 2025 and February 2026. The global average breach came in at $4.99 million. Breaches that were AI-enabled, now one in four of all malicious breaches, ran roughly $6 million, and IBM measured that as a 56% year-over-year increase.
The shadow AI slice is the part worth pinning to your wall. The share of incidents involving shadow AI more than doubled in a year, to 43%. More than two-thirds of organizations said they had no governance process to limit it. Of the organizations breached through an AI model or application, 92% had failed to control access to those tools properly. Pin that one up.
Those are enterprise dollar figures and a 40-person company in Katy is not losing $5 million. Fair. But the ratio underneath is what transfers. Almost half of these incidents came through tools nobody had approved, at organizations that had never written down a rule, and the control that was missing was access, not detection. Every one of those three things is cheaper to fix at 40 employees than at 4,000, which is the only genuinely good news anywhere in the report. That part transfers.
Which Rules a Texas Business Trips the Moment a Prompt Leaves the Building
Texas got its own AI statute on January 1, 2026. The Texas Responsible Artificial Intelligence Governance Act, passed as HB 149, is narrower than the version originally filed. The version of the act that became law on January 1, 2026 dropped the employer disclosure and bias-audit requirements that appeared in earlier drafts, leaving a much narrower statute than the one Texas employers spent most of 2025 preparing for. What it does prohibit is developing or deploying an AI system with intent to discriminate. Enforcement sits with the Attorney General alone, and there’s no private right of action. We broke the statute down in detail in what TRAIGA requires of Texas SMBs.
TRAIGA is rarely the binding constraint for a small business, though. Three other things usually are.
The Texas Data Privacy and Security Act exempts small businesses as defined by the SBA, but the exemption has a hole in it. A small business must still obtain consent before selling a consumer’s sensitive data, and the Attorney General enforces it exclusively, with a 30-day cure period and penalties up to $7,500 per violation. This office has been the most aggressive privacy enforcer in the country. Assuming the exemption covers everything is not a strategy.
HIPAA is stricter and much simpler. OpenAI does not sign a business associate agreement for the Free, Plus, Team or Enterprise versions of ChatGPT, which means protected health information cannot lawfully go into them, no matter how careful the person was about trimming the obvious identifiers first. A BAA is available for the API with zero data retention configured, and through OpenAI’s healthcare offering. Your internal policy does not change this. The violation is the missing agreement, not the intent.
Then there’s contract law. It catches almost everybody. Read a prime contract, an NDA, a customer security questionnaire or a cyber insurance application from the last two years and you will usually find language about third-party disclosure and approved subprocessors. A personal ChatGPT account is an unapproved subprocessor. Nobody signed off on it. Nobody disclosed it.
If any of that applies to you, the governance program is the deliverable, not the policy PDF. We build that as a documented, dated program in AI governance and compliance for Texas businesses, because evidence that controls existed before an incident is worth considerably more than evidence assembled after one.
How to Find Shadow AI in Your Environment in a Week
You cannot govern what you have not found. The good news is that most of the discovery work uses tooling you already pay for, and a competent admin can run the whole sequence in a few afternoons without buying anything new. It’s cheap work. Do these in order.
- Pull the Microsoft 365 or Google Workspace sign-in and audit logs for the last 90 days and filter for AI domains. You are looking for OAuth grants, not just web traffic.
- Review third-party app consents in Microsoft Entra ID. Meeting bots, resume screeners and writing assistants almost always request calendar or mailbox permission, and somebody clicked accept.
- Inventory browser extensions on managed devices. This is where the quiet ones hide.
- Search the last two quarters of expense reports and corporate card statements for AI vendors. A $20 monthly charge coded to software is a personal account with company data in it.
- Check your meeting platform for external bots that have joined recordings, then check who invited them.
- Ask. Run a short amnesty survey and promise nobody gets in trouble, because the fastest inventory in the room is the honest one.
Step 6 outperforms the first 5 more often than any of us would like to admit. People will tell you what they use if the question is not a trap.
If you would rather not build this from scratch, shadow AI discovery is a workstream inside our AI readiness assessment, alongside a 6-area audit of the tenant itself covering SharePoint and OneDrive permissions, sensitivity labels, external and guest access, DLP policy, Teams sprawl and Secure Score. The oversharing side of that audit deserves its own read, and we covered it in the files Copilot surfaces that you forgot you shared.

The One-Page Policy That Actually Stops the Paste
Long AI policies do not get read. The ones that change behavior fit on a single page and answer one question, which is what data may go where. Everything else is commentary. Keep it to one page.
We build it as 3 tiers. Staff can hold 3 tiers in their head. They cannot hold 14 rules and a decision tree.
| Tier | What it covers | The rule |
|---|---|---|
| Tier 1, open | Published marketing copy, public specs, general research questions, anything already on your website | Any approved tool, no review needed |
| Tier 2, internal | Draft proposals, internal process documents, non-identifying operational data | Sanctioned tool only, human reviews the output before it leaves |
| Tier 3, restricted | Client data, PHI, employee records, financials, credentials, source code, anything under NDA or export control | Never in a general AI tool, no exceptions, ask before you improvise |
Add 4 lines under the table and you’re done. Name the sanctioned tool. Name the person to ask. Say what happens when someone gets it wrong, and make it small, because a policy with a firing offense attached to it produces silence rather than compliance. Then require an acknowledgment so you have a dated record.
