Shadow AI: Where Your Business Data Actually Goes
Ask most business owners which AI tools their team uses and you will get a short answer. Ask their staff, and you will get a much longer one. Somewhere between the two sits shadow AI — the ChatGPT tabs, the AI "summarise this" buttons, the meeting-transcription add-ons and the AI features quietly switched on inside software you already pay for. Each one is a door your business data can walk through, and most businesses have never mapped where those doors lead.
This matters because the legal responsibility does not move when your data does. Under UK data protection law, if you decide how and why personal data is processed, you are the controller — and you remain accountable even when the processing happens inside someone else's AI tool.
The question the regulator actually asks
The Information Commissioner's Office (ICO) has been explicit that data protection law applies to AI like any other processing. Its Guidance on AI and data protection sets out obligations around lawful basis, transparency and accountability for organisations that build or use AI. In 2023 the ICO published eight questions organisations should ask before processing personal data with generative AI, and warned businesses — in the words of its executive director for regulatory risk — not to "be blind to AI risks in the rush to see opportunity."
The practical trigger to know about is the Data Protection Impact Assessment (DPIA). Under UK GDPR Article 35, a DPIA is required before processing that is "likely to result in a high risk to the rights and freedoms" of individuals. The ICO's own list of triggers explicitly names innovative technology, including AI. In other words: rolling out an AI tool that touches personal data is one of the textbook situations where the law expects you to have assessed the risk first — not after something goes wrong.
Automated decisions now have their own rulebook
If an AI tool makes decisions about people with little or no human involvement, a second set of rules applies. Following the Data (Use and Access) Act 2025, the ICO's automated decision-making guidance — updated on 31 March 2026 — now frames this under UK GDPR Articles 22A–22D. The rules bite when a system makes a significant decision about a person (one with legal or similarly significant effect — the ICO gives examples such as automatically refusing a credit application or an e-recruitment screen-out) that is solely automated, meaning there is no meaningful human involvement. Many businesses adopt an AI tool for exactly this kind of task without realising they have stepped into that regime.
"Where does our data go?" is answerable
The reassuring part is that shadow AI is a mapping problem, and mapping problems have solutions. The questions are concrete:
- Which AI tools and third-party trackers is your website already sending visitor data to?
- Which of your tools send data outside the UK or EU, and under what safeguard?
- Where does personal or confidential data actually flow when staff use AI in their day-to-day work?
- Do you have an acceptable-use position your staff can actually follow — or just an unspoken assumption?
- Could a task you are paying a per-seat AI subscription for run on a private model on your own hardware instead, keeping the data in-house?
Turning it into a plan
Our AI Readiness Audit answers exactly those questions. It maps how your business uses AI and data against the NIST AI Risk Management Framework, scans your website for the AI and trackers already sending data out, identifies which legal duties apply to you, and gives you a ready-to-adopt Acceptable AI Use policy tailored to your answers. If you are weighing the wider legal picture, our companion piece on what the EU AI Act and UK GDPR mean for small businesses is the place to start.
To find out where your business data is actually going, book a free scoping call for an AI Readiness Audit.
This article is general information, not legal advice. Your specific obligations depend on your circumstances; consider taking your own professional advice. Any assessment we carry out is done only with your authorisation.
Related Articles
What the EU AI Act and UK GDPR Mean for Small Businesses Using AI
The EU AI Act is in force and reaches beyond the EU, and UK GDPR already applies to AI. A plain-English guide to what applies to a small business — and what to do next.
Artificial IntelligenceTaking Control of Your Data: Local AI Setup for SMBs
Stop renting intelligence. For businesses handling sensitive data in law, healthcare, or finance, local on-premise AI setup provides unmatched security, zero latency, and zero recurring API costs...
Artificial IntelligenceExpanding Into Europe: What UK & US Tech Vendors Need to Know About AI Infrastructure
We work with SMBs and vendors across the UK and US who assume that once they've handled UK GDPR, expanding into continental Europe is a formality. It ...