A paralegal pastes a client’s settlement demand into a personal ChatGPT account to tighten the language. A dental office coordinator runs a patient’s intake notes through Gemini to draft a callback script. A bookkeeper feeds a client’s bank statements into Claude to catch errors before a filing deadline. None of it goes through a firm account, and none of it is written down anywhere. This is shadow AI: use of an AI tool that the owner never approved and cannot see, touching exactly the data a law license, a medical practice, or a client engagement letter obligates someone to protect.
Shadow AI is not a hypothetical for a future audit. It is the current, ordinary behavior of employees who found a tool that makes them faster, with no firm-approved alternative and no rule on what not to paste into it. The fix is not a ban, which research on this exact pattern shows only pushes the behavior out of sight. The fix is structured training on business-tier tools, paired with a plain rule about what data never leaves the firm, and California’s ETP Small Business Program can often help pay for it.
What shadow AI looks like inside a California firm
Shadow AI is any use of an AI tool at a firm that the owner or partner group did not approve, does not oversee, and cannot see. At a large company this is a security-team problem: unsanctioned software on a managed device, flagged by network monitoring. At a 5-to-50-person California firm there is no managed device and no network monitoring. Shadow AI is a browser tab on someone’s own laptop or phone, logged into a free account nobody in leadership knows exists.
The behavior is not reckless; it is rational. An employee who discovers that a chatbot turns a stack of receipts into a clean expense summary, in a fraction of the time it used to take, keeps using it. Nobody handed them a firm account, so they use their own. Nobody told them which documents are off-limits, so they guess, and the guess is often wrong. The gap is the absence of an approved, trained-on alternative, not a discipline problem.
What makes this different from an ordinary office-tech habit is the material involved. A California firm’s daily work product is exactly the data that carries the most legal weight: named clients tied to financial or medical detail, matters under an engagement letter, records a state or federal rule already protects. Shadow AI does not create new categories of sensitive data. It moves data that was already sensitive onto a system the firm does not control.
How common this actually is
The scale here is not a guess; it shows up consistently across independent 2025 surveys. MIT Project NANDA’s “The GenAI Divide: State of AI in Business 2025” found that more than 90% of employees at surveyed companies use personal AI tools for work, while only about 40% of those companies had purchased an official AI subscription. That gap, adoption running well ahead of anything a firm sanctioned, is shadow AI in one statistic.
KPMG International and the University of Melbourne’s “Trust, attitudes and use of Artificial Intelligence: A global study 2025,” fielded November 2024 to January 2025 across more than 48,000 respondents in 47 countries, adds the part that should worry a firm handling client data: 48% of employees using AI at work admitted feeding potentially sensitive company information into a public tool, and only 40% of workplaces had any generative-AI policy at all. Most of the exposure sits at firms that never wrote a rule.
Neither report targeted California small businesses on their own, so read the percentages as a directional signal rather than a claim about one team’s exact rate. Both agree that adoption ran well ahead of governance, and a 12-person practice with no IT department has had fewer resources to close that gap than the large enterprises these reports mostly sample.
Why regulated professions carry extra exposure
Every California business that lets employees paste client data into a consumer AI account carries some CCPA exposure, covered below. Three professions carry an added layer, because a specific rule already governed their client data years before generative AI existed.
| Profession | Rule that applies | What it means for shadow AI |
|---|---|---|
| Law firms | Duty of confidentiality; California State Bar’s Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, approved November 16, 2023 | An attorney should not input client confidential information into a generative AI tool unless the provider is known not to use or share it, which a free consumer account usually cannot guarantee |
| Medical and dental practices | HIPAA, enforced by HHS’ Office for Civil Rights | Consumer-grade generative AI is not HIPAA-compliant by default; patient information usually needs a signed Business Associate Agreement most free accounts do not offer |
| CPA, bookkeeping, and tax-prep firms | FTC Safeguards Rule under the Gramm-Leach-Bliley Act, updated rules effective June 9, 2023 | The rule treats an accountant or tax preparer as a “financial institution” regardless of size, with a written security-program duty an ungoverned AI habit works against |
None of these rules were written with ChatGPT in mind, and none ban AI use outright. What they share is a baseline expectation that client data stays inside a controlled system. A free, personal AI account is close to the opposite: no administrative oversight, no signed data agreement, and terms that on some consumer plans let the provider use inputs to improve its own product. A firm in one of these categories that has never checked its team’s habits against its existing obligation is not looking at a new risk; it is looking at an old one nobody has re-read since ChatGPT arrived.
