Stay ahead!
Click a tag to get email alerts when we publish related content.
Shadow artificial intelligence is a management problem
Published on August 19, 2026
In June, between sessions at an advanced-markets symposium in Montreal, I was standing with a group of advisors talking about how artificial intelligence (AI) was already being used in insurance work.
The conversation was lively until I suggested they ask their business insurer a specific question: what coverage would apply after a data breach involving a personal AI account outside the firm’s approved environment and not held in the firm’s name?
Brows furrowed. Several pairs of eyes dropped toward the floor. That is often the reaction, and it appeared to be the first time anyone in the group had heard the question asked that directly. Before long, the conversation picked up again, as it often does when industry colleagues start talking shop with AI.
When the group dispersed for the next session, I headed toward the elevator. A senior advisor who waited behind approached me privately. He admitted he was at a loss over what to do about shadow AI inside his firm. He was certain employees were using their own personal AI accounts for client work instead of the tools the company had approved, and he wanted to address it before a breach or compliance problem forced the issue.
Shadow AI is unauthorized or undisclosed AI use inside a business. Someone summarizes a meeting, drafts a client email, or organizes case notes on a personal ChatGPT or Claude account because they are trying to work faster.
A November 2025 KPMG survey found that 51 per cent of Canadian employees surveyed were using generative AI at work, up from 22 per cent in 2023.
The firm still inherits the consequences. Client information may now sit somewhere the organization cannot administer, supervise, audit, or pull records from.
Prohibition can push the behaviour underground
Across separate conversations with professionals at large firms, I have encountered both hard blocks and hard threats.
At one organization, ChatGPT and Claude could not be accessed through corporate devices or Wi-Fi. At another, employees had been warned that using anything outside the approved AI environment could cost them their jobs.
The professionals I spoke with said plainly that the approved tools were weaker.
I understand why people go around the policy. In many cases, the personal AI tool is noticeably better. The work has not disappeared, and neither has the appetite for faster research, better summaries, and stronger first drafts.
When a firm asks people to abandon a capable product for one that makes more work instead of less, the policy will eventually be tested in private.
Shadow AI is a management problem before it becomes an IT problem. Firms need a clear boundary, a useful, approved tool, and training that shows people how to work inside it.
Senior leaders can start by finding out what is already happening. Ask employees what work they are trying to do faster or better, which tasks consume the most time, where approved tools fall short, and which (if any) personal AI tools they reach for instead.
The purpose is to identify the workflows that must be stopped, redesigned, or moved into an environment the firm can oversee in a way that doesn’t penalize early adopters.
Five questions before AI touches client work
“The good news,” I tell clients, “is that your firm doesn't need to settle every question about AI before approving one useful workflow.” What they do need, is five clear answers about that specific workflow before starting.
-
What data is being touched?
Public material and fictional examples carry far less exposure than health details, estate records, discussions of family dynamics, policy data, corporate documents, or a meeting transcript. As many readers will already know, removing a client’s name may still leave enough family, corporate, financial, and geographic detail to identify them.
If AI is polishing the wording of a client’s explanation, it does not need the client’s whole file. If it is preparing a follow-up from one portion of a meeting, it may not need the full transcript.
Use only what the task requires.
-
Which tool and account are being used?
A personal ChatGPT, Gemini, Grok or Claude account is a different environment from a firm-approved enterprise deployment with administrative controls, audit trails, and contractual data-handling terms.
Tool approval attaches to the exact product, account type, and configuration that the firm reviewed. It does not automatically extend to every service the AI vendor sells.
-
What exact workflow is being approved?
Will the tool summarize a client-consented, approved meeting record? Organize case facts? Draft a reason why letter? Help an advisor test an explanation before speaking with an accountant?
Each workflow needs a defined purpose, approved inputs, expected output, and a named point of human review. It should also say what the AI is permitted to do, what it is forbidden to do, and where approval is recorded.
The trouble with vague policies that “permit” AI is that they leave employees inventing their own processes instead of following standard operating procedures designed for regulated workflows.
-
What controls are in place?
The firm should know where information is stored and processed, who controls the account, who can reach the information, and how long it is kept.
It should also know whether prompts or outputs can be used to improve the vendor’s systems, whether information passes to other service providers, and whether activity can be audited.
Consent, recordkeeping, deletion, and review have their place in the workflow design. Settle these questions before the first upload. Once client information enters the system, the firm is relying on whatever consent, access, retention, and deletion rules were already in force.
