Shadow AI agents are tools and automations that staff have deployed without formal approval - and a security report published in September 2026 found 17,800 public AI add-ons drawing instructions from unverified external sources across 6.7 million installations. For UK SMEs, the issue is not whether to ban AI agents but how to know what is already running in your business and set boundaries that protect your data without removing the productivity gains.
What counts as a shadow AI agent?
Shadow AI follows the same pattern as shadow IT: employees adopt tools that solve immediate problems without a formal approval or security review. In 2026, this typically includes:
- Browser extensions that read and act on page content in your CRM, email, or accounting tools
- Slack or Teams apps connected to external AI services
- Zapier or Make automations staff built using personal accounts
- Third-party agents added to CRM, email, or accounting software through marketplace integrations
The September 2026 security research found that some public AI add-ons were impersonating trusted AI providers and were capable of running arbitrary code within the host application. CrowdStrike launched its Falcon Guardian product specifically to discover, trace, and block unapproved AI agents running on company devices.
Why does this matter under UK GDPR?
The data risk is direct. An AI add-on that pulls context from your CRM, email threads, or accounting records to answer a question is passing that data to whatever external service the add-on connects to. Under UK GDPR, your business is responsible for personal data processed by third-party tools acting on your behalf - whether or not those tools were selected by management.
The ICO's guidance on AI and data protection is explicit: if a third-party AI system processes personal data for your business, you are a controller or joint controller, you need a lawful basis, and you need a data processing agreement in place. An unapproved browser extension installed by one team member has none of those safeguards.
How to find out what is already running
You cannot govern what you cannot see. Four practical steps:
- Audit browser extensions across company devices. Most shadow AI enters through the browser. A full list of installed extensions across the team surfaces the majority of unapproved tools.
- Review connected apps in your core platforms. Google Workspace, Microsoft 365, Slack, and Salesforce each have an admin view of third-party apps granted access to data. Run that report.
- Check your automation platforms. If your business uses Zapier or Make, list every active automation and the account under which it was built. Automations built by individuals on personal accounts may not appear in company billing dashboards.
- Ask the team directly. A brief internal survey - "what AI tools are you using day to day?" - surfaces most of what technical audits miss, and opens the policy conversation with staff.
A lightweight AI governance policy for a UK SME
You do not need a thirty-page framework. Three components cover most of the risk:
- An approved tools list. A short, plain-English document stating which AI tools are approved, what data they may access, and what they may not do. Review it quarterly as the market moves fast.
- A lightweight request process. A simple way for staff to flag new AI tools they want to use, with a brief check on data access and security before approval. This takes minutes per request, not days.
- Clear data categories. A rule stating which data - customer personal data, financial records, employee information, confidential commercial data - may not be passed to any unapproved external service.
The goal is not to discourage AI use. Staff using AI agents are almost certainly doing so because the tools save them time - that productivity gain is worth preserving. Governance makes it safe to keep.
Frequently asked questions
What is shadow AI in a business context?
Shadow AI refers to AI tools, agents, and automations that employees have installed or built without formal approval. This includes browser extensions, Slack apps, Zapier workflows built on personal accounts, and AI integrations added to company tools without IT or management sign-off.
What are the GDPR risks of staff using unapproved AI tools?
Under UK GDPR, businesses are responsible for personal data processed by third-party AI tools on their behalf, regardless of who installed them. Without a data processing agreement and lawful basis in place, an unapproved AI tool processing customer or employee data creates direct regulatory exposure.
How do I find out what AI tools my staff are using?
Audit browser extensions across company devices, check connected-app admin views in Google Workspace, Microsoft 365, Slack, and Salesforce, review Zapier or Make for automations built on personal accounts, and run a brief team survey. The survey typically surfaces tools that technical audits miss.
How many AI add-ons have security risks in 2026?
A security report published in September 2026 identified 17,800 public AI add-ons across 6.7 million installations drawing instructions from unverified external sources. Some were found to impersonate major AI providers and were capable of running arbitrary code within the host application environment.
James Paulinson LinkedIn
Co-Founder, SMEAutomate
James Paulinson is the co-founder of SMEAutomate. With two decades across advertising, technology, and consulting, he focuses on helping boutique businesses and founders scale with AI-powered workflow automation.
Related articles
The Government Is Consulting on AI Staff Monitoring. What UK SMEs Must Know Before 30 September 2026
UK Job Postings Are Down 11%: How SMEs Are Using AI Agents to Cover the Gap
ICO's Free Data Protection Essentials Training: A Route to UK GDPR Confidence for Small Businesses
Get automation insights in your inbox
Practical tips for UK SMEs. 1–2 per month. No spam, unsubscribe any time.
