Your Employees Are Using AI. Do You Know How?
The first step in responsible AI adoption is not a ban. It is finding out which tools employees are already using, what work they are doing with them, and where the real risks and opportunities are.

Employees are already using AI, often through personal accounts and tools management never approved. The fix is not a crackdown. It is a short, non-punitive inventory that brings that use into the open so it can be supported, trained, and monitored.
A manager asks the team, “Are we using AI anywhere?”
The room gets quiet.
One employee uses ChatGPT to rewrite customer emails. Another uses an AI meeting assistant. Someone in marketing uses an image generator. A supervisor has started pasting production notes into a chatbot to help organize shift reports. None of them thought of those activities as an “AI program.” They were simply trying to get work done.
That is how shadow AI develops.
The term sounds more threatening than it needs to. In most small and midsize organizations, shadow AI is not evidence of bad employees. It is evidence that useful tools have become available faster than management systems have caught up.
There is now a number for this. In an April 3, 2026 FEDS Note, Monitoring AI Adoption in the US Economy, Federal Reserve economists reported that Census Bureau data showed roughly 18% of U.S. firms had adopted AI at year-end 2025, while the Real-Time Population Survey showed roughly 41% of the workforce using generative AI for work as of November 2025. The Atlanta Fed’s Survey of Business Uncertainty estimates that 78% of the labor force works at a firm that has adopted AI in some form.
Sit with the first two numbers. Firms at 18%. Individuals at 41%. That gap is shadow AI, quantified at the national level.
Gallup, reporting April 12, 2026 on a February 4–19, 2026 survey of 23,717 U.S. employees, found AI use continuing to expand and frequent users often reporting productivity benefits. Gallup also found that the workplace changes tied to AI adoption are most pronounced among small and midsized employers, which is to say among companies that look exactly like this one.
The practical implication for a small or midsize company in Western North Carolina is simple: assuming nobody is using AI because the company has never purchased an “AI platform” is no longer a safe assumption.
Discovery should come before restriction
An organization cannot govern what it does not understand.
The first management task is to build a basic inventory of AI use. That does not require enterprise software or a forensic investigation. It can begin with conversations and a short questionnaire.
Ask employees:
- What AI tools do you use for work?
- Are you using a company account or a personal account?
- What tasks are you using them for?
- What kinds of company, customer, or employee information do you enter?
- Which uses save meaningful time?
- Where have you seen bad or unreliable output?
- Which tools are built into software the company already pays for?
The tone matters. If employees believe the exercise is designed to punish them, they have an incentive to underreport. If management frames it as “help us understand what is useful so we can support it responsibly,” the organization is more likely to learn something valuable.
Personal accounts create a management blind spot
An employee may use the same public AI tool at home and at work, but the business context is different.
A personal account may not have the privacy terms, administrative controls, retention settings, access management, or contractual protections that a business account provides. That does not automatically make every personal-account use dangerous. It means management should know when business information is moving into systems the company does not control.
The Federal Trade Commission has warned AI providers that privacy and confidentiality commitments matter and that companies must live up to representations about how customer data is handled (January 2024). It has also acted on it: Operation AI Comply, launched September 2024, has produced consent orders against companies making unsupported AI claims, with enforcement continuing through 2026. From the user’s side of the relationship, that is a reason to read the terms and understand the service rather than assuming all AI tools handle data the same way. It is also a reminder that no new AI statute is needed for existing law to reach AI conduct.
Inventory the use case, not just the tool
A list that says “ChatGPT, Gemini, Copilot” is not enough.
The same tool can be used for low-risk brainstorming one minute and sensitive-data analysis the next. A useful inventory therefore records both the tool and the task.
For example:
| Tool use | Typical task | Account type | Data category | Human review | Initial management concern |
|---|---|---|---|---|---|
| AI chatbot | Brainstorming event themes | Either | Public / internal | Author | Low |
| AI chatbot | Drafting customer correspondence | Business | Customer data | Author, before send | Review and accuracy |
| AI chatbot | Uploading payroll spreadsheet | Business only | Personal, sensitive | Manager approval | Data sensitivity |
| Meeting assistant | Internal team meeting | Business | Internal | Owner of the meeting | Recording, consent, retention |
| Image generator | Marketing concept | Business | Public | Marketing lead | Accuracy, rights, disclosure |
| AI search tool | Research | Either | Public | Author | Source verification |
The account type column does more work than it looks like it should. Personal versus business account is the single most diagnostic field in the whole inventory, and it is the one employees are least likely to volunteer unless the form asks.
This is where NIST’s voluntary AI Risk Management Framework becomes useful even for a small company. Its four functions, Govern, Map, Measure, and Manage, translate into ordinary management questions: who is responsible, where is AI used, is it working, and what do we change. A small business does not need to implement it like a federal contractor. It can borrow the logic.
Do not forget the AI already inside software you own
The inventory should also capture AI features embedded in software the company already pays for. Employees may not think of an email assistant, a meeting summarizer, a CRM feature, or a document tool as a separate AI product, and so they will not report it when asked which AI tools they use.
For most small businesses, this is the larger exposure. More company information probably flows through AI features in Microsoft 365, the CRM, and the phone system than through anything an employee signed up for on their own. Ask about it by name rather than by category. “Do you use Copilot in Outlook?” gets a better answer than “do you use AI?”
The goal is not to eliminate unofficial experimentation
Some of the best AI use cases in an organization will be discovered by employees closest to the work.
A receptionist may find a better way to turn rough call notes into a clean handoff. A project coordinator may use AI to convert meeting notes into a task list. A salesperson may discover that an AI-assisted first draft cuts follow-up time in half.
Management should want to find those examples.
The objective is to separate productive experimentation from uses that create unacceptable risk. That requires more than an approved-tool list. It requires employees to understand what information can be shared, what outputs need verification, and when a proposed use needs approval.
A five-step model: Discover → Understand → Approve → Train → Monitor
For a small or midsize organization, the process can stay simple.
- Discover. Ask where employees are already using AI. Include embedded features inside existing software, not just standalone chatbots.
- Understand. Identify the task, data involved, business benefit, potential harm, and level of human review.
- Approve. Decide which tools and use cases are allowed, restricted, or prohibited. Give employees a path to request approval for something new.
- Train. Teach people how the rules apply to the work they perform. A policy without training is just a document.
- Monitor. Revisit the inventory periodically. Tools change, vendor terms change, and employees find new uses.
NIST’s AI RMF Playbook specifically includes actions related to AI inventories, monitoring, and risk management. It is voluntary guidance, but the concepts translate well to companies that need structure without bureaucracy.
What management learns from the inventory is often more useful than the inventory itself
The discovery process reveals two things at once: where the organization may be exposed and where employees are creating value.
Perhaps the biggest issue is that customer information is being pasted into personal AI accounts. That needs attention.
But perhaps the company also discovers that three people independently built nearly the same workflow for summarizing weekly reports. That may be an opportunity to standardize a good process, train the rest of the team, and save hours across the organization.
That is why the right response to shadow AI is not “catch people using it.” It is bring useful AI use into the open so it can be managed, improved, and repeated.
If a manager takes one idea from this article, take that one. Discovery is not an audit. It is the cheapest source of process improvement most small companies have available right now.
Start with the discovery step: the employee questionnaire and the six-column inventory table above are ready to use as-is. Or book a free call and we’ll help you run the discovery conversation and build the inventory together. Our AI Assessment is a good next step once you know where AI is already being used.