Your Staff Is Already Using AI. You Just Don’t Know Which Parts.
Revised August 22, 2026
Why is shadow AI a problem?
Shadow AI is a problem because three things happen without anyone deciding they should: confidential information leaves the business through a free consumer account, output nobody checked reaches a paying customer, and the company keeps no record of which work was AI-assisted. Each is survivable on its own. Together they mean you cannot answer basic questions about your own files.
Keep reading ↓Imagine it’s a Thursday morning and the estimate your office manager sent out on Tuesday has come back with a question you cannot answer. The document reads well. Cleaner than anything that has left your Rock Hill shop in years. The tone is right, the scope is right, and buried in the middle is one tidy paragraph describing a warranty you have never offered in your life.
So you ask her where that came from. She says the customer was waiting, she was slammed, and she got most of it out of the chat app on her phone. She isn’t hiding anything. She’s a little proud of it, honestly. A two-hour job took twenty minutes and the customer replied the same afternoon.
That moment is the entire subject of this article, and some version of it is playing out in small offices from Wentzville to Waterloo this week. Nobody made a technology decision. A person under time pressure found something that worked, used it, and never thought to mention it — because nobody ever told her there was a line, much less where it sits.
Why do the numbers on AI adoption contradict each other?
Because they count two different things. Firm-level surveys ask the business. Worker-level surveys ask the person doing the typing. The U.S. Census Bureau’s Business Trends and Outlook Survey, published May 26, 2026 and covering December 14, 2025 through May 3, 2026, found fewer than 20% of firms with four or fewer employees using AI. Ask workers directly and the share is roughly double that.
Here are the firm-level figures side by side. Census BTOS, same May 2026 release: under 20% for firms with four or fewer employees, 32% for firms with 100 to 249 employees, and 37% for firms with 250 or more. A Federal Reserve FEDS Note published April 3, 2026 put overall firm adoption at roughly 18% as of year-end 2025, using that same BTOS data. Those are government numbers, collected from businesses, and they say the same thing: the smaller the company, the less likely it is to describe itself as an AI user.
Now the worker side. That same Federal Reserve note points to the Real-Time Population Survey run by economists Alexander Bick, Adam Blandin and David Deming, which asks individuals a plain question: do you use generative AI for your job? As of November 2025, about 41% of workers said yes. Non-work use ran closer to 50%. That is not a vendor number and not a press release. It is a research survey asking people about their own hands on their own keyboards.
The Federal Reserve note explains part of the gap in the driest possible language, and it is worth understanding: a random sample of workers pulls disproportionately from large employers, because large employers employ most people. So a worker survey naturally leans toward the kinds of companies where AI is already normal. That is real, and it explains some of the distance between 18% and 41%.
But it does not explain all of it, and the remainder is the part that matters to you. A firm survey asks an owner or a manager to characterize the company. A worker survey asks a person to characterize themselves. When those two disagree, the most likely explanation is not that anyone lied. It is that the company has not adopted AI and its people have. If you want the adoption statistics pulled apart in more detail, including why a question-wording change in November 2025 broke the trend line, that is covered in what percent of small businesses actually use AI.
What shadow AI looks like inside a six-person business
Shadow AI is any use of an AI tool at work that the business never chose, never paid for, and does not know about. In a small company it almost never looks like software. It looks like a phone, a browser tab, and somebody trying to get out the door by five.
Concretely, in a metro-area shop with a handful of employees, it looks like this:
- A quote or proposal drafted in a free chatbot and lightly edited before it goes to the customer.
- A difficult email to an unhappy client rewritten to sound calmer, with the original complaint pasted in to give the tool context.
- A spreadsheet of names, addresses and job totals dropped into a chat window so it can be summarized or sorted.
- Social posts, service-page copy and review replies generated in bulk from a rough prompt.
- A contract, lease or insurance certificate uploaded so somebody can ask, in plain English, what it actually says.
- A transcript or recording of a meeting run through a free summarizer that nobody in the room agreed to.
None of that requires an IT department to permit or a credit card to start. That is the point. The barrier to a staff member adopting AI is a login, and the barrier to a company adopting AI is a decision, a budget and a conversation. The first one is lower by an enormous margin, which is exactly why the two sets of numbers came apart.
Where does the 49% to 78% range come from, and how solid is it?
