Shadow AI Use? Not us!

Shadow AI Use? Not us!

Shadow AI use is real. Except all of us do not think that is a "me" problem. Changes are, it is.

Recent cybersecurity reporting makes the issue concrete. AI use on corporate devices has accelerated sharply. Many employees are accessing public AI tools through personal accounts. Shadow AI has become a meaningful data leakage channel. At the same time, ransomware, vulnerability exploitation, third-party compromise, mobile phishing, and AI-assisted attacks are increasing pressure on already stretched security teams.

For law firms, this is not simply an IT issue. It is a client confidentiality issue, an ethics issue, a privilege issue, a client trust issue, and a law firm governance issue.

The core problem: AI adoption is moving faster than governance

Law firms are under pressure to adopt GenAI because the productivity case is real. AI can help lawyers summarize documents, generate first drafts, analyze large bodies of text, prepare chronologies, brainstorm arguments, support business development, and improve administrative workflows.

But unmanaged AI use creates a very different risk profile.

When a lawyer, paralegal, assistant, marketing professional, or business services employee uses a personal AI account to process firm or client information, the firm may lose visibility into:

  1. What data was uploaded
  2. Which tool was used
  3. Whether the tool was approved
  4. Whether the data was retained
  5. Whether the data was used for model training
  6. Whether the interaction was logged
  7. Whether client restrictions were violated
  8. Whether privilege or confidentiality was put at risk

That is the operational danger of Shadow AI. It is not simply “someone using a tool without permission.” It is sensitive information moving into systems the firm did not approve, cannot audit, and may not even know exist.

A lawyer pasting a client contract into a public AI tool may not think of that act as a data transfer. A litigation associate using a browser extension to summarize a deposition transcript may not think of that extension as a third-party processor. A partner asking a chatbot to refine a sensitive client email may not consider whether the client’s outside counsel guidelines restrict AI use.

Shadow AI use is prevalent and largely unmanaged

Despite widespread adoption, the vast majority (71%) of legal professionals admit to using AI without formal approval, with 35% doing so frequently. Interestingly, unclear policy is not the leading cause for this unapproved use, mentioned by only 24% of respondents. The main drivers include: pressure to deliver faster (35%), insufficient functionality in approved tools (32%), and recommendations from managers or senior colleagues (30%).

Enterprise data shows the same pattern at scale. Verizon’s DBIR-related Shadow AI data found that 45% of employees regularly use AI tools on corporate devices, up from 15% the prior year, and 67% of that activity occurs through personal or non-corporate accounts that organizations cannot adequately see, govern, or audit.Employees use AI because it helps them work faster. If the firm does not provide approved, safe, and practical AI pathways, employees will find their own.

The better approach is not “no AI.” The better approach is governed AI.

That means firms should provide approved AI tools, define permitted and prohibited data uses, monitor for unapproved tools, control browser extensions, train users by role, and align AI policies with client requirements.

1. Inventory actual AI use

Before writing another policy, firms should determine what is actually happening.

This includes reviewing access to public AI tools, identifying personal account usage on firm devices, inventorying AI browser extensions, and examining whether confidential data is being uploaded into unapproved systems.

How to execute:

  1. Review firewall, endpoint, browser, DLP, CASB, and Microsoft 365 logs
  2. Identify the most commonly accessed AI tools
  3. Inventory browser extensions across managed devices
  4. Survey users in a non-punitive way to understand real workflows
  5. Compare actual usage against existing policy

The goal is not to embarrass users. The goal is to replace assumption with evidence.

2. Create a clear AI use framework

A useful AI policy should be practical enough that lawyers and staff can apply it in real time.

The policy should classify uses into clear categories:

  1. Allowed without client confidential data
  2. Allowed only in approved enterprise tools
  3. Allowed only with client approval or matter team approval
  4. Prohibited in public or personal AI accounts
  5. Prohibited entirely for certain types of highly sensitive information

How to execute:

  1. Define what counts as client confidential information
  2. Define what counts as privileged or work-product material
  3. Identify approved tools
  4. Require enterprise accounts where client or firm information may be used
  5. Create examples by practice area and business function
  6. Align the policy with outside counsel guidelines and client contracts

A good AI policy answers practical questions: Can I upload this contract? Can I summarize this deposition? Can I use AI to draft a client alert? Can I use AI to analyze a data room? Can I use a browser extension on a client portal?

