'Shadow IT' and AI: Meeting Your Team's Digital Needs
From hidden spreadsheets to free AI accounts, unmanaged tech is a reality for the third sector. Discover how to tackle the risks and build an open digital culture.
When you work in the third sector, thinking on your feet to find quick solutions is a big part of the job. Frontline teams, volunteers, and project managers are brilliant at finding creative, rapid solutions to problems. If an official spreadsheet feels too slow for project tracking, someone might sign up for a free Trello board. If a report needs quick formatting, a staff member might drop the text into an online AI tool to clean it up in seconds.
These choices are made to save time. However, when staff download software, use cloud apps, or try digital tools without the knowledge of the central team, it is known as Shadow IT.
It is important to say right off the bat: Shadow IT is not inherently a bad thing. In fact, almost everyone does it, across every single industry. Quite often, these quick digital workarounds can help massively, speeding up tasks and introducing great new ways of working without causing any damage whatsoever.
According to guidance from the National Cyber Security Centre (NCSC), Shadow IT is rarely born out of bad intentions. It usually happens because staff are simply trying to get the job done and be productive. But while the drive to be efficient is entirely positive, the explosion of free, accessible AI tools has added a layer of secrecy to these habits.
The urge to hide AI use is incredibly common. Data from Microsoft and LinkedIn’s Work Trend Index highlights that 52% of people using AI at work are reluctant to admit using it for critical responsibilities, driven by the fear that it makes them look less capable or puts their job security at risk.
The goal isn’t to stop people from innovating; it’s simply about being aware of what tools are in play, understanding the risks, and ensuring that great ideas don't accidentally create hidden blind spots for your organisation.

The New Variable: Shadow AI
While Shadow IT still includes everyday actions like downloading a different file-sharing application or using a personal Canva account to design a quick event flyer, the rapid rise of accessible Artificial Intelligence (AI) has shifted the landscape.
"Shadow AI" occurs when staff use public generative AI tools - such as text builders, image generators, or automatic meeting note-takers - for everyday work tasks without checking the platform's background settings. For example, if a team member pastes a draft meeting transcript or a local community feedback form into a free, public AI tool (like the standard, free versions of ChatGPT, Gemini, or Claude) to generate a summary, that information can be absorbed into its public training system.
This means sensitive internal information could accidentally become searchable by anyone online before you even realise it, leaving charities open to the increased risk of data breaches. On top of that, using these platforms without the proper skills and training can easily lead to misinformation, bias, off-brand content, and a lack of trust between the organisation and its stakeholders.

Beyond Security: Why Unknown Tech Limits Your Growth
While data protection is a clear priority, letting Shadow IT and unmanaged AI tools operate entirely in the background impacts an organisations day-to-day operations in several other ways:
- Fragmented Information and Silos: When teams adopt different unapproved tools, information becomes scattered. One department might be using a hidden Slack workspace while another uses WhatsApp, or a team member might keep a standalone AI research repository entirely to themselves. This means critical project updates and valuable AI-generated insights are lost across separate platforms.
- Wasted Budgets: Without a centralised view, a charity might unknowingly pay for three separate premium software or AI subscriptions across different departments that all perform the exact same task (like graphic design, copywriting, or transcription).
- Lost Institutional Knowledge: AI tools learn and adapt based on your prompts and history. If a volunteer or staff member leaves your organisation and they were running a core project - or building highly customised AI prompts and workflows - via a personal, unknown account, the organisation loses access to all that history, data, and efficiency instantly.
Moving From "Lockdown" to Open Conversations
Trying to aggressively block or ban every unapproved website, app, or AI platform rarely works. It simply frustrates staff and pushes the behaviour further underground. A more practical approach involves understanding why the behaviour is happening and turning it into an opportunity:

If staff are turning to external workarounds or unauthorised AI platforms, it is a sign that your official tools or approval processes might be too slow or complex. Look at Shadow IT and AI adoption as direct, valuable feedback on exactly where your current systems are failing your team.

Ensure staff feel safe to tell you what apps and AI tools they are using. If you discover someone has quietly integrated an unmanaged AI note-taker into their meetings, don't reprimand them - ask them what administrative gap that tool is filling for them, and learn more about it.

If you notice that several people are using tools like ChatGPT/Claude/Gemini to make their lives easier, don't hide it. Bring it into the light by running an informal "skill-share" session in your next team meeting. Use this time to share helpful prompts, discuss the practical do’s and don’ts, and upskill the rest of the team so everyone benefits from that knowledge.

Instead of leaving staff to guess what is acceptable, introduce a clear, organisational AI policy. This doesn't need to be a dense, legalistic document; it just needs to outline which platforms are approved, how staff can request new tools, and explicitly state what data can and cannot be entered into public systems. It’s also a good idea to create an outward facing policy to show your organisation's transparency around AI use. Here’s an example.
Take Action: Assess Your Current Digital Landscape Together
Bringing hidden digital tools and AI applications into the light helps your organisation work more cohesively. It allows you to see what features your staff actually need to do their jobs, so you can provide them with the right supported, secure tools.
To help you get started, check out our Free AI Risk Assessment Tool for the Third Sector. While it focuses specifically on AI, the framework is incredibly simple to use and can easily be adapted to look at any digital tool your team uses. It is designed to help you start an open conversation, review digital tools together, and build a confident, connected digital workplace.
Want to Dig Deeper? Helpful Resources for Your Team:
- Read the Official Shadow IT Security Guidance on NCSC The official, easy-to-digest guide from the National Cyber Security Centre breaking down how to manage the risks of unvetted software while keeping your workplace productive and supportive.
- Explore 'The Hidden Use of AI in Charities' on Charity Digital An insightful analysis highlighting why more than 70% of staff use unapproved AI tools at work, the unique GDPR risks for third-sector data, and how to start open discussions with your board.
- Learn How to Build AI Skills Responsibly on Charity Digital A practical guide that explores how to safely transition from inconsistent "Shadow AI" habits into structured team training, balanced guidelines, and ethical content creation.
Like this post? Click below to share: