Category: AI Security

  • Shadow AI Has Three Heads: What Small Businesses Should Do

    OWNER BRIEF / SHADOW AI

    Employee chatbots, third-party agents, and stealth coding.

    The 30-second takeaway

    Does this affect my business? Yes, if employees use AI for work, vendors add AI agents to your software, or AI-built scripts and apps touch company data.

    What should I do? Inventory all three paths, approve exact tools and account types, limit access, require review, and name an owner.

    How urgent is it? Start the inventory this week. If sensitive information or credentials have already been exposed, begin containment immediately.

    OWNER BRIEF / SHADOW AI

    Small businesses will not build most of the AI that changes their work. Employees and software vendors will bring it in — unless the owner controls all three doors.

    No hacker ever touched Community Bank of Pennsylvania. If you own a small business, that is the detail I want you to sit with.

    In May 2026, one of the bank's employees processed non-public customer information — names, Social Security numbers, and dates of birth — through an AI application the company had never approved. No ransomware. No outage. No evidence that the data had been misused. The bank's publicly traded parent, CB Financial Services, did not publicly identify the AI application.

    Days later, CB Financial filed an 8-K with the SEC — the first publicly disclosed shadow AI incident on record. Nobody had broken in. An employee had fed customer records into a tool the company could not see.

    Why would a small community bank tell the world? In practical terms, it had little choice. On May 7, CB Financial decided the incident was material because of “the volume and sensitive nature” of the customer information. For a public company, that decision triggered Item 1.05 of Form 8-K and a four-business-day disclosure clock. Banking and breach-notification rules separately required communication with regulators and affected customers. CB Financial filed with the U.S. Securities and Exchange Commission on May 11. The filing was not an admission that AI had caused financial damage — the company said it expected none. It was a compliance decision: once sensitive customer data had left the bank’s control at sufficient scale, keeping the incident private was no longer a safe option.[13]

    You will probably never file an 8-K. That does not make this a bank-only story. Picture the same click in a 20-person company: a bookkeeper pastes payroll into a chatbot, a salesperson uploads a customer list, or an office manager asks an AI tool to summarize tax forms. The owner now has the same first questions as the bank: What left our control? Who could see it? Can we get it back? Whom do we have to tell?

    All 50 states have breach-notification laws that apply to private businesses, although the definitions, triggers, and required notices vary. Client contracts and cyber-insurance policies may create additional reporting duties. CB Financial’s public-company status determined where the incident was disclosed; it did not create the underlying risk. A small-business owner can face the same data event with no security team, no in-house lawyer, and no reliable record of what the employee entered.[17]

    That is the trap: shadow AI does not break down the door. It is invited in. An employee opens a chatbot. A software vendor turns on an agent inside a product you already buy. Someone uses AI to build a quick internal app, then that “quick” tool starts touching live data. Each move looks useful and reasonable — until you have to explain who had access, what the AI did, and where the data went.

    The next three years will not mainly be about stopping careless employees. They will be about controlling implementation. Small businesses are unlikely to build their own agent platforms; they will inherit AI through vendor features, personal accounts, browser extensions, and code created outside a normal development process. If you do not decide which data, permissions, actions, and AI-built tools are acceptable, convenience and vendor defaults will decide for you.

    Shadow AI in the workday
    Finding Population / source
    48% reported using unapproved AI tools at work TrustedTech/Censuswide, 2026
    65% of senior decision-makers reported shadow-AI use TrustedTech/Censuswide, 2026
    41% reported lacking clear AI data guidance TrustedTech/Censuswide, 2026
    47% of workplace AI users used personal accounts Separate Netskope enterprise research, as reported

    The TrustedTech survey covered 2,001 U.S. and U.K. employees. The Netskope finding comes from a separate enterprise dataset; these percentages should not be combined. [2] [3]

    How widespread is shadow AI?

