Most UK mid-market CPG and FMCG leaders can tell you exactly which AI pilots are running in their business. Far fewer can tell you which AI tools their category managers, demand planners, and finance analysts are actually using day to day often with no sign-off, no data policy, and no idea what's happening to the spreadsheet they just pasted into a chatbot.
That gap has a name: shadow AI. And in 2026, it's grown from an IT footnote into one of the most under-audited risks in mid-market operations.
What "Shadow AI" Actually Means
Shadow AI is any AI tool: ChatGPT, Gemini, a browser extension, an unapproved Copilot plugin that employees adopt on their own, without going through procurement, IT, or a governance review. It's distinct from the formal, sanctioned AI programmes we've covered in our guide to AI governance audit readiness and our breakdown of whether the EU AI Act applies to your UK business. Those posts are about the AI programmes leadership knows about. Shadow AI is about the ones they don't.
The Scale of the Problem
The numbers should give any UK mid-market operations or compliance leader pause:
- 86% of employees now use AI tools at least weekly for work-related tasks, according to BlackFog's 2026 shadow AI research and 60% agree that using unsanctioned tools is justified if it helps them hit a deadline.
- 63% of organisations have no AI governance policy in place at all, per IBM's 2025 Cost of a Data Breach Report and where shadow AI usage is high, it adds an average of $670,000 to the cost of a breach.
- Organisations manage an average of 490 SaaS applications, but only 47% are authorised meaning more than half the tools touching company data were never formally approved, according to Reco's 2025 State of Shadow AI Report. Once an unsanctioned AI tool embeds itself in a workflow, it persists for 400+ days on average before anyone notices.
- On the data itself: BlackFog found 33% of employees have shared research or datasets with unapproved AI tools, 27% have shared employee data (names, payroll, performance records), and 23% have shared financial statements or sales data. 51% have connected an AI tool to other work systems without IT approval.
For a CPG or FMCG business, "financial statements or sales data" isn't abstract it's trade spend models, supplier pricing, NPD roadmaps, and retailer scorecards. The same commercially sensitive data this blog has covered in posts like how to reduce trade spend waste using AI is exactly what's most likely to end up pasted into a free-tier chatbot by someone trying to move faster.
Why It Happens
Shadow AI isn't usually malicious it's a symptom of governance moving slower than demand:
- Sanctioned tools lag behind need. If the "official" AI rollout is still in pilot, staff won't wait they'll use what's already on their phone.
- Deadline pressure beats policy. BlackFog's research found senior leaders are more likely to accept the risk: 69% of President/C-level respondents said speed takes priority over security, versus 37-38% at junior levels meaning the tone from the top often quietly encourages the behaviour it should be governing.
- No clear "yes" list. Most policies say what's banned. Almost none say what's approved, so employees default to whatever is easiest to access.
- Fear of looking behind. In fast-moving categories, being seen as the person not using AI carries its own reputational cost.
This is the same dynamic we explored in what AI change management actually requires governance failures are rarely about the technology. They're about incentives and pace.
A 5-Step Audit Framework for Mid-Market Leaders
You don't need an enterprise security programme to get shadow AI under control. You need visibility, a policy people will actually follow, and a review cadence.
- Discover actual usage. Survey teams honestly (anonymously, if needed) and check expense reports, browser extension lists, and SSO logs for AI tool sign-ups. Assume the real number is higher than what's reported.
- Classify the data risk, not just the tool. A free chatbot used for drafting internal copy is a different risk to one used for supplier pricing or customer data. Map tools against the sensitivity of what's likely to be pasted into them.
- Publish a "yes" list, not just a "no" list. Name the 2-3 sanctioned tools people can use today, with clear rules on what data is and isn't allowed. A policy with zero approved options guarantees shadow usage continues.
- Fix the access gap that's driving the behaviour. If procurement for an approved tool takes eight weeks, that's the real root cause not employee judgement.
- Review quarterly, not annually. Tool adoption moves faster than most governance calendars. A lightweight quarterly check-in catches drift before it becomes a 400-day embedded habit.
This is close to the discovery work we run inside AI FlightCheck™ the difference being FlightCheck also benchmarks what you find against what "good" looks like for a business your size, so you're not just cataloguing risk, you're prioritising what to fix first. It's a natural complement to the broader readiness work covered in what is an AI Check?
The Bottom Line
Shadow AI isn't a reason to panic, and it's not a reason to ban AI tools outright that just pushes the behaviour further underground. It's a governance blind spot that's cheap to close and expensive to ignore: the ICO's guidance on AI and data protection makes clear that UK organisations remain accountable for personal data processed through AI tools, whether or not those tools were formally approved. If you haven't audited what your teams are actually using not what's on the approved vendor list, but what's genuinely running day to day that's the gap worth closing first.
Want an honest read on what's really running across your business? Book an AI FlightCheck™ to find out.
