Shadow AI Is Really About Who Owns How You Think

People are building a working version of how they think in personal AI accounts, and they're keeping it away from their employers on purpose.

Part one of three

Silhouetted person working on a laptop beside a rain-streaked window at night.

We’ve been writing about shadow AI for eight months, and the argument keeps shifting under us. It started as a data problem: sensitive, finance-related information landing in unapproved public tools, with the breach risk that comes with it. Then it moved to leadership: firms bolting Microsoft Copilot onto existing licenses instead of tools that fit daily work, or rushing an investment and ending up with something nobody asked for. 

Most recently we’ve argued shadow AI is a demand signal: the tools people reach for are a map of what to fix, so the answer is to find out what’s being used and deploy something better.

That’s a healthier place for the debate to land. But we don’t think unapproved AI goes away even once the right tools are in place. Here’s why.

Take a researcher at a mid-size firm, someone with two ChatGPT accounts. One is the company account, which is logged, reviewed, and fully within policy. The other is personal, paid for out of her own pocket, and it’s where she does her thinking. Years of context, half-formed ideas across business and personal topics in the shorthand she’s built up so she doesn’t have to explain herself from scratch every time. She’d never move that over to the company account.

It’s not that she’s hiding anything shady, it’s that it feels like handing over a piece of how her mind works to an employer who might make her redundant next year and keep the workflow running without her.

What looks like a compliance problem is really an ownership problem. Firms think policy can fix it. But the people keeping their real thinking in personal accounts already know the rules. What the rules don’t cover is what happens to the thinking once it’s handed over. 

Those personal accounts are becoming a working version of how they think. For some people, it may end up as commercially valuable as a contact book once was. That points to something firms haven’t caught up with yet: a future where people negotiate salary for their labour and, separately, access terms for their AI-shaped expertise.

Shadow AI is the first visible fight over that. 

The ownership problem underneath

Firms have never owned the intangible side of how someone works. The instinct an account director has for when a client’s about to churn, three months before it shows up in the numbers. A framework for managing this might be easy to write. Years of pattern-matching to know when to break it aren’t. 

That boundary has been fought over for decades: an account director who leaves and takes her client relationships with her, a salesperson who walks off with the contacts she built on the company’s time. Courts have spent just as long working out who owns a contact book through restrictive covenants, garden leave and springboard injunctions. A whole body of law has grown around one question: does the relationship belong to the person who built it, or the firm that paid for the hours she spent building it? 

Judgement capital raises the same question, just over different material. Not the client list this time, but the reasoning that told her which client was worth chasing and when. 

What’s changed is that it can now be logged. That instinct used to stay intangible. There was no way to get at it even if a firm wanted to. It just lived in someone’s head, in relationships that needed the person to keep maintaining them. AI usage doesn’t get that protection: the back-and-forth, the workarounds someone’s built for getting good output, all of it sits in a database somewhere, accessible to the firm, the moment it runs through an approved company tool.

Part of what makes the personal account valuable is that it’s stayed off employer systems, unlogged and unreviewed by anyone but her. So what looks like secrecy is people avoiding the one form of tacit expertise that’s suddenly capturable, whereas every other form always got to stay theirs by default.

The two-tier distinction

Some of what sits in a personal AI account is just hygiene, call it tier one: a spreadsheet that patches a CRM export because it drops half the fields, or a manual fix somebody reruns every Tuesday because two systems still don’t talk to each other. None of it is special. It’s evidence that something earlier in the process is broken. Most people would rather hand the fix over than keep doing it manually forever, as long as admitting the workaround exists doesn’t get them blamed for the system being broken in the first place.

Then there’s judgement capital, tier two: the read a specialist has built up over years, the thing they were actually hired for. It’s an analyst’s instinct for which numbers don’t add up before the model shows it, or the moment a strategist knows the plan on the table just isn’t going to hold.

It’s the reason the person is worth what they’re paid, and surrendering it costs them their leverage while the firm gives up nothing in return.

Most firms apply one policy to both categories. A blanket ban catches the hygiene fixes that should have been surfaced months ago. It does nothing to the judgement capital, which was never going through the approved tool anyway.

Once you see those as different problems, the usual fixes look inadequate. Bans, monitoring, even the return-to-office push, all treat this as one problem with one solution.

Part two looks at why those fixes don’t work, and what changes the incentive.