3. Provide sanctioned AI tools

If firms want to reduce Shadow AI, they need to provide acceptable alternatives.

How to execute:

  1. Select enterprise-grade AI tools with appropriate contractual protections
  2. Disable training on firm or client data unless expressly approved
  3. Use SSO and MFA
  4. Maintain administrative controls
  5. Enable logging and audit trails
  6. Configure retention settings
  7. Restrict use by data type, matter type, or user role where appropriate
  8. Review vendor terms for confidentiality, data processing, breach notice, subcontractors, retention, deletion, and jurisdictional issues

Governed access is more effective than prohibition because it gives users a safe path to productivity.

4. Control AI browser extensions

Browser extensions are often overlooked. They may have access to page content, including content displayed in document-management systems, client portals, e-discovery platforms, HR systems, and deal rooms.

How to execute:

  1. Inventory all installed browser extensions
  2. Block unauthorized AI extensions
  3. Create an approved extension list
  4. Use endpoint or browser management tools to enforce policy
  5. Review extension permissions before approval
  6. Treat AI extensions as third-party software, not harmless productivity add-ons

This is an immediate control opportunity for many firms.

5. Strengthen vulnerability and patch management

The DBIR’s vulnerability findings should push law firms to revisit basic cyber hygiene. GenAI governance will not protect a firm if attackers exploit unpatched systems.

How to execute:

  1. Maintain a current asset inventory
  2. Run recurring vulnerability scans
  3. Prioritize known exploited vulnerabilities
  4. Set patching deadlines by severity
  5. Track exceptions and compensating controls
  6. Require managed service providers and key vendors to report patch status
  7. Review remote-access tools, VPNs, legal SaaS integrations, and identity systems

For critical vulnerabilities, leadership should expect clear reporting: what is exposed, who owns it, when it will be fixed, and what interim controls are in place.

6. Update phishing and mobile-device training

Law firm training must move beyond suspicious email links.

How to execute:

  1. Train on smishing, vishing, QR phishing, fake DocuSign links, fake Microsoft login pages, and MFA fatigue
  2. Use simulations that include mobile scenarios
  3. Adopt phishing-resistant MFA where feasible
  4. Require number matching or stronger MFA controls
  5. Create a simple process for reporting suspicious texts, calls, and authentication prompts

Mobile devices are now part of the firm’s risk surface. Training and controls should reflect that.

7. Build an evidentiary trail

Law firms need to be able to prove what they did, not merely describe what they intended to do.

How to execute:

  1. Maintain AI policies and approved tool lists
  2. Keep records of training completion
  3. Log AI system access where possible
  4. Document vendor reviews
  5. Preserve security questionnaires and SOC reports
  6. Track policy exceptions
  7. Record tabletop exercises and remediation steps
  8. Maintain evidence of compliance with client requirements

This matters because after an incident, clients, insurers, regulators, and courts may ask what controls existed before the problem occurred.

The leadership question

Can the firm use AI in a way that is productive, client-aligned, ethically defensible, secure, and auditable?

That requires coordination across IT, risk, general counsel, innovation, practice leadership, HR, privacy, marketing, and legal operations. AI governance cannot live in a policy document alone. It has to be embedded into workflows, tools, training, vendor management, matter intake, and client relationship management.

What “good” looks like

A mature law firm AI governance program should include:

  1. A current inventory of AI tools in use
  2. A clear acceptable-use policy
  3. Approved enterprise AI platforms
  4. Prohibited-use rules for confidential and privileged data
  5. Browser extension controls
  6. Matter-specific client restrictions
  7. Vendor due diligence for AI tools
  8. Logging and auditability
  9. Role-based training
  10. Incident response procedures for AI-related data exposure
  11. Periodic review by firm leadership

This does not need to be perfect on day one. But it does need to be intentional, documented, and continuously improved.

Final thought

The firms that succeed with GenAI will not be the firms that either ban it or adopt it indiscriminately. They will be the firms that make AI useful, safe, and governable.

For law firms, GenAI governance is now part of professional responsibility, client service, cybersecurity, and operational excellence. Shadow AI is the warning sign. The response should be practical governance: approved tools, clear rules, measurable controls, trained users, vendor accountability, and evidence that the firm can show when clients ask.

The point is not to slow innovation. The point is to make innovation defensible.

Contact us for services at info@kartalegal.com.

Go To Top