Most Canadian business owners, asked whether their finance team uses AI, will answer based on what the company has formally licensed. That answer is almost always wrong, and the gap between it and reality is not a marginal rounding error. It is, according to the most widely cited enterprise AI research of the past two years, close to universal.
Key Takeaway
MIT's GenAI Divide research documented what it termed a "shadow AI economy": employees at over 90% of firms surveyed use personal AI tools at work, frequently in the same organizations where official, sanctioned AI pilots have stalled or failed. This is not primarily a compliance failure by employees; the same research found sanctioned enterprise tools often fail precisely because they cannot adapt to real workflows, while consumer tools remain flexible enough to be useful. For a finance function, the resulting exposure is specific and serious: confidential financial data, client information, and personal information may be entering third-party systems outside any contractual or jurisdictional control, creating potential PIPEDA obligations, professional confidentiality problems for accountants, and an audit trail that cannot be reconstructed. The effective response is a usable policy with a sanctioned tool, not a prohibition, because prohibitions in this area reliably drive the behaviour further underground rather than stopping it.
The Finding, And Why It's Not What It Looks Like
The core empirical claim comes from the same MIT NANDA research examined elsewhere in this publication. Alongside its widely-reported finding that roughly 95% of enterprise generative AI pilots produced no measurable P&L impact, the study surfaced a parallel and considerably less-discussed result: a shadow AI economy in which employees at more than 90% of firms use personal AI tools even where official pilots fail[1]. Related coverage of the same research described employees driving this shadow economy through consumer tools used without employer approval[2].
The juxtaposition of those two findings is the genuinely interesting part, and it inverts the intuitive reading. The obvious interpretation of widespread unsanctioned tool use is that employees are circumventing policy for convenience. The study's own framing suggests something closer to the opposite: that the sanctioned tools failed to be useful, for the specific reason that they could not retain feedback, adapt to context, or improve over time, while the consumer tools employees reached for instead were flexible enough to actually help with real work[3]. The research explicitly noted that even avid ChatGPT users distrust internal generative AI tools that do not match their expectations[4].
This Is Not A Discipline Problem
Framing matters here because it determines the response, and the wrong frame produces an actively counterproductive one. If shadow AI is read as employees breaking rules, the natural response is enforcement: policy reminders, monitoring, disciplinary consequences. If it is read as employees solving a real problem the organization failed to solve for them, the natural response is to provide a sanctioned tool that actually works, which addresses both the productivity need and the governance exposure simultaneously.
The evidence supports the second reading. A bookkeeper pasting an ambiguous supplier contract clause into a chatbot to understand it is not being reckless in their own frame; they are doing their job with the best tool available to them, in an organization that has not provided a better one. The exposure they create is real and needs addressing, but treating the behaviour as misconduct misdiagnoses why it is happening and predicts the wrong intervention.
What Finance Teams Actually Paste In
The generic shadow-AI discussion tends to stay abstract. For a finance function specifically, it is worth being concrete about what actually gets entered into unsanctioned tools, because the sensitivity varies enormously and so should the governance response. Common patterns include: pasting a supplier or client contract clause to have it explained or summarized; entering a column of transaction descriptions to have them categorized; uploading or pasting portions of a trial balance or aged receivables listing to ask for anomaly identification; drafting collections correspondence that includes a named client and an outstanding balance; and asking for help constructing a spreadsheet formula while pasting in sample rows of live data as context.
These are not exotic misuse cases. They are ordinary, reasonable attempts to work faster, and several of them involve information a business would never knowingly send to an unvetted third party in any other format. The employee pasting three rows of a receivables aging into a chatbot to get a formula would not email those three rows to an unknown vendor, and would recognize immediately that doing so was inappropriate. The chatbot does not trigger the same recognition, which is precisely the governance gap.
