Sidekick Digital logo Sidekick Digital Book a Discovery Call
Home Solutions Industries Resources About Contact Book a Discovery Call
Responsible AI

Your Staff Are Already Using AI Tools You Haven't Approved

July 27, 2026 · Sidekick Digital

Intuit's 2026 AI Impact Report, based on more than 34,000 survey responses from small and mid-sized business owners, found that 77 percent in the US now use AI regularly. That's not a niche behavior anymore, it's the norm. What the same report keeps coming back to is the gap sitting right behind that number: the vast majority of those businesses have nothing written down about what staff are actually allowed to do with these tools.

We hear a version of the same story from almost every owner we talk to. Someone on the team found a tool that saves them an hour a day, everyone quietly adopted it, and nobody ever sat down to decide what's safe to type into it. That gap has a name now, shadow AI, and this year there's real data on what it costs when nobody closes it.

What the breach data actually shows

Verizon's 2026 Data Breach Investigations Report found that unapproved AI use is now the third most common non-malicious insider action showing up in breach investigations, with detections up roughly fourfold from the year before. The report puts the number of employees who are now regular AI users, sanctioned or not, at 45 percent of the workforce. Of those, 67 percent are doing it through personal, non-corporate accounts on company devices, which means the business has no contract, no data agreement and no visibility into where that information ends up.

The part worth sitting with is what Verizon found people were actually uploading to these unsanctioned tools. Proprietary source code topped the list by a wide margin, followed by images and structured business data, with research and technical documentation close behind. None of this is malicious. It's a developer pasting a code snippet to debug it faster, or someone pasting a client spreadsheet into a chatbot to reformat it. The intent is convenience, not harm, and that's exactly why banning tools outright rarely works. It doesn't remove the convenience, it just removes your visibility into how staff are getting it.

Why vetting the tool matters as much as the policy

A written policy answers what staff can do. It doesn't answer whether the tool they're using is safe to use at all, and that second question gets skipped constantly. Before a tool gets approved, it's worth knowing three things about it: where the data you enter actually gets stored, whether that input is used to train the vendor's models by default, and whether there's a real way to have your data deleted if you stop using the service. Free consumer tiers of major AI products are frequently the worst on all three counts, which lines up with the BlackFog and Sapio Research study on shadow AI showing that a majority of unapproved AI use happens specifically on free versions of these tools rather than paid, business-tier accounts that come with actual data agreements.

This is where a lot of small businesses talk themselves out of doing anything. Vendor vetting sounds like a project for a company with a procurement department, not a nine-person shop. In practice it's a short conversation you have once per tool, not an ongoing program: read the vendor's data retention terms, ask directly whether inputs train their models, and pick the paid or business tier when one exists, since that's usually where the actual contractual protections live.

The short version that actually gets written down

A workable AI policy for a small business fits on one page and covers three things: which tools are approved for work use and on which tier, what categories of information can never be pasted into any AI tool, meaning client data, financial details, anything under an NDA, and who signs off on AI-assisted work before it reaches a client or goes into a filing. That third piece matters more than people expect. A human reviewing the output before it leaves the building catches the mistakes that pasted-in client data or a hallucinated detail would otherwise turn into an actual incident.

None of this requires slowing down how your team works. It requires deciding, on purpose, the things your team is currently deciding by accident, one paste at a time.

← Back to all posts

Close the gap between AI use and AI policy

Sidekick Digital helps small businesses and municipalities write the plain-language AI policy and vendor checks their actual usage already needs.

Book a Discovery Call