Those shadow-AI percentages come from vendor surveys, not from government statistics, and you should treat them accordingly. Two are quoted constantly. BlackFog, a cybersecurity company, reported 49%. WalkMe, a software adoption company, reported 78%. Both companies sell products that address the problem their research describes. That does not make the numbers false. It does mean you read the methodology before you repeat the headline.
The BlackFog figure, published January 27, 2026, comes from research conducted by Sapio Research in November 2025 among 2,000 respondents, 1,000 in the United States and 1,000 in the United Kingdom, all at organizations with more than 500 employees. Of that whole sample, 49% said they use AI tools their employer has not sanctioned. Among those people, 58% were using free versions of those tools.
The WalkMe figure, published August 27, 2025, comes from a Propeller Insights survey fielded July 16 to 23, 2025, with a margin of error of about three percentage points. The sample was 1,000 working U.S. adults — and here is the part that gets dropped when the number travels — screened so that every respondent already uses AI in their job. WalkMe says so plainly in its own release: the 100% adoption rate in that sample is by design, not a picture of the American workforce. The exact claim is that 78% say they use AI tools not provided by their employer, which is a softer statement than tools their employer forbade.
So the 29-point spread is not two studies disagreeing about reality. It is two studies asking different questions of different people. One is 49% of everybody at a big company. The other is 78% of people who already use AI at work. Stack them in a slide deck and you get a scary range; take them apart and you get two narrow findings that never had the same denominator.
Compare that with how the Census Bureau builds its number. BTOS is a recurring survey of a large probability sample of U.S. employer businesses, reported by firm size and industry, with the question wording published and the reference period stated on the page. When the Bureau changed that wording in November 2025 from AI used to produce goods or services to AI used in any business function, reported rates jumped by 47% to 159% depending on industry — and the Bureau said so, which is why anyone can adjust for it. A vendor survey rarely gives you enough to do that.
One more honest caveat, and it is a big one: neither shadow-AI survey looked at a business like yours. BlackFog sampled companies with 500-plus employees. WalkMe sampled people who already use AI. Nobody has published a solid measurement of unapproved AI use inside a nine-person landscaping company in St. Charles County. The direction of these findings is believable. The precise percentage, applied to your payroll, is not something anyone has actually measured.
Why is shadow AI a problem?
Shadow AI is a problem because three things happen without anyone deciding they should: confidential information leaves the business through a free consumer account, output nobody checked reaches a paying customer, and the company keeps no record of which work was AI-assisted. Each is survivable on its own. Together they mean you cannot answer basic questions about your own files.
Take them one at a time, because the fixes are different.
Client information in a free consumer tool. The BlackFog research from November 2025 asked what people actually put in. Among respondents, 33% had shared company research or datasets, 27% had shared employee data including names, payroll and performance information, and 23% had shared financial statements or sales figures. Free consumer tiers generally have looser data handling than paid business tiers, and 58% of the people using unsanctioned tools in that study were on free versions. If you carry client confidentiality obligations — medical, legal, financial, anything involving a signed agreement — that paste is the exposure, not the AI. The practical boundaries are worked through in what is safe to paste into ChatGPT for your business.
Unreviewed output reaching a customer. This is the failure that costs money soonest, and it is the one in the estimate at the top of this article. A generated draft is confident and fluent whether or not it is correct. It will invent a warranty term, quote a lead time you cannot hit, cite a code section that does not apply in your county, or promise a same-day response your crew has never once delivered. A customer holding a written promise does not care which software produced it.
No record of what was AI-assisted. Six months later a dispute comes up and you want to know how a sentence got into a document. Nobody remembers. There is no draft history, no note, no version marked. The work looks the same as everything else in the folder. That is not a technology gap; it is a bookkeeping gap, and it is the one owners underestimate.
Wildly off-topic — if the office is relocating this fall, start with St. Louis movers.
Can you actually tell which work was AI-assisted?
Not reliably, and you should stop planning around the idea that you can. OpenAI launched its own AI Text Classifier on January 31, 2023 and pulled it on July 20, 2023, citing a low rate of accuracy; in its own evaluation the tool flagged only 26% of AI-written text correctly. If the company that built the model could not detect the model, a third-party detector on a marketing site is not going to settle an argument in your office.