    • Unapproved use is already normal. In the TrustedTech/Censuswide survey, 48% of employees said they used unapproved AI tools at work.[2]
    • Leaders were more likely to do it. Sixty-five percent of senior decision-makers reported shadow-AI use, compared with 31% of employees below decision-maker level. The original report says 65%, not the 67% repeated in some coverage.
    • Many workplaces have not drawn the boundary. Forty-one percent said their organization lacked clear guidance about what information could be entered into AI tools. Only 23% learned to use AI through employer training; 54% learned by trial and error.
    • Personal accounts remain part of the problem. Netskope’s 2026 enterprise research was reported as finding that 47% of employees who used AI at work did so through personal, unmanaged accounts.[3]
    • Shadow AI incidents are getting more expensive. In IBM's 2026 Cost of a Data Breach Report, security incidents involving unapproved AI more than doubled to 43%, up from 20% the prior year, and averaged $5.39 million in breach costs, up from $4.63 million. About one in five of those incidents drew a regulatory fine.[14]

    The available research is weighted heavily toward large organizations. I did not find a publicly documented shadow-AI leak that names a small business, and I will not pretend the enterprise numbers are a small-business survey. What they show is the behavior produced by the same tools your staff can open in two minutes. A 20-person firm may have fewer users, but it also usually has fewer controls and less ability to investigate where information went.

    Shadow AI is becoming a three-headed monster

    Shadow AI is any artificial-intelligence use the business has not approved, configured, or made visible. The first wave was easy to picture: an employee pasted work into a public chatbot. The next wave is broader. Agents arrive inside third-party software, while AI coding tools let people create working software without a normal development process.

    Most small businesses will not build an agent platform from scratch. They will inherit AI through products they already buy and through tools their staff adopt. That shifts the owner’s question from “Who is using ChatGPT?” to “Which AI can see our data, take actions in our systems, or create software we now depend on?”

    Three ways AI enters the business
    AI entry point Exposure Owner control
    Employee chatbots Prompts and uploads Control inputs and accounts
    Third-party agents Access and actions Control permissions and logs
    Stealth coding Ownership and upkeep Require review and inventory

    Head one: employee chatbots move data across the boundary

    This is the familiar head. An employee uses a personal chatbot, meeting assistant, browser extension, image generator, transcription service, or coding assistant because it produces a useful answer quickly. The risk begins when customer, employee, financial, legal, or technical information crosses into an account the business does not manage.

    A personal paid account is still a personal account. A familiar product name does not tell you which contract applies, whether workspace data is used for training, how long it is retained, whether shared links exist, or who can administer the account when an employee leaves.

    Control the input: Name the approved product and the approved account type. “ChatGPT is allowed” is not a policy. “ChatGPT Business through our company workspace is allowed for the uses listed below” is a policy.

    Head two: third-party agents turn access into action

    A chatbot waits for a person to paste something. An agent may read email, search files, update customer records, send messages, schedule work, or trigger another system. For a small business, that capability is more likely to arrive as a feature inside accounting, customer-relationship, support, productivity, or security software than as an agent the company builds itself.

    Agents in business software
    Period Gartner enterprise-application forecast
    2025 Less than 5% include task-specific agents
    End of 2026 Up to 40% include task-specific agents
    By 2028 Agent ecosystems begin working across applications

    This is an enterprise forecast, not a measured small-business adoption rate. [15]

    The control problem is no longer only what someone pastes. It is what the agent can reach and what it can do without a second approval.

    Control the access: Before enabling an agent, document its data sources, permissions, actions, logs, human-approval points, and off switch. Treat a vendor’s new AI feature as a new access decision, not a harmless software update.

    Head three: stealth coding creates software nobody owns

    AI coding tools let developers and non-developers create scripts, automations, dashboards, and internal apps quickly. The danger is not that every AI-built tool is bad. It is that a useful prototype can become a production dependency before anyone reviews its data access, authentication, logging, backup, error handling, or maintenance owner.

    Retool-sponsored survey of 307 technology and security leaders
    Finding Reported response
    Concern 93% were worried about AI-coded tools running in production
    Priority 38% called it one of their biggest operational risks
    Visibility 95% could not say they knew every AI-coded tool in production

    Enterprise leadership sample; vendor-sponsored research, not a small-business prevalence study. [16]

    This vendor-sponsored enterprise survey is not a small-business prevalence study, but its warning is blunt: AI-built software can reach production before a business even knows it exists—let alone reviews it or assigns an owner.[16]

    Control the code: Require registration and review before an AI-built script, workflow, or app touches live company data. Record who owns it, where it runs, which credentials it uses, how changes are tested, and how it will be retired.

    Employee chatbot incidents show what happens when data leaves your control

    Prompt-based chatbot use arrived first and is easiest to observe. Its documented incidents reveal the many forms an exposure can take; agents and AI-built tools add permissions, actions, and software dependencies to the same loss of visibility.

