
Shadow AI is rife within UK organisations, but banning AI won’t stop your salespeople using it. Sam Whisker, CTO at Bid King, explores the risks of unsanctioned AI use among commercial teams, and offers practical advice to regain compliance, without jeopardising productivity, morale and KPIs.
Somewhere in your sales team right now, a colleague is pasting a customer email into a chatbot. Someone else is feeding a call recording into an AI transcription service, and another is uploading a draft proposal to see whether it can be tightened up. None of them has asked permission, yet most believe they are doing exactly what their employer would want, which is getting more work done.Â
And while sales directors and chief commercial officers would like to hope this isn’t happening in their departments, shadow AI – the use of AI tools at work without formal approval or oversight – is no longer an edge case. It is the norm. It is prevalent almost everywhere.Â
The real question leadership teams need to answer is whether they understand how far it has gone.Â
Shadow AI is now the defaultÂ
Accessibility has been a driving force behind the rise of shadow AI. A few years ago, new technology meant procurement, IT involvement and an implementation project. Today an employee can open a browser, create an account and be using an extremely capable AI tool within two minutes.Â
Research appears to underpin this view. Adaptive Security found that 80% of employees already use unapproved generative AI applications at work, and Thomson Reuters reported that nearly half of professionals using AI would carry on even if their employer prohibited it. Gartner’s survey found that 69% of cybersecurity leaders say prohibited tools are still being used anyway. Â
Most senior teams now accept that their people use AI. What they rarely know is the scale or the specifics. There is a wide gap between “our people use ChatGPT” and knowing if someone has connected an AI tool directly to the CRM – and this is where the risk sits.Â
Why sales teams are ahead of the curveÂ
Sales is one of the functions where AI pays back most obviously. Salespeople spend a large proportion of their time conducting work relating to selling, rather than selling itself – researching prospects, updating CRM records, summarising calls, building proposals, diarising follow ups and conducting the check-ins themselves. AI strips out much of that admin. Used well, it gives sales professionals more time with prospective customers and helps them respond faster and more consistently to the opportunities they’re targeted to close.Â
That is precisely why AI adoption is happening whether or not the business has sanctioned it. When a tool saves an hour a day – and we’ve become accustomed to using these tools everyday in our personal lives – nobody waits for a policy to catch up. Â
This is rarely a sign of a rogue workforce. It is indicative of people trying to hit their KPIs.Â
Where is the biggest risk?Â
The biggest risk associated with the shadow AI surge is data leakage, and we cannot ignore that sales teams hold some of the most commercially sensitive data in the entire business. From customer details and contractual specifics, to prospect lists, pricing and proposals, sales teams ‘own’ it all. Â
But with rich data, and multi-step sales processes, comes a lot of workload. These data pools are therefore exactly the areas that salespeople instinctively want AI to help with. Â
Consider the salesperson who thinks, “I’ll upload this proposal and ask AI to sharpen it.” They are unlikely to consider where that document is stored, who can access it, how long it is retained, or whether the service has ever been through a security review. Multiply that by every rep, every week, and you have a steady, invisible flow of pricing and customer information into services you have never assessed. Samsung engineers leaked sensitive corporate data through ChatGPT in 2023, and it was a wake-up call for many executives. Â
There are two further problems. The first is accuracy – AI can produce output that is confident, plausible and wrong, and an invented capability or misquoted figure in a proposal immediately becomes a commercial and contractual liability once it reaches a customer. Â
The second is visibility. If the business doesn’t know which tools are in use, it is impossible to assess their security, compliance or contractual implications. Those all-important guardrails that IT directors and chief information officers would normally insist upon, are non-existent. In fact, Optro’s research suggests only 25% of organisations have comprehensive visibility into how employees use AI day to day. Â
Why banning it won’t workÂ
It is important to stress that none of this is an argument against AI. The danger is not the technology itself. It is unmanaged technology.Â
So, the instinctive response is often to prohibit its use, but this rarely works. If a tool genuinely saves people time, they will find a way to use it, on personal devices and personal accounts, for example. In these cases, the shadow AI simply becomes even harder to spot. Â
The aim should be to move AI use from something happening invisibly across the organisation to something the business understands and can manage. Â
Three steps to greater visibility and controlÂ
Of course, every business is different. But these three steps will get you much of the way there. Â
- Find out what people are already using.
Do not open with a ban, or with an audit that feels like an investigation. Talk to your sales teams, ask which tools they use and what problems those tools solve. Also make it safe to answer honestly. Â
You will likely uncover some genuinely valuable use cases that the business can consider adopting formally, along with a few that need to stop immediately. Either way, the bones of a plan will begin to form.Â
- Set simple rules on data.
Employees need to know what they can and cannot put into an AI system, and the rule has to be one they can remember as a 30-page policy will not be read. Start with something as plain as this – public information is fine, and confidential customer data is off limits unless the tool has been specifically approved. Â
Clear boundaries will do more than any lengthy document. Also don’t forget to explain why this is so important, to encourage greater buy-in.Â
- Give people approved tools. I
If employees are getting real value from AI, give them a safe route to it. Choose industry-specific products that deliver proper control over data, access and retention, and check the privacy and administrative terms before rollout. Â
Then train people to use them well, because a sanctioned tool nobody understands will lose out to the free one in the browser tab. If the safest option is also the easiest option, compliance will come naturally. Â
Don’t be comforted by invisibility Â
Even if you can’t see AI in action within your organisation, your sales team is already using AI. That is likely not a failure of discipline, a disrespect for company policy or an intentional breach of customer trust. Â
But it is evidence that the tools work and that your people want to use them to heighten their performance. The leaders who bring that activity into the light, set sensible boundaries, and give their teams something better than a workaround, will inevitably boost morale, productivity, proposal creation numbers, and deal win rate. Â
Those who reach for a ban may feel some immediate comfort, but they will be the last to know what is happening in their own business.Â