The Confidentiality Exposure, Specifically
The exposure created depends heavily on which tool is used and under what terms, and this is where most informal shadow AI use goes wrong. Consumer-tier and free AI services frequently operate under terms permitting the provider to retain submitted content and, in some configurations, use it for model improvement, whereas enterprise and business-tier offerings from the same providers typically include contractual commitments against training on customer data and offer defined data handling terms. An employee using a personal free account has, by default, accepted the consumer terms, and the organization has no contractual relationship with the provider at all.
The practical consequences worth naming: the business has no data processing agreement governing the information, no ability to require deletion, no visibility into where the data is stored geographically, no contractual confidentiality protection, and no notification obligation if the provider suffers a breach. For information subject to a client confidentiality obligation or a supplier non-disclosure agreement, this is not a theoretical governance gap; it is a plausible contractual breach that occurred without anyone in the organization knowing it had happened.
PIPEDA And Client Data
Where the information entered includes personal information, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) engages directly, and its requirements do not contain an exception for information an employee entered informally into a tool the organization never approved. PIPEDA requires organizations to protect personal information with safeguards appropriate to its sensitivity, and to remain accountable for personal information transferred to a third party for processing, including obligations around ensuring a comparable level of protection. An organization whose employee has entered customer personal information into a consumer AI service has, at minimum, a difficult accountability position, because it cannot demonstrate the safeguards or the comparable protection the statute contemplates.
Cross-border transfer adds a further dimension. Most widely-used consumer AI services process data outside Canada, which is permissible under PIPEDA but carries transparency obligations regarding transfers for processing. An organization that does not know its employees are using these tools cannot possibly be meeting a transparency obligation about transfers it is unaware are occurring. This is one of several reasons the discovery exercise recommended below matters more than the policy document itself.
Professional Obligations For Accountants
For accounting professionals specifically, an additional layer applies beyond general privacy law. CPA provincial bodies impose confidentiality obligations regarding client information under their codes of professional conduct, and those obligations attach to the professional regardless of the medium through which a disclosure occurs. A CPA who enters identifiable client financial information into a consumer AI service is engaging conduct that at minimum warrants examination against their applicable code, and the fact that the disclosure was inadvertent, or that the professional assumed the tool was private, does not obviously resolve the question.
This matters practically for Canadian businesses in two directions. A business employing CPAs in its finance function has staff carrying personal professional obligations that the business's own permissive or absent AI policy does not discharge. And a business engaging an external accounting firm has a reasonable interest in asking that firm what its own AI policy actually is, a question very few clients currently ask and most firms would benefit from being able to answer clearly.
Why Outright Bans Usually Backfire
The instinctive response to the exposure above is prohibition: a policy stating that AI tools may not be used with company data, full stop. This is understandable and, in most organizations, ineffective in a specific and predictable way.
A ban does not remove the underlying problem the employee was solving. The ambiguous contract clause still needs interpreting; the transaction descriptions still need categorizing. What a ban reliably changes is not whether the tool gets used but whether its use is disclosed, which converts a visible governance problem into an invisible one. The organization loses the ability to know what data is exposed, to review outputs before they inform decisions, and to detect the pattern at all. It also loses the diagnostic signal discussed below, since usage that has gone underground cannot be measured.
There is a second failure mode worth naming. A ban that staff quietly ignore erodes the credibility of the broader policy framework, including the parts that matter most. A finance team that has learned the AI policy is unenforced and unenforceable is a finance team that has learned something general about which policies are real, which is not a lesson a business benefits from teaching.
The Audit Trail Problem
A distinct concern, separate from confidentiality, deserves its own treatment because it surfaces later and is harder to remediate. When an AI tool contributes to a financial output, a reconciliation approach, an accrual estimate, a variance explanation, and that contribution is undocumented because the tool was unsanctioned, the reasoning behind the resulting figure becomes unreconstructable. Six months later, when an auditor, a lender, or a successor employee asks how a particular judgment was reached, the answer exists only in a chat session on someone's personal account, if it exists at all.