    Examples of information leaving the owner’s control
    Example from the source document Exposure Safer practice
    CISA official [4] At least four sensitive, unclassified government documents uploaded to public ChatGPT Approved tools and a never-paste list
    Shared chats, 2025 [5] About 4,500 conversations indexed after users enabled discoverability Avoid public work-chat links and review existing links
    Heppner case, 2026 [6] Consumer-Claude documents found not privileged under the account terms and case facts Keep legal strategy and client confidences out
    Samsung, 2023 [1] Proprietary code, equipment-test code and a meeting recording entered into ChatGPT Provide an approved route before convenience wins

    Owner-facing forums confirm the pattern—not a breach count

    Public forums are anecdotal and self-selected. They cannot prove that a specific organization suffered a leak, and anonymous posters cannot be independently verified. Their value is narrower: they show what owners and managed-service providers are actually finding.

    Practitioner discussions
    Forum discussion Reported pattern Owner lesson
    r/msp, December 2025 [7] An IT-provider audit reportedly found six different AI note-takers, extensions and an unknown operations tool Inventory extensions, accounts and retention settings
    r/ChatGPT, January 2024 [8] An employee asked whether a personal paid account was safer for work data A paid consumer account is not a company-managed workspace
    r/sysadmin, 2023 [9] Office network blocks did not address home devices and phones Use controls and training alongside filtering

    Anecdotal, self-selected forum posts; these are not verified breach counts.

    Those posts do not establish loss. They reinforce the same operating pattern the survey data shows: people use what helps, personal accounts blur the boundary, and network blocks do not create governance. The note-taker, extension, and quick automation are also the bridge from the first head to the other two: a tool begins as an assistant, gains access, and quietly becomes part of the workflow.

    PART TWO

    Take back control: empower with policy—not a ban

    You've seen how control is lost. What follows is how to take it back.

    A ban feels decisive. It is also easy to evade with a personal phone, home computer, browser extension, or consumer account. TrustedTech found that 29% of workers would continue using AI even if a ban put them at risk of discipline; among decision-makers, the figure was 37%.[2]

    Even a perfectly enforced chatbot ban would not govern an agent activated inside approved software or an AI-built app running on company data. The control has to match all three ways AI enters the work. If a useful tool saves an hour and the approved alternative is “do not,” someone will eventually create a workaround.

    Start with a two-week amnesty inventory. Tell employees: “List the AI tools and accounts you use for work, and tell us what kinds of information have gone into them. During this inventory, disclosure will not be punished.” The purpose is to find the real environment before writing a rule for an imaginary one.

    Ask about all three heads:

    • Employee chatbots: personal accounts, meeting assistants, transcription services, browser extensions, and company information already entered.
    • Third-party agents: AI features inside accounting, customer-relationship, design, hiring, support, productivity, and security tools — especially features with permission to read, write, send, or approve.
    • Stealth coding: scripts, automations, dashboards, integrations, and internal apps created or substantially modified with AI, including where they run and who owns them.

    Do not ask only, “Who uses ChatGPT?” That misses the agent attached to an approved subscription and the quick app that became a business process.

    AMNESTY LANGUAGE

    Tell us now so we can make the safe path work. For the next two weeks, report every AI chatbot, agent, coding tool, automation, or AI-built app used for company work. Include the account type, data or systems involved, actions it can take, and who owns it. This is an inventory, not a disciplinary exercise. After the inventory closes, the approved-tool, access, and review rules take effect.

    One page governs all three heads

    A 20-person company does not need a 40-page AI standard. It needs a rule an employee can use before opening a chatbot, enabling an agent, or putting an AI-built tool into service.

    The one-page AI rule
    Question Requirement
    Which path? Approve the chatbot, agent or AI-built app
    What access? Limit data, systems, permissions and actions
    Who reviews? Check high-stakes output, actions and code
    Who owns it? Name a person accountable for access, logs and upkeep

    1. Which tool, account, agent, or app may I use?

    Name the exact product, account type, approved use, and owner. A company-managed business workspace gives the owner contractual terms and administrative control that a personal account does not. An embedded agent also needs an approved permission scope, and an AI-built app needs a named maintainer. OpenAI says it does not train on ChatGPT Business workspace data by default; its published price was $25 per user monthly or $20 per user monthly with annual billing when this article was prepared.[10]

    Do not assume every business product has identical terms. Read the current data-use, retention, administrator, permission, and logging settings before approval.

    2. What must never go in — or be granted?

    The short list should include:

    • Customer personal information, payment details, or authentication data.
    • Passwords, recovery codes, private keys, or application programming interface keys.
    • Employee records, payroll, health information, or performance details.
    • Material covered by a client contract or nondisclosure agreement.
    • Unpublished financials, legal strategy, source code, trade secrets, or acquisition plans.

