Your board approved an AI pilot last quarter. Somewhere in procurement, a category manager is pasting supplier pricing into a free ChatGPT account to draft a negotiation email. In the warehouse office, an ops planner is uploading a carrier rate sheet to a personal Claude account to "tidy it up." In finance, someone is running unreconciled deduction data through an AI tool nobody vetted, because it's faster than the reporting templates.
None of this shows up in your AI programme dashboard. All of it is now, by definition, your board's problem.
This is shadow AI and for UK mid-market CPG and logistics operators, it's quietly become one of the highest-probability, least-visible risks on the books.
What is shadow AI?
Shadow AI is the use of AI tools public chatbots, browser extensions, unreviewed features bundled into existing SaaS platforms by employees without IT approval, security review, or governance oversight. It's distinct from "shadow IT" in one critical way: shadow IT put a file in the wrong folder. Shadow AI sends your data to a third-party model provider, where it may be retained, logged, or used to train future models outside your control and, often, outside your knowledge.
It isn't a discipline problem. It's a convenience problem. Employees adopt these tools because they're faster than the sanctioned alternative, and most have no idea they're creating exposure.
The numbers your board needs to see
The scale of this has moved fast in 2026:\
| Metric | Figure | Source |
|---|---|---|
| Employees on corporate devices regularly using AI tools | 45% | Verizon 2026 Data Breach Investigations Report |
| Office staff at large firms who used AI despite believing it was prohibited | 66% | PagerDuty 2026 workplace AI survey |
| UK employees reporting unsanctioned AI tool use | 55% — vs. only 4% of executives who doubt their own visibility into it | Okta / Apprize360 research, via The Register |
| Employees who have entered customer data into a public AI model | ~1 in 3 | Industry survey aggregate |
| Year-on-year growth in shadow AI detections inside enterprises | 4x — now the 3rd most common non-malicious insider risk | Security vendor telemetry |
| Breaches involving shadow AI, 2026 vs. 2025 | 43%, up from 20% the prior year | IBM Cost of a Data Breach Report 2026 |
| Additional average breach cost when AI is involved | ~$1 million on top of baseline breach costs (global average breach cost: $4.99M, +12% YoY) | IBM Cost of a Data Breach Report 2026 |
| Breached organisations with no proper access controls on the AI tools involved | 92% | IBM Cost of a Data Breach Report 2026 |
| Breached organisations with no AI governance framework at all | 68% | IBM Cost of a Data Breach Report 2026 |
Put simply: the tools are already inside your business, most leadership teams overestimate their own visibility into it, and when something goes wrong, the financial and regulatory exposure lands well above where a normal IT incident would.
Where it actually shows up in CPG and logistics operations
This isn't abstract. In the businesses AI Navi works with, shadow AI risk clusters around a handful of very specific, very ordinary workflows:
- Retailer and EDI data. Category and RGM teams routinely handle Nielsen/NPD extracts, retailer scorecards, and EDI feeds — exactly the kind of structured, commercially sensitive data that gets pasted into a public chatbot "just to summarise it." (See our work on revenue growth management for how this data is meant to be used.)
- Trade spend and deduction files. Finance and revenue teams working through trade spend waste and deduction backlogs are under pressure to move fast, and unreconciled spreadsheets full of retailer and pricing data are a common candidate for an AI shortcut.
- Supplier and carrier contracts. Procurement and logistics ops teams uploading rate cards, SLAs, or contract drafts to AI tools for redlining or summarisation often the same systems covered in our guide to integrating AI with WMS, TMS and carrier systems and the same contracts covered by confidentiality clauses that say they shouldn't leave the building.
- Pre-launch NPD and R&D concepts. Product development teams using AI to accelerate concept testing and R&D timelines, sometimes before formulations, pricing, or launch dates are public.
