← Insights

Your staff is already using AI. You just can't see it.

More than half of employees use AI tools their employer never approved. At a 15-person firm, that's 8 or more people pasting client data into tools you've never evaluated.

The Albi team · July 26, 2026 · 6 min read

The uncomfortable truth

You probably already suspect this, but here it is: your staff is using AI tools right now. ChatGPT. Claude. Gemini. Copilot. Perplexity. They're using them to draft emails, summarize documents, research case law, and prepare client communications.

More than half of employees use AI tools their employer never approved, according to Salesforce research. Three in four workers have signed up for AI tools on their own rather than using employer-provided options. At a 15-person firm, that's potentially 8 or more people pasting client data into tools you've never evaluated, never approved, and can't see into.

This isn't hypothetical. It's happening today. And you'd never know it unless you looked.

From the article · Exposure by tool
ChatGPT128
Claude61
Gemini38

Anonymized scan data, 30 days

What shadow AI actually looks like in a law firm

Shadow AI is an industry term for AI tools used without organizational knowledge or approval. In enterprise companies, CISOs and security teams are scrambling to get ahead of it. But at a 10-person or 20-person law firm, nobody is even watching.

In practice, it looks like this. A paralegal pastes a client's demand letter into ChatGPT to clean up the language. An associate copies deposition notes into Claude to generate a summary. A legal assistant uploads a settlement agreement to Gemini to extract key dates. An office manager uses Copilot to draft a client follow-up email.

None of these people think they're doing anything wrong. They're trying to be more efficient. They're trying to get through the day. And on the surface, it looks harmless.

But every one of those actions sent client data to a third-party server. The data went to OpenAI, Anthropic, Google, or Microsoft. It left your firm. In most cases, it was processed on servers shared with millions of strangers. And there's no record, no paper trail, and no way for you to know it happened.

The question isn't whether your team is using AI. They are. The question is whether you can see it.

Why it matters more than you think

This isn't just a security hygiene issue. It's a professional responsibility issue.

Bar associations across the country are issuing opinions on attorney use of AI. The ABA released Formal Opinion 512 in July 2024, establishing that attorneys using AI must consider their ethical obligations around competence, client confidentiality, communication, and reasonable fees. States are following: Florida now mandates disclosure when AI affects client billing. Texas requires human oversight of AI-generated work. New York is requiring AI competency CLE credits.

If your paralegal pasted a privileged document into ChatGPT last Tuesday, you have a problem. Not a theoretical one. A real one. That data now sits on OpenAI's servers. You can't retrieve it. You can't delete it. And if someone asks about it (your insurer, a bar committee, opposing counsel in a discovery dispute) you won't have an answer, because you didn't know it happened.

One privilege breach could mean a bar complaint, a malpractice claim, or a lost client. And the hardest part is that the person who did it probably had no idea they were creating risk.

"But we bought the enterprise version"

Some firms have taken a proactive step. They bought enterprise seats for ChatGPT or Claude or Copilot. They told their team to use the approved tool. They assumed the problem was solved.

It's not.

Enterprise versions typically prevent your data from being used to train the AI model. That's real, and it matters. But enterprise subscriptions don't solve the full problem. They don't show you whether your team is actually using the enterprise version or their personal account. They don't tell you if someone is also using three other AI tools on the side. They can't classify which data is privileged and which isn't. And they don't generate the kind of log that would satisfy a bar committee or an insurer asking "what happened with this client's data?"

Buying an enterprise seat is a step in the right direction. But if you can't see what your people are actually doing, it's a policy without enforcement.

What you can do about it right now

The first step isn't blocking anything. It's not writing a policy. It's not picking a "sanctioned" tool. The first step is seeing what's actually happening.

You need to know: What AI tools is my team using? How often? What type of data are they putting into them? Are they using the approved tool or something else?

If you can't see what's happening, every other decision you make about AI at your firm is based on guesswork. And guesswork isn't a strategy. It's a liability.

That's why we built ShadowAI. It's a free browser-based tool that shows you which AI tools your team is using and how often. It installs in five minutes, runs silently, and your first exposure report is ready in under 24 hours.

No IT team required. No disruption to your staff. Just a clear picture of what's actually happening.

Because the question isn't whether your team is using AI. They are. The question is whether you can see it.

Find out what your team is actually using.

ShadowAI is free and takes minutes to install. Your first exposure report lands inside 24 hours.

Albi product walkthrough