    If a task requires real data, use a sanitized version with names, identifiers, secrets, and unique business details removed. “Anonymized” should mean the information cannot be tied back to a person or client — not simply that the name was deleted. Apply the same logic to access: an agent should not receive an entire mailbox, drive, or customer database when one folder, queue, or read-only view will do.

    3. Who checks the output, action, and code?

    Require human review before AI output reaches a customer or affects money, contracts, legal advice, health, hiring, discipline, production code, or security settings. Require approval before an agent sends, changes, deletes, or purchases. Require testing and code review before an AI-built tool touches live data. Input exposure, confident errors, unauthorized actions, and weak software are separate risks; the policy should address each one.

    4. Who owns it?

    Name one accountable person for every approved chatbot workspace, agent, and AI-built tool. An employee facing an unusual task needs a fast yes, no, or safer alternative. A workflow also needs someone responsible for permissions, logs, failures, updates, and retirement. A policy without ownership becomes wallpaper.

    A free, adaptable AI-use-policy template is available from Safe AI Australia under an MIT license. It is more detailed than many small firms need, but its approved, conditional, and prohibited-use structure is a useful starting point.[11]

    A 45-minute owner plan is enough to start

    The first version does not need to be perfect. It needs to make responsibility visible.

    1. Minutes 0–10: announce the three-part inventory. Set the two-week amnesty window. Ask for chatbots and personal accounts, agent features and connected systems, and AI-built scripts, automations, or apps.
    2. Minutes 10–20: publish the never-paste and never-grant list. Include client data, employee records, credentials, payment information, legal material, source code, and trade secrets. Add broad mailbox, file-drive, customer-database, payment, and administrator access unless specifically approved.
    3. Minutes 20–30: choose approved paths. Use a company-managed chatbot workspace where the vendor’s terms and settings match your needs. Require a documented permission and approval model for agents. Require registration and review before AI-built tools touch live systems.
    4. Minutes 30–40: remove the easiest shadow routes. Review browser extensions, meeting assistants, connected applications, OAuth grants, automation platforms, and scripts running under employee accounts. Use filtering as a backstop, not as the whole program; it cannot govern every vendor feature or home-built workflow.
    5. Minutes 40–45: teach one ten-minute lesson. Show one safe and unsafe example for each head, where to ask, and how to report a mistake quickly. Repeat it for new employees.

    COPY INTO YOUR POLICY

    Use approved AI only. Protect the input. Limit the access. Review the action and the code. Company work may be performed only through approved accounts, agents, and AI-built tools. Never enter restricted information or grant broad system access without approval. A person must review high-stakes output and approve consequential actions. AI-built software must be registered, tested, and assigned an owner before it touches live data. Report mistakes immediately; early reporting will be treated as help, not concealment.

    Prepare for an Incident

    Do not begin by demanding a perfect explanation. Begin by containing what you can and learning exactly what happened. The event may be a pasted prompt, an over-permissioned agent, an unauthorized action, or an AI-built tool connected to live data.

    • Record the facts. Note the tool, account type, date, data entered, files uploaded, systems connected, permissions granted, actions taken, code or automation deployed, people involved, output created, and whether a share link exists.
    • Delete the chat or file from the service. OpenAI documents how users can delete chats.[12] Deletion is a necessary containment step, not proof that every copy or prior processing vanished.
    • Review and remove shared links. In ChatGPT, shared links are managed under Settings, Data Controls, Shared Links. Do not assume deleting a local chat removed a previously shared public version.[5]
    • Rotate exposed secrets now. Replace passwords, API keys, tokens, recovery codes, or payment credentials that appeared in a prompt, upload, output, or AI-built tool. Revoking the old secret matters more than deleting the sentence that contained it.
    • Revoke agent access and stop unsafe automation. Disable the agent or AI-built workflow, remove its connected-app grants and service credentials, preserve relevant logs, and confirm whether it sent, changed, or deleted anything before restoring service.
    • Check contracts and notification duties. If customer or employee information was involved, review the relevant agreement and state breach-notification law. Many small firms fall below comprehensive privacy-law thresholds; breach-notification duties may still apply regardless of company size.
    • Call the right people before making promises. Notify your insurer or broker under the policy terms. Use qualified legal counsel when regulated data, client confidences, or notification duties may be involved.

