Your Team Is Already Using AI. Do You Know Where?

shadow AI Denver

A typical Denver business with 100 employees might count three or four AI tools in its tech stack. The real number tends to be closer to fifteen, once you include the free ChatGPT accounts, the Gemini features quietly turned on inside Google Workspace, the Copilot suggestions surfacing in Microsoft 365, and the AI summary buttons that appeared overnight in tools like Slack, Zoom, Notion, and HubSpot. Most of those weren’t approved. Some were never even noticed.

This discrepancy is what people mean when they talk about shadow AI. Not deliberate misuse. Not employees going rogue. It’s the gap between what leadership thinks is happening and what is happening, every day, on every laptop in the building.

The headcount problem

In a five-person business, leaders tend to know what tools their team uses. They sit close enough to see it. At 40 employees, that visibility starts to blur. At 200, it’s gone. Shadow AI follows the same curve. The bigger the team, the wider the surface area for unmanaged AI use, and the harder it gets to track who is pasting what into which interface.

The numbers back these findings up. IBM’s 2025 Cost of a Data Breach Report found that one in five breaches studied was linked to shadow AI (unsanctioned tools adopted by employees without IT oversight). Those breaches added an average of $670,000 to the total cost, and disproportionately exposed customer personally identifiable information. A separate WalkMe survey of US workers put the prevalence figure higher, as 78% of employees report using AI tools their employer didn’t provide.

If you run a 100-person company and assume most of your team isn’t using AI yet, the survey data says you’re almost certainly wrong.

Where it lives

Shadow AI doesn’t only mean someone opening a free ChatGPT tab. The bigger blind spot for established businesses is that vendors are putting AI into the tools you already pay for. Microsoft has added Copilot. Google has added Gemini. Salesforce has added Einstein. Adobe, Zoom, Slack, Notion, Atlassian, HubSpot. Every major platform in a modern business stack has been quietly absorbing AI features for two years.

That’s where the real exposure hides. Industry data from Zylo’s 2026 SaaS Management Index shows that 77% of IT leaders have discovered AI-powered features running inside their existing applications without their awareness. And 60% admit they don’t have full visibility into where AI is now operating in their environment.

This matters because the security perimeter has quietly moved. A staff member doesn’t need to download a new tool to send sensitive data through an AI model. They just need to ask Copilot to summarize a customer email or use a meeting transcription feature that ships the audio off to a third-party service for processing. The action feels routine. The data path is anything but.

Why training and policy lag behind

Most growing businesses have responded to AI by writing a policy, sending an all-hands email, and moving on. The WalkMe research found that only 7.5% of employees have received extensive AI training, while 23% have received none at all. Around half of employees say the guidance they have received is contradictory.

Employees know they’re supposed to be careful with AI, but they don’t know what that means in practice. They use the tools anyway because the work has to get done, and the AI helps. So they do their best, they don’t ask, and the company never finds out which model now has a copy of last quarter’s customer list.

The deeper issue is that banning AI was never going to hold, and approving AI requires a kind of operational maturity most growing businesses haven’t reached yet. There’s no procurement process for a feature that arrives via an automatic update, nor an offboarding step for a free account a former employee signed up for using their personal email.

What this looks like in practice

In our client work, we typically find three or four AI surfaces a business didn’t know it had:

  • AI features inside Microsoft 365 or Google Workspace that were turned on at the tenant level by an admin three months ago and never communicated to staff
  • Free-tier accounts on consumer AI products that staff use for quick edits, summaries, or draft writing
  • AI features inside industry-specific tools (the CRM, the marketing platform, the HR system) governed by terms of service no one has read since the AI module launched

This is the predictable outcome of how AI has been rolled out to the world over the last two years: fast, embedded, and on by default. The companies that handle this well usually share one quality. They have a clear, up-to-date picture of what’s running across their tech stack.

Start with what you can see

You can’t do anything sensible about AI you can’t see. So start with the dull job first and find out what’s being used and what data it’s touching.

That’s the conversation we’re hosting this August in Downtown Denver: a lunch and learn for established business leaders who want a clearer view of their AI footprint before deciding what to do about it. Marc Evans, our CEO, will walk through what we’re seeing inside client environments and what’s worth doing differently. Details and registration are at redbigfoot.com/is-your-business-ready-for-ai.

Marc redbigfoot

Marc Evans

Founder of Red Bigfoot, a leading MSP dedicated to delivering scalable, simplified IT solutions that drive business growth.

Denver-moutainside

Receive the latest news

Subscribe To Our Quarterly Newsletter!