- HR and workforce data. Especially in businesses running frontline logistics and warehouse teams navigating AI-driven labour automation, where scheduling, performance, or restructuring data is sensitive and often poorly governed even before AI enters the picture.
None of this requires malicious intent. It requires a Tuesday afternoon deadline and a tool that's faster than waiting for IT.
Why this is now a board issue, not an IT issue
Three things are converging on mid-market UK operators specifically:
- Regulatory deadlines are now dated, not theoretical. The EU AI Act's remaining obligations land in August 2027 — see our own EU AI Act compliance guide — and the UK's own Cyber Security and Resilience Bill is tightening expectations on documented governance — not just for AI-native companies, but for any business processing customer or supplier data through third-party AI tools.
- Insurers are starting to ask. Cyber insurance renewals increasingly probe AI usage and governance documentation. "We don't really know" is becoming an expensive answer.
- Accountability has shifted upward. IBM's 2026 research found that a large share of breached organisations had no AI access controls or governance framework at all when the incident happened. That gap doesn't stay with IT — it becomes an executive and audit-committee liability the moment a regulator or insurer asks the question directly, which is exactly the exposure our AI governance audit readiness framework is built to close.
For a £100M–£2B CPG or logistics business already juggling AI pilot pressure, board ROI expectations, and EU AI Act compliance work, shadow AI is the risk most likely to be genuinely unmanaged — not because leadership doesn't care, but because it doesn't show up on the pilot tracker, the vendor contract list, or the governance audit unless someone specifically goes looking for it.
A 90-day starting point
You don't need a six-month security programme to close the biggest part of this gap. A focused first pass looks like:\
- Weeks 1–2 — Find out what's actually being used. A lightweight discovery pass (network/SaaS logs, a short anonymous staff survey, or both) to establish real usage against the 96%-confidence-vs-55%-usage gap most leadership teams are sitting in.
- Weeks 3–4 — Write the policy you don't have. Not a 40-page AI charter — a one-page usage policy: which tools are approved, what data categories are off-limits (retailer data, contracts, HR data, pre-launch NPD), and who owns exceptions.
- Weeks 5–8 — Allow-list and route demand. Stand up one or two sanctioned, enterprise-grade AI tools with proper data handling terms so employees have a faster legitimate option — removing the reason to go around IT in the first place.
- Weeks 9–12 — Fold it into existing governance. Connect the policy into whatever audit and EU AI Act compliance structure is already in motion, so shadow AI isn't a standalone initiative but a documented line item the board can point to.\
This is exactly the kind of structural gap our AI Check diagnostic delivered through an AI FlightCheck™ engagement is built to surface, alongside the data, pilot, and adoption issues already on most mid-market AI agendas. It's also the kind of policy ownership a fractional Chief AI Officer is typically the one to hold. The cost of finding it now is a two-week diagnostic. The cost of finding it after a breach is, on average, an extra $1 million and a board meeting nobody wants to be in.
Sources
- Verizon 2026 Data Breach Investigations Report
- IBM Cost of a Data Breach Report 2026
- PagerDuty — Shadow AI Workplace Survey 2026
- Okta / Apprize360 research, reported by The Register
- UK Cyber Security and Resilience Bill — summary, GOV.UK
- EU AI Act implementation timeline, European Commission AI Act Service Desk
Related AI Navi reading (internal links)
- What Is an AI Check? The UK Mid-Market Guide (2026)
- AI Governance Audit Readiness
- Does the EU AI Act Apply to Your UK Business?
- What Is a Chief AI Officer? UK 2026 Role Explained
- How to Turn Board Pressure for AI ROI Into Your Strategic Advantage
- How to Reduce Trade Spend Waste Using AI (UK CPG, 2026)
- CPG Deduction Management: Why Multi-System Complexity Is Bleeding Your Margin
- How to Integrate AI with WMS, TMS and Carrier Systems
- AI in Food and Beverage R&D
- Why Logistics Leaders Need AI Strategy Before Labor Automation