    Turning off a training setting is useful going forward, but it is not a time machine. Temporary-chat features can also reduce retention for appropriate low-risk work; they do not make it acceptable to paste client personal information into a consumer account.

    Break the chain: Make accidental disclosure easy to report. The employee who tells you in five minutes gives you options. The employee who hides it for five weeks takes them away.

    Your IT provider should be able to account for all three heads

    An owner should not have to accept “we have security” as an answer. Ask for evidence about chatbot use, agent permissions, and AI-built software in ordinary language.

    CONTROL

    ASK FOR PROOF

    Chatbot inventory

    Which AI tools, accounts, bots, and extensions are known?

    Agent access

    Which systems can agents read, change, send from, or delete?

    AI-built tools

    Which scripts, apps, and automations run, and who owns them?

    Data terms

    Are training, retention, sharing, and deletion settings documented?

    Review and logs

    Which outputs, actions, and code require approval or logging?

    Incident response

    Who records, contains, escalates, and assesses notification duties?

    The provider does not need to promise that no employee will ever use an unapproved tool. It should be able to show which controls exist for each head, who receives alerts, what the limitations are, and what happens after a report.

    The bottom line

    Shadow AI is a three-headed visibility problem created by useful tools. Employee chatbots expose inputs. Third-party agents add permissions and actions. Stealth coding creates software dependencies the business may not know it owns. Punishing people for wanting to work faster will not solve any of them.

    After years in security, my advice is to make the safe route easier than the shadow route: one approved business account, explicit limits on agent access, a register of AI-built tools, one page of rules, a named owner, and a response plan that rewards fast reporting.

    You do not need to monitor every thought or stop every experiment. You need to control which data leaves the business, which systems AI can reach, what actions it can take, which software it creates, and who remains accountable. That is small-business AI governance in practical form.

    Sources

    Accessed September 29, 2026. Statistics describe the cited source’s sample or reported dataset and should not be generalized beyond that scope. No publicly named small-business shadow-AI leak was found in the research for this article.

    1. Samsung employee ChatGPT incidents. DarkReading, “Samsung Engineers Fed Sensitive Data to ChatGPT, Sparking Workplace AI Warnings” (2023). Open source

    2. Workplace shadow-AI survey. TrustedTech/Censuswide, “Shadow AI in the Workplace” (March 2026; 2,001 U.S. and U.K. employees). Open source

    3. Personal-account use. Newsworthy summary of Netskope’s Cloud and Threat Report 2026. Open source

    4. CISA document uploads. TechRepublic, “Former CISA Chief Admits Uploading Sensitive Documents to ChatGPT” (September 10, 2026). Open source

    5. Indexed shared chats and deletion steps. Bitdefender, “Your Shared ChatGPT Chats May Be Publicly Searchable” (2025). Open source

    6. Consumer AI and privilege. Ogletree Deakins, analysis of United States v. Heppner (2026). Open source

    7. MSP shadow-AI inventory discussion. Reddit r/msp (December 10, 2025; anecdotal). Open source

    8. Personal ChatGPT Plus workplace-data discussion. Reddit r/ChatGPT (January 25, 2024; anecdotal). Open source

    9. Blocking-versus-governance discussion. Reddit r/sysadmin (June 7, 2023; anecdotal). Open source

    10. ChatGPT Business data terms and pricing. OpenAI Help Center, “ChatGPT Business FAQ.” Open source

    11. Adaptable AI-use-policy template. Safe AI Australia, MIT-licensed governance template. Open source

    12. Chat deletion instructions. OpenAI Help Center, “How to Delete and Archive Chats in ChatGPT.” Open source

    13. Community Bank shadow-AI SEC filing and disclosure context. American Banker, “A bank breaks its silence on its shadow-AI breach” (June 11, 2026). Open source

    14. Shadow-AI breach costs. IBM, Cost of a Data Breach Report 2026 (602 breached organizations, March 2025–February 2026; non-statistical, enterprise-weighted sample). Open source

    15. Agents embedded in enterprise applications. Gartner, “Gartner Predicts 40% of Enterprise Apps Will Feature Task-Specific AI Agents by 2026” (August 26, 2025; forecast, not a small-business adoption count). Open source

    16. Governance of AI-coded internal tools. Retool press release reporting a Wynter survey of 307 CTOs, CISOs, and CIOs (June 17, 2026; enterprise leadership sample and vendor-sponsored). Open source

    17. State breach-notification laws. National Conference of State Legislatures, “Security Breach Notification Laws” (all 50 states and listed U.S. territories; requirements and definitions vary). Open source