Skip to content

Shadow AI and the Problem with Personal AI Accounts

Shadow AI and the Problem with Personal AI Accounts
7:38
Shadow AI and the Problem with Personal AI Accounts

Who Owns the Work?

When an Employee Leaves, Their AI Account Can Take Your Workflow With It

A lot of business owners tell us their team isn't really using AI yet. Then we ask the team...

The answer is almost always some version of "all of them." ChatGPT for emails, another tool for spreadsheets, a free app for meeting notes, a browser extension somebody found on a Tuesday. Most of it runs on personal accounts that the company never set up and can't see.

That's shadow AI. It's usually well-intentioned, and it creates a problem most leaders haven't considered yet: who owns the work.

A department's workflow lived in one person's personal account

On Episode 7 of Shh... IT Happens, John shared a story he heard from an HR consultant we've had on the show.

A manager had built an agent-style tool inside his personal ChatGPT account. Over time, his whole department, somewhere between 10 and 15 people, ran their daily workflow through it. When the company decided to part ways with him, it realized the process it depended on didn't belong to the company.

According to John, the severance terms required the manager to hand over his personal account. The number being discussed was around three times his salary. The manager knew exactly what that workflow was worth.

That's really on the company. That's not on the individual.  The employee did what employees do. He found a faster way to work. Nobody gave him a company account to build it in.

Shadow AI is a visibility problem first

Recent research shows how common this has become:

  • IBM's 2026 Cost of a Data Breach Report, researched by the Ponemon Institute, found that security incidents involving shadow AI more than doubled in a year, from 20% to 43%.
  • A 2026 survey of 1,253 cybersecurity professionals by Cybersecurity Insiders found that 88% can't tell personal AI accounts apart from corporate ones.
  • BigID's AI Risk & Readiness in the Enterprise report found that only 6.4% of organizations have an advanced AI security strategy.

In plain English, most businesses can see that AI is being used. Very few can tell whose account the work lives in or where the data goes afterward.

Our post, Shadow AI Is Entering Your Business From All Sides, covered how these tools get in. This post is about what happens to your work once they do.

Both ends of the AI risk dial leak data

Picture a dial from 1 to 10. At 1, leadership avoids AI entirely and gives the team no guidance. At 10, leadership connects every tool to everything with no guardrails.

Most people assume the risk sits at 10. It sits at both ends. The 10 leaks data through the connections it approves. The 1 leaks data through the personal accounts employees open because the company gave them nothing else.

The goal is the middle of the dial: approved tools, clear rules, and work that stays in company-owned accounts.

Enterprise licenses protect more than personal accounts, but a gap remains.

A September 2026 Harvard Business Review article, "Is Your AI Training the Competition?," named a hidden risk: AI Sherlocking. E

nterprise AI agreements usually protect prompts and outputs. The author argues that feedback logs, synthetic data, and general capability improvements can still teach the platform how your best people solve problems.

In the AI era, it's what we do with the data that is our IP, even more so than the data.

Personal accounts skip even the protections an enterprise license provides. On consumer ChatGPT plans, the setting that allows OpenAI to train on your conversations, called "Improve the model for everyone," is on by default. OpenAI's Business and Enterprise workspaces don't train on your content by default.

That's one more reason to read the terms before you click accept. We covered that in Nobody Reads the Terms and Conditions.

A personal AI account is a company key on a personal key ring

Think of your office key hanging on an employee's personal key ring, next to the house key and the car key. It works fine every day. When they leave, the key leaves with them, and you're asking for it back.

Most offboarding checklists cover the laptop, the email account, and the badge. Very few cover the AI accounts, custom assistants, saved prompts, and automations an employee built along the way.

HR and IT need to handle this together, which we discussed with Jordan George in The Intersection of HR and IT.

What works:

  1. Ask first, without blame. Ask each team: which AI tools do you use, for what, and on whose account? Make it safe to answer honestly. The goal is a map of how work gets done.
  2. Approve tools, starting with what you already pay for. If you're on Microsoft 365, Copilot Chat signed in with a work account comes with enterprise data protection. Microsoft says it doesn't use prompts and responses to train its foundation models, and Microsoft Purview can audit and retain the activity.
  3. Move shared work into company-owned accounts. Any prompt library, custom assistant, agent, or automation that more than one person relies on belongs in a company workspace.
  4. Write a short never-enter list. Keep client data, employee records, financials, passwords, and proprietary methods out of any unapproved tool.
  5. Add AI to onboarding and offboarding. New hires get the approved tools on day one. Departing employees hand off their AI work before their last day.

What can wait: privately hosting your own AI model in Azure. John made a good case for private AI, but for most small businesses it's a later step. Get visibility and ownership right first.

Where Solve iT fits in

We aren't anti-AI. We use it, we help clients adopt it, and we'd rather see a team use a well-governed tool than work around a ban.

Security is people, process, and technology, in that order. Shadow AI is mostly a process problem, so the fix starts with the process: which tools, which accounts, which data, and who owns what.

If you're not sure which AI tools your team is using or whose accounts hold your work, book a free threat assessment. It includes a dark web scan, a phishing simulation, and a plain-English security posture report, and it now looks for shadow AI too. You'll see where your exposure sits and what to fix first.

Book your free threat assessment

Quick Answers

What is shadow AI? AI tools employees use for work without company approval or visibility, often through personal accounts. It's usually well-intentioned and creates data and ownership risks.

Is it safe for employees to use personal ChatGPT accounts for work? It creates two risks. Consumer plans can use conversations for model training unless the user turns that off, and the company loses access to the work when the employee leaves.

Does an enterprise AI license protect my company's data? It adds important protections, including no training on your content by default for major business plans. Harvard Business Review notes that feedback and usage patterns can still fall outside typical contract terms, so review them.

How do I find out what AI tools my employees use? Ask them directly, then confirm with the visibility your IT provider has on your network and devices.