This connects directly to the accountability framework discussed elsewhere in this publication: genuine accountability requires an identifiable agent, an available forum, and a real account of how a conclusion was reached. Shadow AI use systematically destroys the third element, not through anyone's bad intent, but because the tool sits outside every system designed to capture the audit trail.
The Departing Employee Problem
A specific exposure deserves separate treatment because it is invisible until it materializes and cannot be remediated afterward. When an employee who has been using a personal AI account for work purposes leaves the organization, everything in that account leaves with them: the prompts containing company data, the outputs informing company decisions, and any accumulated context the tool built up about the business. The organization has no access, no ability to compel deletion, and frequently no knowledge the material exists.
This differs meaningfully from conventional shadow IT. An employee using an unsanctioned file-sharing service at least leaves the files somewhere the organization might discover and reclaim. A personal AI chat history is functionally unreachable, sits under an individual's consumer terms of service, and may contain months of company financial information in a form the departing employee retains indefinite access to. For a business with any concern about a departing employee joining a competitor, this is a straightforward information-security gap that standard offboarding checklists, built around returning hardware and revoking system access, do not touch at all.
A Worked Case: The Reconciliation Nobody Could Reproduce
A Canadian distribution business discovered during a lender's due diligence review that the methodology behind a recurring inventory-in-transit accrual could not be explained by anyone currently on staff. The accrual had been calculated consistently for fourteen months and was materially correct. The employee who had designed the approach had left the business, and the working papers documented the calculation but not the reasoning, specifically why certain shipments were included at a particular stage and others were not.
On investigation, the former employee had worked out the treatment with the help of a consumer AI tool, in a chat session on a personal account, and had implemented the resulting logic without documenting the underlying rationale anywhere the business could access. The accrual itself was defensible; a subsequent review by the firm's external accountant confirmed the treatment was reasonable. What the business could not do, for several weeks, was explain to its lender why the figure was calculated the way it was, at exactly the moment when explaining it clearly mattered most.
The point is not that the AI produced a wrong answer. It produced a right answer whose reasoning left the organization when the employee did. That is a governance failure with no villain in it, and it is considerably more common than the dramatic data-breach scenario that dominates shadow AI discussion.
A Workable Policy, Not A Prohibition
The response supported by the evidence has four components, and its logic is to make the sanctioned path the easiest path rather than to make the unsanctioned path forbidden.
Provide a sanctioned tool that is actually good enough. This is the load-bearing element. Given the MIT finding that shadow AI proliferates specifically where official tools fail to be useful, no policy will succeed if the approved alternative is worse than what employees are already using. A business-tier account with contractual terms against training on customer data, at genuinely modest per-seat cost, removes most of the exposure while preserving the utility.
Run a discovery conversation, without consequences attached. Ask the finance team directly what they are already using and for what, explicitly framed as information-gathering rather than as an audit with disciplinary implications. A team that expects consequences will under-report, and the resulting picture will be useless. The purpose is to size the actual exposure and identify which use cases the sanctioned tool must cover.
Define data tiers rather than a blanket rule. A usable policy distinguishes categories: information that may be entered into the sanctioned tool freely (public information, general questions, anonymized structures), information requiring specific approval (identifiable client or supplier data, personal information), and information that may not be entered into any external tool regardless of tier (certain regulated data, information under specific contractual restriction). A binary permitted-or-forbidden rule fails because most real questions fall in the middle.
Require documentation where AI contributed to a financial judgment. Not every use, which would be unworkable, but specifically where an AI tool informed a treatment, estimate, or judgment that ends up in the financial records. This addresses the audit trail problem at proportionate cost.
The Signal Hidden In Your Shadow AI Usage
A genuinely useful reframe, and one most governance-focused coverage of this topic misses entirely: shadow AI usage is the highest-quality free data a business has about where its finance function actually needs help. Employees adopting a tool voluntarily, without prompting, training, or mandate, are revealing exactly which tasks are painful enough to be worth the friction of finding their own solution.
