home  /  governance & policy  /  approved tools & shadow AI
governance · ai for legal practice

Approved tools and shadow AI.

Every firm with a restrictive policy and no good sanctioned tool has shadow AI. The only variable is whether it knows.

begin here

Where is your firm?

Start a conversation with the AI Adoption Concierge, already scoped to approved tools & shadow AI. Pick a starting point, or describe your situation directly.

AI Adoption Conciergeapproved tools & shadow AI · orientation, not legal or ethics advice
Tell me what the firm has approved and what visibility you have today. I'll help you work out where the gaps are — usually they point at a task nobody was given a tool for.

Shadow AI is the use of unapproved tools for firm work, and it is the predictable consequence of a gap between what people need and what they have been given. The tools are free, they are capable, and they are one browser tab away on a personal device the firm does not manage. A policy that prohibits without providing an adequate alternative does not eliminate the usage; it removes the firm's ability to see it, govern it, or know what client material has left. Firms that treat this as a discipline problem tend to make it worse. Firms that treat it as a product gap — what were people trying to do, and what would they have used if we had offered it — tend to close it.

mechanisms

Why it happens.

Almost never defiance. Almost always friction, a gap, or not knowing there was a rule.

The approved tool is awkward

Extra steps, another login, documents that must be moved. Friction paid dozens of times a day loses to a tab.

No approved tool for the task

The register covers research but the need was summarising. People solve the problem they have.

Nobody knew the rule

The policy exists and was not read, which is a communication failure rather than a compliance one.

Personal devices

Work done on equipment the firm does not manage and cannot observe.

Deadline pressure

The rule is known and set aside at midnight, which is exactly when the risk is highest.

No visibility either way

The firm cannot tell compliance from non-compliance, so both look identical from the centre.

methodology

What the evidence shows — and what we examine.

How firms close the gap.

Ask what people are usingAnonymously and without consequence. The answers are usually more surprising than the policy anticipated.
Fill the gaps in the registerApprove something adequate for the tasks people are actually doing, or the shadow use continues.
Establish visibilityNetwork and identity signals that show which services are in use, within what the firm may properly monitor.
Make the rule knownRepeatedly and at the point of use, not once in an all-staff email nobody opened.
what's at stake

What shadow use exposes.

The confidentiality risk is the serious one; the loss of visibility is what makes it unmanageable.

client confidences in unvetted tools material under terms nobody read no record of what was used or when a policy the firm cannot show was followed outside counsel guideline breaches unverified output reaching a filing

Treat it as a product gap, not a discipline problem.

People reaching for an unapproved tool are telling you what the approved set does not do. Firms that respond by enforcing harder get quieter shadow use. Firms that respond by closing the gap get compliance almost for free.

common questions

Shadow AI — practical questions.

How do we find out what people are actually using?

Ask, in a way that carries no consequence, and pair it with whatever technical visibility the firm properly has. An anonymous survey stating plainly that the purpose is to fill gaps rather than to discipline anyone gets remarkably candid answers — people generally know they are working around something and would rather not. Network-level and identity-provider signals show which services are reached from firm systems, though not what went into them, and monitoring has its own limits and obligations that the firm should take advice on.

What if someone has already put client material into a consumer tool?

Establish the facts quickly — what material, which tool, when, and what the terms of that service permit regarding retention and training. Then take advice on the firm's obligations, which may include client notification depending on the material, the jurisdiction and any contractual commitments. Handle it as a confidentiality incident rather than a disciplinary one at first: the immediate priority is understanding exposure, and a response that leads with blame reliably ensures the next occurrence is not reported.

Is a personal-device ban the answer?

Rarely enforceable and frequently counterproductive. Firms with genuine mobile working cannot practically prevent someone opening a browser on their own phone, and a rule that cannot be enforced erodes the credibility of the rules that can be. The more effective controls are making the approved tools available on the devices people actually use, being unambiguous about what may never be entered anywhere, and ensuring the sanctioned option is good enough that reaching past it is not tempting.

How current does the approved list need to be?

Current enough that it does not itself create shadow use. A register listing tools the firm evaluated a year ago, with nothing added since, tells people the process has stalled and that asking is pointless. Firms that keep it useful review it on a short cycle — quarterly at first — and publish a route for requesting an addition with a commitment to answer within a defined period. The route matters as much as the list: an unanswered request becomes an unapproved tool.

related

Related specialization areas & resources.

Find out what is actually in use.

Describe your approved set and what you can see. The Institute will help you close the gap.

AI adoption conciergeorientation · not legal or ethics advice
Tell me what the firm has approved and what visibility you have today. I'll help you work out where the gaps are — usually they point at a task nobody was given a tool for.