The CCPA layer every California firm should check
Every for-profit business in California should check its own status against the California Consumer Privacy Act before assuming shadow AI is someone else’s problem. Meeting any one of three thresholds published by the California Attorney General triggers it: over $25 million in annual gross revenue, buying, selling, or sharing 100,000 or more California residents’ personal information, or deriving 50% or more of revenue from selling personal information. A modest-revenue firm can still be covered through the data-volume test if it holds a large client or patient list, common at legal, medical, and financial practices well under the revenue number.
A CCPA-covered business that lets client data flow into an unmanaged AI account has a harder time meeting its obligations around data minimization and vendor accountability, because it usually cannot say what the AI provider does with that input. The California Privacy Protection Agency’s automated-decisionmaking rules add a further layer starting January 1, 2027 for covered businesses using AI to make “significant decisions” about people; the state training playbook covers that rule and the rest of California’s 2025-2026 AI-at-work statutes in depth. A firm below every CCPA threshold should still treat shadow AI as live risk: the statute is one exposure, and the confidentiality duties above are a separate, often larger one that doesn’t depend on hitting any CCPA number at all.
Why banning consumer AI tools backfires
The instinct once an owner sees this exposure is a firm-wide email banning ChatGPT, Claude, and Gemini outright. It is also, per the same 2025 data, close to the least effective response available. KPMG and the University of Melbourne found that 57% of employees already hide their AI use and present AI-generated work as their own, a habit that predates any formal ban. Cisco’s 2025 AI Readiness study, 8,000 decision-makers across 30 countries, found 81% of organizations already have no visibility into how employees use AI, before any policy change at all.
A ban on top of that starting point makes visibility worse, not better. An employee using a personal ChatGPT account on office Wi-Fi moves the same habit to a personal phone on cellular data, still pasting the same client documents, with the one advantage the firm had, seeing and correcting the behavior, removed. A ban does not stop AI use; it happens exactly as often, minus the firm’s ability to govern it. The absence of a rule and an approved tool was always the actual gap, and a ban fixes neither.
What closes the gap: training, not policing
The alternative to a ban is two concrete moves, neither requiring a security specialist.
The first is a written, one-page rule stating which data never goes into an AI tool (named clients tied to financial or medical detail, anything under an NDA or engagement letter, protected health information), paired with a switch from personal free accounts to business-tier accounts on ChatGPT, Claude, Gemini, or Microsoft Copilot. On the plans a firm should confirm before rolling out, those tiers keep firm inputs out of model training and give an owner administrative visibility a personal account never offers.
The second is training built on the firm’s actual documents, not a generic slide deck, because the data above shows why an untrained team using an approved tool still carries risk: people never told what “sensitive” means for their role default to pasting whatever gets the task done fastest. A program that drills a law firm’s staff on which matter documents can never leave a firm-controlled workspace, or a medical practice’s front desk on the line between an appointment reminder and protected health information, changes behavior in a way a memo alone does not. The state training playbook lays out the full 90-day framework for getting from ungoverned use to a trained, business-tier standard, and the San Francisco hub page covers what that looks like for Bay Area firms, including delivery logistics inside and outside the city.
Training like this still has to get funded, and most owners have never checked whether it already is. California’s ETP Small Business Program reimburses training at $28 per trainee hour for California-domiciled firms with 100 or fewer California employees, funded by a payroll tax most employers already pay. Confirm current terms at etp.ca.gov before applying, since rates are reviewed yearly.
Frequently asked questions
Is shadow AI actually a legal problem, or just a bad habit?
It can become one, and the size of the risk depends on the profession. A law firm risks a confidentiality breach the moment privileged material enters a consumer AI account it doesn’t control. A medical practice risks a HIPAA violation if patient information reaches a tool without a signed Business Associate Agreement. A CPA or bookkeeping firm has a written-security-program duty under the FTC Safeguards Rule that ungoverned AI use works against, and every other California business carries CCPA exposure if it meets the statute’s thresholds. None of this depends on anything going wrong publicly; the exposure exists the moment data leaves the firm’s control.