Detectors also fail in the direction that hurts most. They flag plain, competent, unadorned writing as machine-made, which is exactly what a careful employee produces. Accusing your best writer of using a chatbot because a website scored her paragraph at 94% is a fast way to lose her.
So the answer is not detection. It is disclosure, and it is cheap. A one-line note in the job file — drafted with AI, reviewed by me, sent 8/14 — costs four seconds and answers the question permanently. The businesses that get this right are not the ones with better software. They are the ones where saying so is normal and nobody gets in trouble for it.
That last part is the whole game. WalkMe’s July 2025 survey found 49% of respondents had hidden their use of AI to avoid judgment, rising to 62% among the youngest workers, and that only 7.5% had received extensive training while 23% had received none at all. Again, a vendor survey of self-selected AI users — but the shape of it matches what owners describe. People conceal the tool because they think using it looks like cheating, and no one has told them otherwise. If the answer to that is training, it is worth knowing how to judge an AI course before you pay for one — most of what is sold to small businesses does not survive a serious look.
Missouri and Illinois are not in the same place on this
If you employ anyone in Illinois, the rules changed on January 1, 2026. House Bill 3773 amended the Illinois Human Rights Act to prohibit employers from using AI in a way that has the effect of discriminating on the basis of a protected class in recruitment, hiring, promotion, training selection, discharge, discipline, tenure, or the terms and conditions of employment. It also bars using ZIP codes as a proxy for a protected class, and it requires notifying applicants and employees when AI is used in those decisions.
Two details make that matter for a small shop rather than only for a corporation. First, the Illinois Human Rights Act has covered employers with one or more employees since July 1, 2020, under Public Act 101-0430, so there is no small-business exemption to hide behind in Metro East. Second, the statute reaches the effect of the AI, not the intent behind it. An office manager in Fairview Heights who pastes a stack of resumes into a chatbot and asks it to rank them has just used AI in a hiring decision, whether or not you knew, approved, or ever heard about it. The Illinois Department of Human Rights has been working through implementing rules on notice and disclosure during 2026; the statute itself is already in force.
Missouri has no equivalent AI-in-employment statute as of August 2026. That is not the same as no rules. Federal and Missouri anti-discrimination law still applies to the outcome of any screening or evaluation process, and outsourcing the judgment to software does not move the responsibility off the employer. The practical difference is disclosure: Illinois has written the notice obligation into statute, and Missouri has not.
If your service area crosses the river — and for most St. Louis metro businesses it does — write your policy to the Illinois standard. Running one rule is simpler than running two, and the stricter of the two is the one you would rather be caught complying with.
The one-page AI policy you can write this week
A workable small-business AI policy answers three questions and nothing else: what may be pasted in, what may never be pasted in, and who reads the output before it leaves the building. You do not need a law firm or a template pack. You need one page, five decisions, and a staff meeting to say it out loud.
1. AI is allowed here, and you will not get in trouble for saying you used it. Put that first, in that order. Every rule below it depends on people telling you the truth, and they will not if the opening line reads like a threat. A ban does not stop the behavior; the surveys above are what a ban looks like in practice.
2. What may be pasted. Your own marketing copy. Public pricing. Published spec sheets and manufacturer instructions. Job descriptions. Anything already on your website. A customer question with names, addresses and account numbers stripped out. If it could be printed in the newspaper without a phone call from anyone, it can go in a chat window.
3. What may not be pasted, ever. Customer names, addresses, phone numbers or emails. Payment or bank details. Anything from a signed confidentiality or vendor agreement. Employee records, payroll, medical notes, disciplinary write-ups. Insurance claim files. Photographs of a customer’s home interior. Resumes, applications, or anything used to sort, rank or screen a candidate — that one is a legal line in Illinois, not a preference. Name the categories in your own words, on paper, so nobody has to guess.
4. Nothing goes to a customer unread. Pick the reviewer by name, not by title. In a six-person company that is usually you, or the one person who has been quoting jobs for a decade. The reviewer checks three things: are the numbers ours, are the promises ones we keep, and does it sound like a person here wrote it. Estimates, contracts, warranty language, anything with a date or a dollar figure gets read twice.
5. Say so in the file. One line where the work lives: drafted with AI, reviewed by whom, sent when. That is the whole record-keeping requirement. It takes seconds and it is the only thing that will answer a question in March about a document from August.
