Resources

Shadow-AI visibility checklist

"Shadow AI" is AI use a practice hasn't approved, doesn't know about, or hasn't thought through. Not because staff are being careless, but because nobody has asked. This checklist is the asking.

A hand ticks a box on a Cast & Rule checklist on a clipboard, a laptop and papers on the desk behind.

About this checklist

What the evidence actually shows

No checked survey of UK accountancy measures how often staff paste client data into public AI tools. The evidence below is real, but wider than accountancy. Read the limits column before quoting a figure.

The evidence, source by source

Show all 4 evidenceHide evidence
Evidence on AI use and confidentiality risk, with its limits stated alongside
SourceFindingLimits
PagerDuty / Wakefield, 2026 Shadow AI Survey34% of respondents (1,250 office professionals at organisations with $500m+ revenue, UK n=250, fieldwork April 2026) reported entering customer data or information into public AI tools; 66% used tools they believed were not permitted.An international survey, paid for by a supplier, of office professionals in general, not UK accountancy. "Customer data" isn't the same as accountancy client data.
Salesforce / YouGov, Generative AI workplace survey89% of UK respondents (of 14,000+ across 14 countries, October 2023) reported no clear generative-AI guidelines at work; 84% reported no formal AI training.Shows a gap in rules and training, not a measured rate of client-data copying.
ICAEW Practice Assurance Monitoring Report 2025Of the larger firms ICAEW held AI discussions with during 2024 monitoring, AI policies commonly covered confidential data and access controls, but only 20% monitored staff access to AI tools and 22% restricted open-source AI tools.Covers the larger firms discussed during monitoring visits (ICAEW doesn't give the number), and describes firms' controls rather than staff behaviour.
ICAS study at a mid-tier UK firm52% of respondents in a named UK firm case study (published 17 March 2026) raised client-data privacy and confidentiality concerns about AI.A study of one firm, not a measurement of the whole sector.

The checklist

Discover

  • Ask every team, not just IT, which AI tools they already use for any part of client work.
  • Check browser extensions and mobile apps, not only desktop software. A lot of shadow AI arrives this way.
  • Look at what free-tier AI tools staff can reach without a company card or sign-off.
  • Ask new starters which AI tools they used at their last job, and assume some habits came with them.

Assess

  • For each tool you find, work out whether confidential client information has gone into it, even once.
  • Check each tool's terms for whether it trains a model on the data it is given.
  • Identify where each tool processes and stores data, and for how long.
  • Note which tools have no written answer to the questions above. That's a finding in itself.

Control

  • Decide, tool by tool, whether it's approved, restricted to non-confidential use, or blocked.
  • Write the decision into the practice's AI-use policy, not into an email that will be forgotten.
  • Set out clearly what must never be typed into an unapproved tool, in plain words.
  • Give staff an approved alternative for the task they were using the shadow tool for. A ban with no alternative just pushes the behaviour further underground.

Evidence

  • Keep a dated record of the exercise itself: what was asked, of whom, and when.
  • Keep the approved-tool list up to date, and date it at each review.
  • Record any incident where confidential information went somewhere it shouldn't have, and what was done about it.
  • Repeat the whole exercise at a set interval, not only after something goes wrong.

Train

  • Walk staff through the practice's AI-use policy in plain terms, not as a document to sign unread.
  • Explain why the rule exists (confidentiality, not distrust of staff), so it's followed rather than worked around.
  • Make it easy and blame-free to report a mistake, so problems surface while they're still small.
  • Repeat the training when the policy changes, not only once at induction.

Download the checklist and worksheet

Free to download and adapt, with no sign-up.

Update notices

Update notices for this checklist

We use your details only to answer you. The downloads above need no sign-up.

Questions partners ask

Frequently asked questions

What counts as "shadow AI"?

Any AI tool used in client work that the practice hasn't formally reviewed or approved. Often taken up with good intentions, by staff trying to work faster.

Do I need special software to run this checklist?

No. It's an exercise a practice can run with conversations, a spreadsheet and this page.

Is a 34% or similar figure true for UK accountancy specifically?

Not on the evidence checked here. The surveys above show real risk and a gap in the rules across office workers in general. No checked figure for client-data copying in UK accountancy exists yet.

One practice first

Start with one workflow, over six weeks, with us alongside

For a UK practice of 5 to 20 staff, with a partner who'll own the review. We run one workflow, measure it before and after, and agree in writing how it ends. Send an enquiry or email us today.

Contact us