This connects directly to the MIT research's finding on budget misallocation, that spending concentrated in sales and marketing while returns concentrated in back-office operations[5]. A business trying to decide where to direct its first sanctioned AI investment has, sitting unexamined in its own shadow AI usage, a revealed-preference map of where the friction actually is, generated by the people who do the work. The discovery conversation recommended above therefore serves two purposes at once: sizing a governance exposure, and identifying the use cases most likely to belong in the successful 5%.
A Note For Students Of Governance
Shadow AI is a clean modern instance of a durable governance principle worth internalizing beyond this specific technology: when a control and a legitimate operational need conflict, the need usually wins, and the control's actual effect is to determine whether the resulting behaviour is visible or hidden. This pattern recurs across decades of information governance, unsanctioned file sharing, personal email for work documents, unapproved SaaS subscriptions, and the organizations that handled each well were consistently those that asked why the sanctioned path was worse rather than those that escalated enforcement of a path staff had already routed around. The specific technology changes every few years; the underlying dynamic between control design and operational necessity does not, which is why the diagnostic instinct, ask what problem the circumvention was solving, generalizes considerably better than any particular AI policy template will.
The Limits Of This Analysis
Several caveats matter. The 90%-plus shadow AI usage figure comes from the MIT NANDA research discussed above, a single non-peer-reviewed study whose sample and methodology carry the limitations noted in this publication's companion article on that research; it should be read as a credible directional finding rather than a precise measurement, and usage rates in Canadian small and mid-sized finance functions specifically have not, to our knowledge, been separately measured. This article's discussion of PIPEDA and professional conduct obligations is a general characterization of how those frameworks apply and is not legal advice; the application to any specific disclosure depends on facts this article cannot assess, including the specific tool's terms, the nature of the information, and the applicable provincial CPA code. Finally, AI vendor data handling terms change frequently, and the general distinction drawn here between consumer and business-tier terms should be verified against the current terms of any specific service rather than assumed.
Frequently Asked Questions
What is shadow AI?
Should we just ban AI tools outright?
Does PIPEDA apply if an employee pastes client data into a chatbot?
Do CPAs have additional obligations here?
What's the single most effective step?
Is there any upside to shadow AI usage?
References
- MIT Media Lab NANDA Initiative. (2025). The GenAI Divide: State of AI in Business 2025, documenting shadow AI usage at over 90% of firms surveyed, as reported in Snyder, J. (2025, August 26), Forbes. forbes.com/sites/jasonsnyder/2025/08/26/mit-finds-95-of-genai-pilots-fail
- Legal.io. (2025, August 23). MIT Report Finds 95% of AI Pilots Fail to Deliver ROI, Exposing "GenAI Divide", describing the employee-driven shadow AI economy. legal.io/blog/MIT-Report-Finds-95-of-AI-Pilots-Fail
- MIT Media Lab NANDA Initiative. (2025). The GenAI Divide, on tools failing to retain feedback, adapt to context, or improve over time.
- Dawiso. (2025, November 25). Why 95% of GenAI Pilots Fail: The Hidden Data Crisis, reporting the finding that avid consumer AI users distrust internal enterprise tools. dawiso.com/blog-post/why-95-percent-of-genai-pilots-fail
- Congruity 360. (2025, October 28). Why 95% of Generative AI Pilots Are Failing, on budget allocation to sales and marketing versus back-office ROI. congruity360.com/blog/why-95-of-generative-ai-pilots-are-failing
- Office of the Privacy Commissioner of Canada. Personal Information Protection and Electronic Documents Act (PIPEDA), Principle 7 (Safeguards) and guidance on accountability for personal information transferred for processing.
This article discusses published research and general regulatory and professional frameworks and is provided for informational purposes. It is not legal, privacy, or professional conduct advice. PIPEDA obligations and CPA professional conduct requirements are fact-specific; confirm your own position with qualified legal counsel and your provincial CPA body.