Shadow AI: The hidden technology spreading through Kenyan offices

The logo of DeepSeek is displayed alongside its AI assistant app on a mobile phone. The AI Bill, 2026 introduces requirements for AI deployers and providers to ensure transparency.

Photo credit: Reuters

A manager asks her junior to prepare an analysis of a new market. The employee turns to an AI chatbot, queries it, formats the responses into a presentation and sends it to the manager.

The manager may not know the analysis – complete with figures, trends and recommendations – was produced by an AI tool. She cannot know which sources the system relied on, the timeliness of the data or whether some conclusions are wrong.

At the same time, the company does not use AI for tasks and there may be no policy governing its use.

This is the emerging problem of “shadow AI”, a term coined to refer to AI tools being used by staff without the knowledge or oversight of their employers. Shadow AI is the use of software, hardware or cloud services for company tasks without the approval or knowledge of the central IT department.

As AI becomes embedded in daily office work, experts say the risk is moving beyond staff accidentally exposing company confidential information to chatbots.

The unregulated use has led to what some AI practitioners describe as shadow AI judgment – decisions or recommendations generated by AI that enter an organisation without executives knowing a machine was involved.

For businesses rushing to adopt AI for tasks like data querying and entry, customer support, editing, transcription and coding, many may already be using far more AI than they realise.

Workers can turn to ChatGPT, Claude, Gemini and other publicly-available tools to summarise reports, analyse data, draft documents, write emails or research markets, often without involving the IT department.

This creates a blind spot for management, with the most pronounced risk being data leakage.

“An employee working on a confidential marketing strategy, financial forecast or product plan may paste the information into a free AI service,” Simon Bransfield-Garth, CEO of the tech consulting firm Akili AI, told the Business Daily.

“Suddenly, your secret fourth quarter marketing plan is sitting in California.”

The bigger problem is when AI moves from assisting with a task to influencing a business decision, such as in the case of a worker using a chatbot to assess the prospects of a market on behalf of the company.

The CEO may assume the analysis represents the worker’s own research, yet the AI may have relied on outdated information, misunderstood a question, fabricated a source or concluded that the employee is not qualified to challenge.

“The CEO may say: ‘Let’s go ahead and invest in that,’ unaware that the judgment was made by AI and her employee did not know how correct or otherwise that information was,” Mr Bransfield-Garth said.

“It is an emerging risk, not necessarily a malicious employee misusing technology, but ordinary workers using it without understanding its limitations.”

Kenya is developing regulations that place responsibility on organisations for understanding how they use AI. The Artificial Intelligence Bill, 2026, introduces requirements for AI deployers and providers to ensure transparency, traceability and explainability of AI-driven decision-making.

Deployers would be required to disclose to users the degree of automation involved and any human intervention, as well as measures adopted to mitigate bias.

“Bosses need to know the AI risks. Should anything go wrong, you have the basic processes figured out,” Mr Bransfield-Garth said.

Executives say staff training is as crucial as technical controls. An employee who knows not to upload confidential files into a public chatbot is less likely to create a data breach, and a worker who understands that an AI-generated market report may contain errors is more likely to verify it before sending it to the chief executive.

PAYE Tax Calculator

Note: The results are not exact but very close to the actual.