Does the CCPA apply to my business specifically?
Meeting any one of three thresholds published by the California Attorney General triggers it: over $25 million in annual gross revenue, buying, selling, or sharing 100,000 or more California residents’ data, or deriving 50% or more of revenue from selling personal information. A modest-revenue firm can still be covered through the data-volume test if it holds a large client or patient list.
Is ChatGPT HIPAA-compliant?
Not by default on a personal or free-tier account. Using generative AI with patient information usually needs a signed Business Associate Agreement between the practice and the vendor, plus the practice’s own risk assessment, none of which exist on a consumer account someone signed up for on their own. Patient-adjacent work like scheduling language should stay separated from anything touching protected health information until a compliant setup is in place.
Can a law firm use AI at all without breaching confidentiality?
Yes. The California State Bar’s 2023 guidance says so directly: the concern is inputting client confidential information into a tool without knowing the provider won’t use or share it, not AI use itself. A firm on a business-tier account with confirmed data controls, a clear rule on which matter documents stay out of any AI tool, and trained staff can use AI for research and drafting without a personal account’s exposure.
Should we just block ChatGPT and similar tools on the office network?
No. KPMG and the University of Melbourne found 57% of employees already hide their AI use, and Cisco’s AI Readiness study found 81% of organizations have no visibility into employee AI use at all. A network block moves the same behavior onto personal phones on cellular data, where the firm has even less ability to see what’s happening. Blocking a tool removes visibility, not use.
What is the difference between a personal account and a business account?
Data handling and oversight. A personal, free-tier account often gives the owner no administrative visibility and, on some plans, lets the provider use inputs to improve its product. Business tiers of ChatGPT, Claude, Gemini, and Microsoft Copilot usually keep firm inputs out of model training and give an admin visibility into usage. Confirm current terms for whichever tool a firm standardizes on, since vendors update these settings.
How do I find out what my team is already doing with AI?
Ask directly, without threatening consequences for what already happened. Most employees aren’t hiding AI use out of guilt; they never had a reason to mention it because nobody asked and no firm account existed to report it against. A short, no-blame conversation about which tools people use, and for which tasks, produces a more accurate picture than any monitoring software a small firm could reasonably buy.
Can training really change this, or is a written policy enough?
A policy sets the rule; training makes people follow it under time pressure. The 48% figure on employees feeding sensitive information into public AI tools came from workplaces surveyed broadly, not only firms with no policy, a sign a memo alone doesn’t close the gap. Structured practice on the firm’s actual documents builds the judgment call a written rule can’t: recognizing which document in front of someone should never go into that browser tab.
How much does this training cost, and can California firms get help paying for it?
Market pricing for a facilitated workshop runs $2,000 to $15,000 depending on group size and session count. California-domiciled firms with 100 or fewer California employees can often offset a meaningful share through the ETP Small Business Program, which reimburses training at $28 per trainee hour; confirm current eligibility at etp.ca.gov.
Key takeaways
- Shadow AI is common: MIT Project NANDA’s 2025 research found over 90% of employees use personal AI tools for work while about 40% of companies have an official subscription, and KPMG/University of Melbourne’s 2025 study found 48% have fed sensitive information into a public AI tool.
- Law firms, medical practices, and CPA or bookkeeping firms carry an added layer of exposure from confidentiality duties, HIPAA, and the FTC Safeguards Rule, on top of any CCPA exposure.
- Check the CCPA’s three thresholds (revenue, data volume, data-sale revenue share) at oag.ca.gov directly; a modest-revenue firm with a large client list can still be covered.
- Banning consumer AI tools doesn’t stop the behavior; 57% of employees already hide their AI use and 81% of organizations have no visibility into it, and a ban only removes the firm’s remaining view.
- The fix is a written data-handling rule, a switch to business-tier accounts, and training on the firm’s real documents, often reimbursable through California’s ETP Small Business Program.
Ready to see where your team’s AI use stands and what a structured, ETP-fundable program would look like for your roles? Book a free AI-readiness call or start with the Team Training overview.
Dirk Jan van Veen, PhD