Insights · Governance

How to reduce shadow AI without slowing the business down.

6 min read · PoseidongrooveAI Insights

By the time most leadership teams start discussing AI policy formally, their staff have already been using it informally for months. That gap - between bottom-up adoption and top-down governance - is what the UK government's Professional and Business Services AI Adoption Plan describes as one of the sector's persistent barriers, alongside limited in-house expertise and concerns over safety and transparency.

Source · GOV.UK, AI Adoption Plan: Professional and Business Services · 2025

The instinct to ban is usually the wrong one

Blocking tools outright rarely removes the behaviour - it just removes leadership's visibility into it. Staff who have found a tool that saves them two hours on a first draft will not simply stop, especially under delivery pressure. They will find a way around the policy instead of a way to follow it.

The more useful leadership question is not "how do we stop this," but "how do we make it safe to keep happening."

What governance before crisis looks like

  • A short, plain-English acceptable-use standard - what can go into a tool, and what never can
  • A named owner for AI usage decisions, distinct from IT and distinct from "everyone"
  • A simple channel for staff to surface a tool they're already using, without fear of penalty for having started
  • A review point - quarterly is usually enough - where usage, incidents and new requests are looked at together

None of this requires a large governance programme. It requires leadership to treat the existing usage as a starting fact, not an embarrassment to correct retroactively.

Why this is a leadership issue, not an IT issue

In owner-managed professional and compliance firms, the real risk sits with confidentiality, audit trail and client trust - commercial and reputational concerns that sit above the technical layer. Framing shadow AI purely as a systems problem hands it to the wrong owner and slows the one thing that actually reduces risk: clear, leadership-endorsed standards that staff can follow without having to guess.

Once teams are already using AI informally, the leadership question is no longer about permission. It is about control, standards, and knowing which use case to prioritise next.

Recognise this in your firm?

Talk through what this means for your firm.

Talk through what this means for your firm