Two thirds of office workers say they have used an AI tool at work while believing their company did not allow it. They did it anyway, because it made the afternoon shorter. That is shadow AI, and in most Hong Kong small businesses it arrived long before anyone discussed it.
What is shadow AI?
Shadow AI is the use of artificial intelligence tools inside a business without the owner's knowledge or approval. Staff sign up with personal accounts, paste in work information, and get the job done faster. Nothing is stolen and nothing is broken. The company simply has no record that it happened.
The name borrows from an older idea, shadow IT, which described staff installing their own software before the boss noticed. Shadow AI is faster, because there is nothing to install.
A free chatbot needs no purchase order, no laptop, and no permission. It needs a browser and thirty seconds. The barrier that used to slow unauthorised software down has been removed entirely.
How does shadow AI start in a small company?
Shadow AI usually starts with one helpful person solving one boring problem. It spreads because the result looks good, not because anyone intended to bypass a rule. In a company of nine people there is no procurement process to bypass in the first place.
The typical sequence looks like this.
--- A sales assistant is asked to write a quotation email in polished English on a Friday afternoon.
--- She pastes the client name, the item list and the discount into a free chatbot and gets a clean draft in twenty seconds.
--- The email goes out. The client replies well. Nobody mentions the tool.
--- Two colleagues notice her drafts improved and ask how. Within a month, four people are pasting customer information into three different free accounts.
None of those four people did anything malicious. They were rewarded for being fast. The reason shadow AI grows is that it works.
This is why treating it as a discipline problem misreads the situation. Staff are not sneaking around a policy. In most Hong Kong SMEs there is no policy at all, so there is nothing to sneak around.
How common is shadow AI, and what does the Hong Kong data show?
Shadow AI is now the normal way AI enters a workplace, not the exception. Independent research puts regular AI use at close to half of employees, and Hong Kong's own regulator has documented that adoption is climbing while formal oversight is not keeping pace.
What the international research reports.
--- Verizon's 2026 Data Breach Investigations Report found shadow AI detections rose roughly fourfold in a year, with about 45% of employees using AI regularly on corporate devices.
--- A 2026 PagerDuty survey found 66% of office professionals had used AI at work despite believing it was not permitted under company policy.
--- Cyberhaven's 2026 AI Adoption and Risk Report, built on data movements at 222 companies, found that 39.7% of data movements into AI tools involved sensitive information, and that over 60% of that activity ran through personal accounts rather than company ones.
What Hong Kong's own regulator found.
In May 2026 the Office of the Privacy Commissioner for Personal Data published the results of compliance checks on 60 Hong Kong organisations. The findings are worth reading closely, because the direction of travel is the story.
--- 57 of the 60 organisations, or 95%, used AI in day-to-day operations, up 15 percentage points on 2025.
--- Of the organisations handling personal data through AI, only 50% had formulated AI-related policies, which was down about 13 percentage points on the previous year.
--- Board-level discussion of AI fell too, to 54%, a drop of roughly 25 percentage points.
Read those three numbers together. Usage went up sharply. Governance attention went down. That gap is exactly where shadow AI lives, and these were mostly large organisations. Half of the 60 employed more than 500 people. A Hong Kong company of twelve has no board meeting in which the subject could have been raised at all.
What can actually go wrong? Three Hong Kong scenarios
The realistic damage from shadow AI is rarely dramatic. It is a quiet loss of control over information you are legally responsible for, discovered months later, usually by someone outside the company.
Scenario one: the client list that left the building. A ten-person insurance brokerage in Wan Chai asks a junior broker to summarise renewal opportunities. He pastes a spreadsheet of 340 client names, policy values and contact numbers into a free consumer AI account. The summary is excellent. The data is now sitting in a personal account the company cannot access, cannot audit and cannot delete. Under the Personal Data (Privacy) Ordinance the brokerage remains the data user and remains accountable, whether or not it knew.
Scenario two: the confident wrong answer. A property agency lets an assistant draft tenancy summaries with a free chatbot. The tool has no access to the actual agreements, so it fills gaps with plausible general knowledge. Three summaries state a two-month deposit where the signed agreement says three. Nobody checks, because the writing is fluent. The error surfaces at handover. This is a failure of grounding, and it is worth understanding the mechanism, which we cover in our explainer on AI grounding.
Scenario three: the resignation that took the workflow with it. A marketing coordinator at a retail chain builds a genuinely good process in her own AI account, with saved instructions, a tone guide and product descriptions. She resigns. The account is hers. Six months of accumulated company knowledge walks out with her, and the replacement starts from zero.
Notice that only the first scenario is a privacy issue. The other two are ordinary operational losses, and they are more common.
What do owners usually get wrong about shadow AI?
Most owners either dismiss shadow AI as a big-company concern or over-correct by banning everything. Both responses make the situation worse, for reasons that are easy to see once stated.