-
Who is responsible?
An AI tool does not hold the advisor’s licence, professional obligations, or relationship with the client.
A named person remains accountable for the facts, assumptions, and final document. The workflow should say who reviews the output, what that person checks, and where approval is recorded.
Reviewing means more than deciding whether the document reads well. The reviewer must check the source facts, assumptions, missing information, and any conclusion the available evidence may not support.
A polished result is not proof that the right source information was used. The advisor is responsible for client communications and what to hand to the client, using the approved tools in the appropriate environment, and ensuring their professional judgement is baked into the process instead of glazed on at the end.
Sovereignty is a stack, not a sticker
I have reviewed vendors that lead with the words “Canadian data residency.” The claim may tell us where data rests. It often says much less about where inference occurs, whether an American parent company remains subject to U.S. jurisdiction, or whether sensitive prompts and outputs can be used to improve the vendor’s systems.
The United States CLOUD Act amended the Stored Communications Act so a U.S.-based provider can be ordered by a U.S. court to produce data in its possession, custody, or control, wherever that data sits.
A Microsoft Teams transcript full of sensitive health, estate, family and financial detail may live in Toronto. Canadian storage still matters, but it may not place the file beyond American legal reach when the provider is an American company under American jurisdiction.
That is why I have been describing AI sovereignty at my recent speaking events as a stack rather than a sticker.
Just consider how “Made in Canada” can describe a product that is foreign-owned, built from imported parts, and run on decisions made somewhere else. The label is accurate while the larger picture remains incomplete.
When a vendor says data is stored in Canada, keep asking who controls the infrastructure, which jurisdictions apply, who can access it, and who stays accountable.
Public demonstrations can normalize unapproved workflows
A financial planner recently told me about a professional webinar where a Canadian advisor demonstrated an elaborate AI team. Separate agents handled research, marketing, coding, and review.
Her reaction was part fascination and part alarm. She was already feeling overloaded, and the demonstration made her anxious she wasn’t adopting AI quickly enough. But “useful” is not “approved”.
My first question to her, although useful, was less exciting: “What client information was entering those systems, and which tools had been approved to touch it”? She couldn't say, because it wasn’t disclosed in the video.
I have repeatedly seen insurance and finance creators demonstrate client workflows through personal ChatGPT or Claude accounts. They upload transcripts, case notes, or financial details, then show how quickly the system produces something sophisticated. It’s hard not to be excited when you see it; unless you’re in governance, or compliance (...or you’re me.)
The screen on a video shows the prompt and polished document because that gets the shares and views. It rarely shows the account type, processing terms, retention settings, consent process, or review requirements.
Then finally, I reminded her: “Judge the whole workflow before copying any of these methods or techniques.”
What becomes possible in the right environment
Once a firm picks an appropriate vendor, sets acceptable storage and processing conditions, approves a defined workflow, and names who is accountable for it, AI can support real work inside a regulated practice.
In one approved advisor workflow, the advisor estimated that a first draft of a reason why letter had typically taken between 90 minutes and three hours. With AI assistance, the first pass took about 30 minutes. The system assembles the available case information into a stronger starting point, and the advisor corrects it, confirms the facts, and approves what goes to the client.
In another, an advisor turned a client-conversation transcript into a first-pass estate-planning brief while travelling to the next appointment. It took minutes, then entered the advisor’s normal review process. The advisor challenged the assumptions, confirmed the information, and decided what belonged in the final version.
I have also seen the opposite. In one advisor workflow, the software produced inconsistent outputs and could not carry instructions or context from one template to the next. The advisor could not predict what it would produce each time. Until the system proved itself across several different cases, he still had to check for invented facts and fill in information it was missing.
Once that trust threshold is crossed for a defined workflow, the system can help with document assembly, meeting briefs, information gathering, translating the case to different stakeholders and first-pass compliance documentation. The advisor remains responsible for the result.
Approve one workflow at a time
Pick one repeatable workflow and run it through these five questions.
Test it first with fictional or appropriately minimized information. Compare the results across several cases. Define what the reviewer must check, and record who approved the workflow, for what purpose, and under what conditions.
Once the workflow performs consistently and has earned the firm’s trust, consider the next one.
AI prepares. The advisor decides.
Stay ahead!
Click a tag to get email alerts when we publish related content.