Free Security Consultation Button

Click Here to Schedule a
Complimentary Security Consultaion

My Tech Coach Cyber Security & Managed IT Services Logo
  • Cyber Security
    • CATO Networks
    • Next-Gen Endpoint Protection
    • Lucid Data Security
  • Managed IT Services
    • Managed IT
    • Office Networks
    • Workstation Set-Up
  • VoIP Phones
  • Pricing
  • About Us
    • Contact Us
  • Cyber News


Call Us Today

(603) 600-5375
My Tech Coach Cyber Security & Managed IT Services Logo
  • Cyber Security
    • CATO Networks
    • Next-Gen Endpoint Protection
    • Lucid Data Security
  • Managed IT Services
    • Managed IT
    • Office Networks
    • Workstation Set-Up
  • VoIP Phones
  • Pricing
  • About Us
    • Contact Us
  • Cyber News


Call Us Today

(603) 600-5375

Shadow AI: The Silent Security Breach Happening Every Day in 8 Out of 10 Small Businesses

by Greg Phillips

Shadow AI - The real world dangers hiding in your business - MyTech Team
Table of Contents show
1 Shadow AI Joined Your Team Months Ago,It’s Just Nobody Told You
2 What “Shadow AI” actually looks like in a small office
3 Four risks I see that the enterprise playbooks barely mention
4 My Tech Coach game plan: six moves, none expensive
5 The bottom line
5.1 You May Also Be Interested In...

Shadow AI Joined Your Team Months Ago,
It’s Just Nobody Told You

I want to share with you something I’m now seeing in almost every office I walk into around Concord and Manchester — from bookkeeping firms to medical practices to contractors. It’s called “Shadow AI,” and I promise you it’s already in your business, whether you invited it or not.

The term got on my radar through a recent CrowdStrike whitepaper aimed at big-company security teams (credit where it’s due — it’s a good read if you have a security department). But most of my clients don’t have a security department. You have a front office, a couple of laptops, Microsoft 365 or Google Workspace, and people trying to get work done.

My Tech Coach Cyber Security & Managed IT Services Logo

So, I went digging into the broader research to see how this plays out at our scale. Short answer: the numbers are eye-opening, and small businesses are more exposed than the big guys, not less.

What “Shadow AI” actually looks like in a small office

Shadow AI is just a fancy term for something simple: your team using AI tools — chatbots, notetakers, browser assistants, you name it — without anyone in charge knowing about it or signing off on it.

Nobody’s being sneaky. They’re just trying to get work done faster. But if you don’t know it’s happening, you can’t protect what company information is flowing out into the internet and being stored on third party servers where it is no longer under your control.

This is not a fringe thing. Microsoft’s 2025 Work Trend Index found that 78% of people using AI at work are bringing their own tools, outside of IT approval. A more recent UpGuard study put unapproved AI use at over 80% of workers — with half using these tools regularly.

In a 500-person company, that’s a policy problem. In a 10-person company, that’s your bookkeeper, your office manager, and probably you.

Here’s what it looks like in practice, from what I see in the field:
 

    • Someone pastes a client email thread into a free chatbot to “help draft a reply”
    • An AI notetaking bot quietly joins your Zoom calls and records everything
    • A browser extension summarizes web pages — and has permission to read everything in the browser, including your banking portal
    • Your accounting software, CRM, and Microsoft 365 quietly switch on AI features through a routine update

None of this comes from bad intentions. People are just trying to work faster. But research from CybSafe and the National Cybersecurity Alliance found that 38% of employees admit to sharing confidential data with AI platforms without approval.

Worse, a Menlo Security study found 68% of employees were accessing free AI tools through personal accounts — and over half of those were feeding in sensitive data.

Read that again: personal accounts. Not company accounts you control. Which brings me to the risks the big enterprise reports tend to gloss over.

Four risks I see that the enterprise playbooks barely mention

1)  The AI notetaker sitting in your meetings. This one is my biggest flag for small businesses right now, and it’s the piece the enterprise crowd almost completely skips.

Tools like Otter, Fireflies, and built-in meeting assistants are wonderful — and they also mean a third party is now recording, transcribing, and storing your conversations. Attorneys are warning that this can waive attorney-client privilege, run afoul of consent and wiretap laws (New Hampshire, by the way, is an all-party consent state), and turn what you thought was a private conversation into a permanent, searchable record stored somewhere outside your control.

Legal analysts also note that AI meeting summaries can be discoverable in a lawsuit, just like meeting minutes. If you’re a law office, a medical or counseling practice, or you ever discuss personnel matters on a call — this deserves a policy today.

2)  The data that leaves when an employee does. When someone uses their personal ChatGPT account for work, every prompt they typed — client names, pricing, that draft contract — lives in their account.

When they leave your company, it leaves with them. There’s no “revoke access” button for an account you never controlled. This is the small-business version of what the big companies call an “offboarding gap,” and almost nobody is thinking about it.

3)  The phone call that sounds exactly like you. AI-powered scams have gone from clumsy to genuinely scary.

In 2025, the FBI logged roughly $893 million in reported losses from complaints involving an AI component — and that’s almost certainly an undercount, because most victims never realize AI was involved.

Voice cloning is the one that keeps me up at night for my clients: research shows people can detect high-quality AI-cloned voices less than 30% of the time.

Picture your office manager getting a call that sounds exactly like you, asking her to push through an urgent payment. That scam used to require targeting a Fortune 500. Now it takes a few seconds of audio from your voicemail greeting or a Facebook video.

