Is shadow AI a real risk for a 500-person company?
What unapproved AI use actually looks like at 500 people, the three exposures that matter, and a self-check drawn from the audit's Governance pillar.
By Carl Chessum
Yes, and the reason is arithmetic rather than alarmism. Salesforce’s 2026 Workforce AI Survey found 67% of employees use AI tools at work while only 18% of organisations report having formal AI security policies in place (source). Apply the first number to 500 people and you get roughly 335 employees using AI in some form. Apply the second to your own company and there is a better than four-in-five chance you have nothing written down that tells them what is and is not allowed. That gap is shadow AI. It is not a future risk. It happened at some point in the last eighteen months and nobody sent you a memo.
The more useful question is not whether it exists but which parts of it can actually hurt you. There are three that matter at this size: customer data sitting in tools nobody approved, business decisions being made with no record of how they were reached, and the absence of any document you can point to when a client, an insurer or a regulator asks what your policy is. Everything else in the shadow AI conversation is noise borrowed from enterprise security content written for people with a SOC and a DLP budget. You have neither. You have an IT Director with three other jobs.
What shadow AI actually looks like at 500 people
Shadow AI is employees using AI tools the business has not approved, procured or configured. At a 50-person company it usually means the founder’s ChatGPT account. At 10,000 it means a procurement problem with a named owner and a discovery tool. At 500 it means something more awkward than either: enough usage to be material, not enough structure to see it.
PagerDuty’s 2026 international Shadow AI Survey, run across 1,250 office professionals at companies with $500 million or more in annual revenue in Australia, Japan, the UK and the US, found two-thirds had used unauthorised AI tools at work (source). That is not a survey of startups. Those are companies with legal departments.
In practice, at your size, it looks like this. A salesperson pastes a prospect list into a free tool to draft follow-up emails. A finance analyst uploads a management pack to summarise it before a board meeting. Someone in HR runs candidate CVs through a model to shortlist. A developer pastes a chunk of production code into a chat window to debug it. None of these people are being reckless. They are doing the thing you have been telling them to do since the board started asking about AI, in the only way available to them, because the approved route does not exist.
The usage is invisible for a specific and boring reason. Free-tier AI tools are browser-based, consumer-grade and require no procurement. There is no invoice, so finance never sees it. There is no install, so IT never sees it. There is no licence, so nobody renews it. The first time most mid-market companies get a number for their AI usage is when someone finally asks.
Exposure one: customer data in tools you have no contract with
This is the one with teeth. When an employee pastes customer records into a consumer AI tool, you have made a disclosure of personal data to a third-party processor with whom you have no data processing agreement, no defined retention period and no stated position on whether the input is used for training. Under UK GDPR that is your problem, not the employee’s. You are the controller.
IBM’s 2026 Cost of a Data Breach Report, based on Ponemon Institute research across 602 breached organisations, found shadow AI-linked security incidents rose from 20% to 43% of AI-related breaches year over year (source). The share more than doubled in twelve months. Whatever the underlying cause, the direction is not ambiguous.
The mid-market twist is that you probably cannot answer the follow-up question. If a client asks you, in writing, whether their data has been processed by a generative AI system, can you answer it? Not “we don’t think so”. Answer it. Most 500-person companies cannot, and the reason has nothing to do with AI. It is the same reason they struggle with the first Data question in the audit, the one about producing a clean accurate list of your best 500 customers on demand. If you do not know where your customer data lives, you cannot know where it has been sent.
Exposure two: decisions made with no record of how
The quieter exposure, and the one nobody puts in a risk register. Someone used a model to shortlist candidates, to price a renewal, to draft a clause, to prioritise a debtor list. The output went into the business. The prompt, the model version and the reasoning went nowhere.
This matters at 500 people in a way it does not at 50, because at 500 you have enough separation between the person making the decision and the person accountable for it that the reasoning has to survive a handover. When a decision is challenged six months later, the normal recourse is to ask the person who made it. If the honest answer is “the tool suggested it and it looked right”, you have a decision with no defensible basis and no audit trail.