Then do the part most owners skip: ask what people are already using, and do not react badly to the answer. You will usually learn that two or three staff members have been doing this for months, that one of them is genuinely good at it, and that nobody was hiding anything on purpose. If you would rather work through the setup with other local owners than write it cold, that is a large part of what the AI workshops are for.
What this looks like from the owner’s side
In a small local service business, the crew is not usually the constraint. The office is. One person answers the phone, schedules, orders parts, chases the insurance adjuster, writes the estimates and follows up on the ones that went quiet — and almost none of that time is billable. The free estimate is the loss leader of the whole trade, and every owner has done the math on what an hour of quoting costs against a close rate that never gets above a certain number. Add the seasonality — the stretch from late spring through the first cold snap carries the year, and February is where nobody wants to look at the books — and the pattern is obvious: the busier you are, the more the unbilled work gets rushed. That is precisely where the chatbot shows up. Not because anyone chose AI, but because the quoting and the follow-up are the parts nobody is paid for. If you run one of these shops and want people to find you when they search locally, a complete listing on St Louis Near Me Directory is the low-effort half of that.
Would rather talk it through than read about it? See the AI workshops for business owners across the St. Louis metro on St Louis Near Me Directory, then bring the one document your staff already runs through a chatbot — the estimate, the review reply, the follow-up email — and leave with a rule for it.
Frequently asked questions
What are examples of shadow AI?
A quote drafted in a free chatbot on someone’s phone. A client spreadsheet uploaded to be summarized. A meeting recording run through a transcription tool nobody in the room approved. Review replies and social posts generated in bulk. A contract uploaded so somebody can ask what it means. The common thread is a personal login, no invoice, and no record at the company.
Can employers tell if you have used AI?
Generally no. OpenAI discontinued its own AI Text Classifier on July 20, 2023, citing low accuracy after it correctly flagged only 26% of AI-written text. Commercial detectors also produce false accusations against plain, careful human writing. An employer can see browser history or account activity on company equipment, but proving a specific paragraph was generated is not realistic.
Can an employee refuse to use AI?
In at-will states like Missouri and Illinois, an employer can generally require the use of a lawful tool as part of the job, and refusing can carry consequences. The usual exceptions still apply: a disability accommodation, a sincerely held religious objection, a union contract, or a licensed professional duty that requires personal judgment. Most refusals in practice are about accuracy or credit, and are worth hearing out before they become a discipline question.
Is IT acceptable to use AI in the workplace?
Yes, within limits your business sets in writing. What makes it acceptable is not the tool but the boundary around it: no confidential customer, employee or financial data pasted into a consumer account, a named human reading anything before it reaches a customer, and a note in the file saying it was used. Without those three, it is not the AI that creates the risk.
What is a good AI policy for a company?
A good one is one page, written in your own words, and specific enough to act on at four o’clock on a Friday. It names the data categories that may never be pasted, names the person who reviews customer-facing output, and states plainly that disclosing AI use carries no penalty. Long policies nobody reads score worse than a short one taped inside a cabinet door.
How do I create an AI policy for my company?
Start by asking staff what they already use, with amnesty attached, because you are documenting existing behavior rather than inventing rules. Write the never-paste list first, since it is the shortest and the most consequential. Name a reviewer by name. Add the one-line disclosure habit. Read it aloud at a meeting, take the objections, revise once. Two hours total is realistic for a small shop.
What is the 30% rule in AI?
It is a rule of thumb that circulates online rather than a research finding, and the versions people quote do not agree with each other. Treat any tidy AI percentage rule as a consulting framework until someone shows you the study behind it. The batch companion post on the AI rules people quote traces each one to its actual origin.
What can AI do for small business owners?
Realistically, it drafts and it summarizes. First-pass estimates, follow-up emails, review replies, listing descriptions, turning a long document into plain English. It does not know your pricing, your suppliers, your code requirements or your crew’s schedule, and it will guess confidently about all four. For a broader look at where it fits locally, see AI for St. Louis and how local businesses can actually use it.
Are people losing jobs due to AI?
No public dataset cleanly isolates AI as the cause of a layoff, and any figure claiming to is an estimate built on assumptions. What is visible in small local businesses is narrower: tasks moving, not roles disappearing — first drafts, summaries and routine replies. Physical, licensed and on-site work is a different question, handled in what AI will not replace in a local service business.