4)  The AI your vendors turned on without asking. Your accounting platform, your scheduling software, your CRM — everybody is bolting AI onto their products, often through license updates you never read.

Some of those features process your customer data in ways that were never part of the original deal. The enterprise answer is to buy expensive monitoring platforms. The small-business answer is simpler and free: ask.

Email your key software vendors two questions — “What AI features are active in our account?” and “Is our data used to train your models?” — and keep the answers on file. You’ll be shocked how few businesses have ever asked.

My Tech Coach game plan: six moves, none expensive

You don’t need an enterprise security platform to handle this. Here’s what I actually walk my clients through:

1)  Take the AI census. Ask your team — no blame attached — what AI tools they use and for what. Check which of your existing apps have AI features enabled. Fifteen minutes at a staff meeting gets you a list that most big companies would envy. (One 2026 analysis found the average enterprise has 14 AI tools in use while IT knows about 4 or 5. You can beat that number by lunchtime.)

2)  Write the one-page rules. Which tools are approved. What never goes into an AI tool: client names, financials, health information, passwords, anything under NDA. Who to ask before trying something new. One page. Most shadow AI exists because nobody ever set the rules, not because anyone broke them.

3)  Move people onto business-grade accounts. Don’t ban AI — your team will just use it on their phones. Paid business tiers of ChatGPT, Claude, Copilot, and the like typically don’t train on your data and give you admin control, so when someone leaves, their access leaves too. That single move closes the personal-account and offboarding problems at once.

4)  Set meeting-recording rules. Decide when AI notetakers are allowed, require that every participant is told and consents, and make them off-limits for anything involving legal, medical, HR, or strategy discussions. If a bot you don’t recognize joins your call — boot it and ask questions after.

5)  Adopt a verification habit for money and access. Any request to move money, change payment details, or share credentials gets verified through a second channel — a call to a number you already have on file, never the one in the message. Pair that with phishing-resistant multi-factor authentication and you’ve neutralized most of what AI-powered scammers can throw at a small office.

6)  Check what your AI assistants can see. Before switching on a copilot that reads “everything,” make sure your file permissions actually reflect who should see what. AI doesn’t create your permissions mess — it puts a search bar on top of it.

The bottom line

AI isn’t coming to your business someday. It arrived a while ago, through browser tabs, personal accounts, meeting bots, and software updates — and the research says it’s being used in your office right now, whether or not anyone’s told you.

The businesses that come out ahead won’t be the ones that ban it. They’ll be the ones that know where it is, set a few common-sense rules, and give their people a safe way to use it.

And if taking that AI census, sorting out permissions, or writing that one-page policy sounds like one more thing on an already-full plate — no worries. That’s exactly what a tech coach is for.

Call us today for a no obligation free consultation
(603) 600-5375

Let’s find out who — and what — is already working at your business.

  • Author
  • Recent Posts
Greg Phillips
Greg Phillips
Head Geek at MyTech Coach
Greg is an IT consultant and founder of MyTech Coach, a managed IT Service Provider focused on supporting small businesses. As President and chief consultant, he has over 25 years of professional IT and cybersecurity experience.

Greg has been put through the test from eccentric people in the sticks of Vermont; to small business owners with funky old PCs; to large college campuses such as Dartmouth where he worked in IT for over five years.

Greg has a Masters Degree in IT Business Management, as well as being Apple and Microsoft MCP certified.
Greg Phillips
Latest posts by Greg Phillips (see all)
  • Shadow AI: The Silent Security Breach Happening Every Day in 8 Out of 10 Small Businesses - July 20, 2026
  • 3 Cybersecurity Threats Small Businesses Should Be Aware Of Right Now - June 25, 2026
  • The #1 Cybersecurity Threat Most Small Businesses Never See Coming - June 8, 2026

You May Also Be Interested In...

Cybercriminals are stealing employee loginsThe #1 Cybersecurity Threat Most Small Businesses Never See Coming The 3 Cybersecurity Threats Small Businesses Should Be Watching Out For Right Now - My Tech Coach3 Cybersecurity Threats Small Businesses Should Be Aware Of Right Now Cybersecurity Steps Every Small and Midsize Business Should RequireThe Top 10 Cybersecurity Tips Countdown for Small Business Zero Trust Security Why Identity Management Is EverythingZero Trust Security: Why Identity Management Is Everything

Recent Posts

  • Shadow AI: The Silent Security Breach Happening Every Day in 8 Out of 10 Small Businesses
  • 3 Cybersecurity Threats Small Businesses Should Be Aware Of Right Now
  • The #1 Cybersecurity Threat Most Small Businesses Never See Coming
  • Who’s Living in Your Digital Basement?
  • Zero Trust Security: Why Identity Management Is Everything

Recent Comments

No comments to show.

Remote Support

Most small tech issues can be fixed securely remotely on your mac or PC or by logging into your cloud services, such as Microsoft Office 365 or Google’s GSuite.

Remote Support
Better Business Bureau Accredited A+ Rating

Cybersecurity News

3 Cybersecurity Threats Small Businesses Should Be Aware Of Right Now

3 Cybersecurity Threats Small Businesses Should Be Aware Of Right Now

CONTACT US NOW

(603) 600-5375
Send Us A Message

© Copyright 2025 MyTechCoach Cyber Security & Managed IT Services – All Rights Reserved | Website Design by ClickThru Digital Marketing, SEO & Website Design