Misconception one: we are too small to be a target. Shadow AI is not an attack. There is no attacker. The risk comes from your own information sitting somewhere you cannot reach, so company size changes nothing about whether it happens.
Misconception two: banning AI solves it. The PagerDuty finding is the direct answer here. Two thirds of people used AI while believing it was against policy. A ban does not stop the behaviour. It stops the reporting of the behaviour, which is the only part you actually needed.
Misconception three: paid accounts and free accounts are the same product. They are not. The difference that matters to a business is the contract behind the account: whether your inputs may be used to improve the model, who can retrieve the data, and whether the company or the individual controls the login. Roughly 60% of shadow AI activity runs through personal accounts, and a personal account gives the company none of those three things.
Misconception four: it is an IT problem. Most Hong Kong SMEs have no IT department, and the ones that do cannot see a browser tab. The effective controls here are decisions an owner makes about what information may leave the company, and those are business decisions rather than technical ones.
How do you bring shadow AI into the open in one afternoon?
You do not need software to fix shadow AI. You need one honest conversation, one short written rule, and one approved account. Most small companies can complete the whole exercise in an afternoon and never revisit it as a crisis.
Step 1. Ask, and promise no consequences. Say plainly that you want to know which AI tools people already use and that nobody is in trouble. You will get an accurate answer once, and only if the promise is credible. In a nine-person company this takes fifteen minutes.
Step 2. Write down what may never be pasted. Keep it to one line each. Customer names and contact details. Identity card or passport numbers. Salary and bank information. Signed contracts. Anything a client gave you in confidence. A rule people can remember beats a policy people file.
Step 3. Approve one tool and pay for it. The single most effective move available to an SME is giving staff a legitimate account that is better than the one they found themselves. Free tools stay in use because they are free and available, so remove that advantage.
Step 4. Put the account in the company's name. Company email, company billing, company control. This is what stops six months of accumulated work leaving with a resignation.
Step 5. Decide which outputs a person must check before they leave the building. Anything with a number, a date, a price or a legal term gets read by a human. Everything else can go. This is the same principle as keeping a person in the decision chain, described in our guide to human-in-the-loop.
Step 6. Write down who to tell when something goes wrong. One named person, one sentence. Without it, a mistake gets quietly deleted instead of reported, and the quiet ones are the expensive ones.
Hong Kong owners have a useful shortcut available. The Privacy Commissioner publishes a free Checklist on Guidelines for the Use of Generative AI by Employees, written to be usable by organisations without legal departments. This article is general information and not legal advice, so read the checklist yourself and take professional advice on your own circumstances.
Frequently asked questions about shadow AI
Is shadow AI illegal in Hong Kong? Using an AI tool is not itself illegal. However, if personal data goes into it, the Personal Data (Privacy) Ordinance still applies and your company remains the responsible data user. Not knowing an employee did it does not transfer that responsibility.
Can I detect shadow AI without buying monitoring software? In a small company, asking works better than monitoring. Monitoring tools are built for organisations with hundreds of devices and a security team to read the alerts. In a firm of twelve, a fifteen-minute conversation produces a more complete picture at zero cost.
Should I ban AI until we have a policy? A temporary ban tends to produce silence rather than compliance. A more workable sequence is the reverse: name one approved tool this week, write the never-paste list the same day, and refine the policy afterwards with real usage in front of you.
Does a paid plan mean my data is safe? It means your data is governed by a business agreement rather than a consumer one, which is a meaningful improvement, not a guarantee. Read what the provider says about training on your inputs and about retention, and keep the never-paste list in force regardless of plan.
What if my staff use AI on their own phones? You cannot control the device, so control the information. That is why the never-paste list is the load-bearing rule. It travels with the person and applies on any screen.
The takeaway for Hong Kong business owners
Shadow AI is not a sign that your staff are careless. It is a sign that they found something useful before the business had an opinion about it. The Hong Kong data makes the timing plain: adoption is rising while formal attention is falling, and the gap between the two is filled by ordinary people trying to finish work faster.
The fix is small and it is not technical. One conversation without blame, one short list of what must never be pasted, and one paid account in the company's name will resolve most of the exposure a small business carries. What you gain is not just safety. You gain visibility of how your team actually works, which is usually more interesting than the risk you set out to manage.
We understand AI. UD stands with you. After twenty-eight years alongside Hong Kong businesses, we have learned that the companies who handle new technology well are rarely the ones with the strictest rules. They are the ones who asked first.
Reviewed by the UD AI team, Hong Kong.
Find out where your business actually stands
Knowing what shadow AI is and knowing what is happening inside your own company are two different things. UD's free AI Ready Check gives you a clear picture of where your business sits today, and we will walk you through it step by step, from the first honest conversation to a written rule your team will actually follow.