Our Texas AI acceptable use policy template is the long-form version of this, with the TRAIGA checklist attached. Take it, cut it down, put your own tool names in it.

Why Blocking ChatGPT Usually Backfires
Here’s a position we’ve changed. A few years ago the standard advice, ours included, was to block the domains at the firewall and move on. It felt decisive. It was mostly theater. We were wrong.
Blocking a domain on a managed laptop does not stop anything. It moves the same paste to a personal phone, where you have no logging, no DLP and no chance of ever knowing. Netskope’s finding that 47% of workplace AI use already runs through personal accounts is a description of exactly this behavior, and those users are on the tools because the tools work. Removing the tool without replacing it removes the visibility, not the risk.
The pattern that holds is different. Give people something sanctioned that’s genuinely as good, make the rule about data rather than about tools, and keep the consequence for asking a question lower than the consequence for guessing. Adoption of the governed option is the actual control. Everything else is a speed bump.
There’s one exception worth naming. If you handle CUI, ITAR-controlled technical data or PHI, block hard and block now, then stand up the compliant alternative in the same week. Some categories do not get a transition period.
What to Do in the First 30 Days
Sequence matters more than speed. Companies that go badly wrong usually did the right things in the wrong order, buying licenses before they knew what the tool could already read, and then discovering the permissions problem in a live rollout instead of in an audit. Here’s the order that works.
| What you’re seeing | The move | Who owns it |
|---|---|---|
| No idea what anyone is using | Run the 6-step discovery pass above, plus the amnesty survey | IT, 1 week |
| Discovery found regulated data in a personal account | Preserve evidence, assess notification duty with counsel, then remediate | Leadership and counsel, immediately |
| Widespread use, nothing written down | Publish the 3-tier policy and collect acknowledgments | Leadership, 2 weeks |
| Policy exists, no sanctioned tool | License a governed option and pilot 1 department | IT and the department lead, 30 days |
| Microsoft 365 tenant never audited | Permissions and label remediation before any AI license lands | IT or your MSP, 2 to 3 weeks |
| Regulated, contractual or export-controlled data | Hard block, compliant alternative, documented governance program | Leadership, counsel and IT, same week |
Notice what’s not on that list. Nobody needs an AI strategy in month 1. You need to know what’s happening, write down one rule, and give people a legal way to keep doing the thing they were already going to do anyway.
Shadow AI Questions Texas Leaders Keep Asking
How do I know if my employees are using AI without telling me?
Check 3 places first. OAuth app consents in Microsoft Entra ID, browser extensions on managed devices, and 2 quarters of expense reports for AI subscriptions. Those 3 sources find most of it in a day. Then run an amnesty survey, which usually finds the rest. Web filtering logs help but miss anything done on a personal phone, which is where the highest-risk usage tends to live.
Is it actually illegal for my staff to paste client data into ChatGPT?
It depends entirely on the data. For protected health information, yes, because OpenAI does not sign a business associate agreement for consumer or standard Enterprise ChatGPT. For client data under an NDA or a prime contract, it is usually a breach of contract rather than a statute. For ordinary business data, it is a governance failure with no specific law attached, which does not make it safe.
Does TRAIGA require me to tell employees when we use AI?
No. The version of the Texas Responsible Artificial Intelligence Governance Act that became law on January 1, 2026 dropped the employer disclosure and bias-audit requirements that appeared in earlier drafts. It prohibits deploying AI with intent to discriminate, and only the Attorney General can enforce it. Government agencies face disclosure duties that private employers do not.
If I turn off the training toggle in ChatGPT, is the risk gone?
No, though it helps. Opting out of model training stops future conversations feeding the model, but it does not give you admin visibility, retention control, audit logs, a data processing agreement or any contractual protection. It also relies on every employee doing it individually and correctly. A business-tier workspace handles all of that centrally and by default.
We already pay for Microsoft 365. Do we still need a separate AI tool?
Usually not. Copilot runs inside your existing tenant with Purview, audit logging and sensitivity labels already attached, which solves the governance problem a personal ChatGPT account creates. The catch is permissions. Copilot inherits whatever oversharing already exists in SharePoint and OneDrive, so the tenant audit has to come first.
What should I do if I find out someone already pasted sensitive client data?
Preserve the evidence before anyone deletes anything, then get counsel involved to assess whether a notification duty was triggered. Document what data, which account, and when. Delete the conversation and the account afterward, not first. Punishing the employee publicly guarantees the next person hides it, so keep the response proportionate and fix the missing control.
How much does it cost to get shadow AI under control at a 50-person company?
Less than most people expect, because the first 3 steps cost nothing but time. Discovery uses tooling you already own. The policy is a page. The real spend starts at permissions remediation and licensing, and it scales with how much oversharing your tenant has been accumulating, which is the line that varies most between businesses of the same size.
Where to Start
Shadow AI is not a discipline problem. It’s a supply problem. Your team found tools that made their work faster and used them, because that’s what capable people do when leadership hasn’t decided anything yet. The risk isn’t the ambition. Silence is the risk.
Uprite runs shadow AI discovery as part of a broader readiness assessment from offices in Houston, Dallas and San Antonio, and everything we sell carries a 120-day satisfaction guarantee that applies to this engagement exactly the way it applies to everything else we do. If you want to know what your people are already doing, and what your tenant would hand an AI tool on day 1, that’s where to start.
Get an assessment and find out before somebody else does.









