In-House Legal Operations' Stubborn 'Shadow AI' Problem

(July 28, 2026, 6:57 PM BST) -- When legal industry consultant Brad Blickstein and his researchers were putting together questions for their latest survey of in-house legal operations, they decided to make a change and start asking not just about company use of artificial intelligence, which had become a staple inquiry, but about shadow AI.

The webinars, conferences, roundtables and an advisory board of in-house legal ops pros they'd been listening to all pointed to the same thing: Unauthorized use of AI at work, or "shadow AI," was becoming a problem in legal operations departments that are supposed to serve as a front line for AI governance.

"We try to keep our finger on the pulse of this all year long," Blickstein told Law360 Pulse after hosting a webinar this summer to talk about some results of the Blickstein Group's 18th annual survey, including the nearly three-quarters of legal operations pros surveyed last fall who said they believed shadow AI would become an increasing problem for corporations and law departments.

"Those numbers indicate that this is a substantial issue for in-house legal ops professionals," he said.

Shadow AI is a type of shadow IT, a term in information technology that captures a phenomenon that occurred during the rise of smartphones, when employees began using their personal technology for work, even though the company didn't approve it or oversee it. Shadow AI describes employees operating AI tools — for example, using a personal ChatGPT account to help with work projects by summarizing company documents. Like its forebear, it's widely seen as a security risk.

But so far, it's also an intractable one — seemingly impossible to address fully as a stream of new AI tools flood the market, many of which anyone can start using with a free trial and some of which people can build themselves in the privacy of their homes.

"It's very hard to stay in compliance as a company, to just say, 'Hey, we're going to blacklist all these products,'" Mike Ferrara, a managing director at FTI Consulting Inc. who advises clients in legal technology, told Law360 Pulse. "I think the biggest problem is that there's too many tools."

The manufacturer Corning Inc. has started asking employees who want to use a new AI tool to first consult an internal chatbot that asks a series of questions to determine whether it passes muster. If the request doesn't get permission right away, it's referred to a committee.

Giving workers real-time guidance on what AI use is permitted can help minimize the volume of shadow AI, but only to a certain extent, Ginene Lewis, the chief of staff to Corning's general counsel and director of the company's legal strategy and operations, told Law360 Pulse.

"You want to establish certain processes and protocols that allow people to understand how they might explore the use of AI, rather than strictly banning it, because they're going to use it anyway," she said.

Some unauthorized AI use is unintentional. An employee might be using an approved product that includes an added AI feature, Lewis said. And beyond the tools, a sometimes bigger challenge is training employees on which company documents they can use AI with, she said, noting the company classifies its data at varying degrees of confidentiality.

Hope Cannon, head of legal operations at marketing software company HighLevel Inc., told Law360 Pulse the question now is not whether employees are using AI — sometimes off the books — but how much and for what purpose. Gathering that information should drive policies and education efforts, she said.

For example, she asked whether a marketing team might feed a contract for an exclusive, high-profile speaking engagement into an AI tool to "cut down on the legalese they might not understand."

Harmonic Security Inc., which sells tools that allow companies to track employee AI use at work, put out a report in May saying that it had analyzed nearly 2 million minutes of AI use and found that workers were using their personal accounts mostly for business. The study looked at some services — including Copilot, Claude, ChatGPT and Gemini — that AI providers offered for free.

"Employees are reaching for their own ChatGPT free subscriptions to write work emails, summarize meeting notes and debug code," Harmonic Security concluded. "They are not using them to plan holidays."

Free accounts are easier to use, the study noted, with users already being logged in and configured and with a chat history. Speaking at Blickstein's webinar in June, Laurie Ehrlich, chief legal officer of the contract intelligence provider Icertis, said she wondered if worries about shadow AI would lessen as companies start to monitor their employees more closely — a requirement, in her mind, for fully integrating AI at work.

"In order for companies to enable true agentic workflows, monitoring of AI use is going to have to be really strong," Ehrlich said. "There are companies out there that are starting to do that. You can use telemetry to see what people are doing in their own work computers and have monitoring on what AI is doing."

Mary O'Carroll, former head of legal operations at Google and now head of consulting company LegalEng, told Law360 Pulse that shadow AI can be very problematic for organizations, and that the issue has come up frequently among larger legal teams. Trying to eliminate it entirely isn't the solution, in her view.

"You have some organizations with dedicated legal ops or innovation teams that have an intake process, they're prioritizing use cases, they've got governance, and they're rolling AI out thoughtfully across the department," she said. "At first glance, that's absolutely ideal."

But those processes take time, and sending every idea through a committee can stifle creativity and the potential for "little pockets of innovation all over the organization," she said.

"I think there's a little bit of a necessary tension right now," O'Carroll said. "You want governance and centralization, but you also don't want to squash creativity."

Ferrara also saw an upside to shadow AI, describing it as "a demand signal from users."

"It's telling organizations that even though there's a lot of fear around AI taking jobs, there's still a pretty large amount of people who want to use these tools," he said. "Why else would they be trying to use them outside the four walls of the organization?"

--Editing by Robert Rudinger.


For a reprint of this article, please contact reprints@law360.com.