There is also a subtler cost. Unlogged AI use produces no learning. Nobody can tell which prompts worked, which tools are actually useful, or whether the sales team’s AI-drafted emails perform better or worse than the old ones. You end up with widespread adoption and zero evidence, which is the same structural failure that kills AI pilots before they scale: activity nobody baselined, so nobody can defend it at budget time.
Exposure three: nothing to point at
The third exposure is the cheapest to fix and the most commonly cited when something goes wrong. You have no policy.
When a client’s procurement team sends a security questionnaire with an AI section, and they now all do, you are answering it from memory. When your insurer asks about AI use in the renewal, same. When an employee does something genuinely careless with customer data, your disciplinary position is weak, because you never told them not to. “Everyone knows” is not a control.
The 18% figure from the Salesforce survey is worth sitting with. Four in five organisations have no formal AI security policy while two-thirds of their people are using the tools. That is not a governance failure by a handful of laggards. That is the normal state of the market, which means the bar for being demonstrably better than average is low. A two-page document naming approved tools, banned data categories and a single owner puts you ahead of most of your peer group by the end of the week.
The self-check, drawn from the Governance pillar
The audit’s Governance pillar asks five questions. Three of them bear directly on shadow AI, and you can run them yourself over a coffee. Answer honestly, in writing, not in your head.
One. Name the person accountable for AI risk. Not a committee. A person, with a job title, who would be the one in the room if something went wrong. If you cannot name them in under five seconds, you do not have one. Deloitte’s 2026 Global CSO Survey found 65% of chief strategy officers do not own the top strategic decisions in their own function (source), which should tell you how thin ownership gets when nobody assigns it deliberately. We have written separately on who owns AI outcomes in a company and the answer is rarely who leadership assumes.
Two. Produce the policy. If it exists, someone should be able to send you the document inside ten minutes. If it takes longer, your people cannot find it either, which means functionally it does not exist.
Three. State which tools are approved. Write the list. Then ask two people in different departments to write theirs. Compare. The gap between your list and theirs is your shadow AI surface area, measured for free.
Four. Say what data must never go into an external AI tool. Customer records? Unreleased financials? Source code? Candidate data? If you have not named the categories, you have not set a boundary, and a reasonable employee will draw their own.
Five. Say how you would know if the policy were breached. This is the one that separates a written policy from an enforced one. Most companies at this size have no answer, and that is fine to admit. Admitting it is better than assuming you would find out.
What you cannot know without asking your own people
Here is the honest limit of this article and of every survey in it. The 67%, the two-thirds, the 43%: none of them tell you what is happening in your building. They tell you what is likely. They are a prior, not a finding.
The only way to get a real number is to ask, and the asking has to be structured so the answer is not a lie. If you send an all-staff email asking who has been using unapproved AI tools, you will get a very reassuring response and it will be worthless. People do not confess to a policy they were never given. Run it as an anonymous survey, or better, as a no-blame amnesty: tell people you want to know what they are using so you can make the useful ones official, and mean it. You will get a more accurate picture and a list of use cases that are already proving their worth, which is a considerably better starting point than a ban.
And note what self-reporting cannot do. It will not surface the tools people have forgotten they used, or the ones they do not think of as AI because they are embedded in software you already own. That is a limitation worth stating plainly rather than papering over.
If you want a structured version of this, the free AI readiness audit is 30 questions across six pillars, takes 7 minutes, and gives you a score out of 120 with a band per pillar and a short synopsis. Governance is the sixth pillar. Every answer is self-reported, which is the point: the score reflects what you actually know about your own business, and a low Governance band usually means the honest answer to “who owns this” is nobody.
Shadow AI at 500 people is not a crisis. It is an unmanaged position. The difference between the two is whether you have looked.