The AI your staff installed — and the register that catches it
People are not using AI behind your back to be dishonest. They are using it because it works and nobody told them where the line was. In the 2026 audits we recorded fourteen undeclared tools across nine firms. Here is what those tools looked like, why an amnesty finds them and a policy does not, and how to build the register your enterprise clients keep asking for.
In the AI audits we ran during 2026 we recorded fourteen undeclared tools across nine firms — tools in active use that appeared nowhere in the firm's policies, procurement records or data-protection paperwork. That is our own finding, and it changes how a partner group thinks about this. Not because fourteen sounds large, but because of where they were found: not in the IT estate, not on the finance ledger, and not on anyone's risk register.1
§ 01Why the tools are invisible
Shadow AI is not a technology problem. It is a gap between what a policy says and what a person needs at four o'clock on a Friday. Three patterns account for almost everything we find:
- The free tier. A consumer chat product, a personal account, no enterprise terms, no data-processing agreement, no retention control. The work is genuine legal work; the tool is a personal one. Nothing in the firm's systems records that it exists.
- The personal card. A paid tool bought by an individual or charged to a practice credit card as a small expense. It does not appear in the software asset list, and because the person is paying, they feel they own the choice.
- The browser extension. Installed in a personal browser profile, running inside the firm's webmail or document store, often with broad read permissions that nobody has reviewed and can be withdrawn or changed by the vendor without notice.
The common thread is that each one was reasonable at the time. That matters, because it means the usual response — a circular, a reminder that the firm has an approved list — does not find them. It makes people quieter. Your document management system will not tell you either: it sees a saved file, not the tool that produced it.
Every one of the fourteen tools was installed by someone trying to do their job faster. Not one firm knew the full count before we asked. — from our 2026 AI audits
§ 02Amnesty is the method, not a soft option
The only thing that reliably produces an accurate count is a declared period of amnesty: a fixed window, in writing, in which anyone can disclose a tool they have installed or used, with a commitment that disclosure itself will not lead to disciplinary action. What follows is not forgiveness without consequence. It is migration — to an approved tool, or to a controlled use with conditions the firm sets.
A date the window closes. That the firm wants the truth about tools, not names of wrongdoers. That anyone who declares will be helped onto a compliant route. And that after the window, undisclosed use becomes a conduct matter. Without the last line the amnesty is theatre; without the first three nobody uses it.
Two practical notes from the reviews. Ask about tools that were tried and abandoned as well as tools in use — data may already have gone through something nobody remembers. And ask the people who know: the practice manager, the paralegal lead, the IT contractor, whoever approves small expenses. In our experience the count that comes back from a partner meeting is roughly half the count that comes back from a quiet conversation with support staff.
Where a tool is found in use, the first question is not what to ban. It is what data actually went into it — client names, matter detail, anything privileged — and whether that flow can be reconstructed if a client asks. That is a records question before it is a procurement one.2
§ 03The register: five control areas
An AI register is a single table, one row per tool, that a stranger could use to review your firm without asking you anything. Across our reviews, five control areas decide whether a register is real or decorative:
- Ownership and scope. Who is accountable for the tool, which teams may use it, and what it is approved to do. A register row with no named owner is a row nobody maintains.
- Data boundary. What is entered into it — client data, privileged material, personal data — where it is processed, whether it trains the vendor's models, and how long it is retained. Get this from the vendor's terms, not from the demo.
- Access and authentication. Firm identity for firm accounts, no shared logins, no personal accounts doing firm work, extensions reviewed before they run inside webmail.
- Review and change. A dated review cycle, and a trigger to re-review when the vendor changes model, terms or subprocessors. Vendors change these quietly; the register is where the change surfaces.
- Exit. How you get your data out, and what happens to it when you stop. If the answer is unclear, note the date you asked — asking is itself evidence of diligence.
Build it in a spreadsheet if that is all you have. The format matters far less than the fact that it is dated, owned and honest about gaps. A register that records "retention unknown, query raised 4 September" is more useful in a review than one that claims all is compliant and cannot show why.3
§ 04Why clients ask, and what to send them
Enterprise clients ask for the register twice: in procurement, and in their own supplier due diligence. Their question is narrow, and it is not "do you use AI?" It is "can you tell me what touches our data?" A policy document frustrates them, because a policy describes intent. A register answers the question, and so does a short covering note: this is the list, this is who owns it, this is when it was last reviewed, this is what changed since last time.
Two supporting artefacts do most of the work. An acceptable-use position that says plainly what may not be entered into any AI tool, in language a fee-earner will remember. And a matter-level record showing where AI touched a piece of work, so a file review years later can reconstruct what happened. That second one is the piece firms skip, and the piece their clients ask about next.4
If you have not counted yet, do a small version of this yourself: one declared week, four questions per team — what did you use, what did you put into it, whose account, what did you keep. Our tools index shows how we score the products themselves, and the resources page carries the free checklists we use in reviews. If the count surprises you, the AI audit turns a list of tools into findings you can hand to a client — or a 42001 readiness engagement if you need the management-system answer rather than the inventory one.
- Probative Co is an independent compliance practice, not a law firm, and nothing here is legal advice. The patterns described are drawn from our own engagements; firms are never identified. ↩
- If a tool has processed personal data, the data-protection questions are governed by the UK GDPR and the Data Protection Act 2018; the ICO's guidance on controllers, processors and international transfers is the place to start. ico.org.uk ↩
- AI management systems are standardised in ISO/IEC 42001, which expects documented responsibilities, an inventory of systems in use and a defined review cycle: iso.org/standard/42001. ↩
- For regulated firms, record-keeping obligations sit alongside AI governance: MLR 2017 requires customer due diligence records to be kept and retrievable. legislation.gov.uk — SI 2017/692 ↩
Send three files.
We'll tell you what a reviewer would flag.
- No charge and no obligation — you keep the findings either way
- Turned around in ~48 hours, encrypted transfer only
- Most firms find at least one issue they did not know they had