
Shadow AI is the name Deloitte gives to staff using AI tools at work without their employer's knowledge, and its survey of 25,000 UK workers, published on 16 September, puts it at 31 per cent of those who use AI. I read the figures with one question in mind, which is what they mean for a practice of ten or twenty people that holds client files.
The survey covers every sector rather than law firms, and the published release gives no figure for legal services, so treat it as a picture of the workforce your staff come from. Ipsos UK carried out the fieldwork between 7 May and 10 June 2026. Of working adults aged 18 to 70, 63 per cent say they knowingly use generative AI for work. Asked what kind of tools they use, 46 per cent say free ones. One user in six pays for at least one tool out of their own pocket, which Deloitte puts at £958 million a year across the country. About half of users have had no formal training on using AI safely, and 65 per cent report a lack of convincing leadership on how it should be used where they work.
Why the figure lands harder in a law firm
The top uses in the survey are searching for information and drafting emails, each at 43 per cent, followed by creating summaries at 31 per cent. Those are the daily tasks of a fee earner. An email drafted in a personal chatbot account carries the client's name and the facts of the matter. A summary of a witness statement means the statement went into the tool first.
The SRA warning notice of 17 August expects contractual, technical and organisational safeguards to be in place before client material enters any AI tool. A subscription a paralegal pays for on a personal card gives your firm none of them. The firm is not a party to the contract, cannot see the settings, cannot tell whether inputs train the model, and cannot retrieve what was typed when a client or the regulator asks.
The survey also explains why the use stays hidden. Nearly a quarter of workers think a stigma attaches to using AI at work, and 64 per cent of weekly users worry their managers will conclude it can do their jobs. Deloitte's chief AI officer, Hayley McKelvey, said that workers who feel that stigma are more likely to conceal their use. A firm that bans AI outright, without offering a tool it has approved, does not stop the use. It moves it somewhere nobody supervises.
What to do this month
Start by asking. Send the team a short, anonymous question on which AI tools they use for work, what they use them for and who pays, and say in the same message that nobody will be disciplined for the answer. You learn more from an honest reply than from any audit of browser histories, and the staff paying for a tool themselves are showing you where the demand sits.
Then remove the reason for going round you. Put an approved tool on a business tier, under a contract that says your inputs will not train the provider's models, and bring the subscriptions people were paying for onto the firm's account. Write the policy that names the tool and the tasks it may be used for, and give everyone an hour of training on it, since half of those using AI at work have had none. A fee earner who has a sanctioned tool and knows the rules has no reason to reach for a private one.
Deloitte's press release, setting out the method and the headline figures, is open to any reader on deloitte.com.
If you want help finding out what your team already uses and turning it into something you can supervise, start with a conversation.