Whether or not your organisation has “adopted AI”, your staff almost certainly have. Surveys consistently show that a large share of UK employees now use generative AI tools like ChatGPT, Copilot and Gemini in their day-to-day work — and that much of this use is invisible to their employers. The industry has a name for it: shadow AI. It’s the modern equivalent of staff emailing spreadsheets to personal accounts, except the data is going into systems the business has never assessed.
Why this is a compliance issue, not just a technology one
The UK has no single “AI Act”. Instead, AI use at work sits under laws that already exist — and that already bite:
- Data protection. Pasting customer details, employee records or commercially sensitive information into a public AI tool is a disclosure of personal data. Under UK GDPR and the Data Protection Act 2018, the employer remains responsible for where that data goes. The ICO has been clear that data protection law applies in full to AI.
- Confidentiality and contracts. Client agreements and NDAs rarely contemplate information being processed by third-party AI services. A well-meaning employee summarising a client document with a free tool may put the business in breach.
- Accuracy and accountability. Generative AI produces confident, fluent and sometimes wrong output. When staff paste that output into reports, quotes, safety documents or customer communications without checking, the organisation owns the error.
- Employment fairness. Using AI in recruitment, monitoring or performance decisions engages discrimination law and data protection rules on automated decision-making.
Banning it doesn’t work
Some organisations have responded with blanket bans. In practice, bans push AI use further into the shadows — onto personal phones and home accounts — where the business has no visibility at all. The more durable answer is the same one that works for every other workplace risk: a clear policy, sensible rules about what may and may not go into which tools, and training so staff actually understand why.
What staff need to understand
Effective AI awareness training doesn’t need to make anyone a machine learning engineer. It needs to give every employee a working grasp of: what generative AI is and how it handles the information you give it; the difference between approved enterprise tools and public free tools; what must never be entered into an AI system (personal data, client confidential information, credentials, unpublished financials); how to sense-check AI output before relying on it; and where the organisation’s policy draws its lines. Managers additionally need to understand the risks in using AI for people decisions.
AI in the Workplace Awareness Training
Our online AI in the Workplace Awareness Training course covers exactly this ground: how AI tools work in plain English, the practical benefits and the real risks, data protection and confidentiality rules, spotting AI errors and bias, and the habits of safe, productive AI use. Staff complete it online in around an hour and receive a certificate — giving you evidence that your workforce has been trained to use AI responsibly, which is fast becoming something clients, insurers and auditors ask about.
It pairs naturally with our GDPR Refresher & Cyber Security Awareness course — because the organisations handling AI well are invariably the ones that already take data protection seriously.


Leave a Reply