Your firm already rolled out AI. Nearly half of it is running on personal accounts you can't see, under consumer terms you never agreed to. Here is how a firm admin takes that back without playing cop.
Netskope's 2026 Cloud and Threat Report puts a number on what firm admins suspect but can't see: 47% of people using generative AI at work do it on personal accounts. In an accounting firm, that means client work product in consumer chatbots. A trial balance pasted into a free ChatGPT window. An engagement letter drafted in someone's personal Claude account. A 1099 recipient list summarized by whatever tool a seasonal hire used at their last job.
The same report counts the damage: the average organization logged 223 gen-AI data policy violations per month last year, more than double the year before. A violation is someone pasting something they shouldn't. In a firm, "something they shouldn't" has names, SSNs, and a GL attached. Your professional liability carrier is already asking about it at renewal. The engagement-letter half of this problem was Issue 9; this is the operational half.
Here is the part most firms get wrong: banning tools makes the number worse, not better. A ban does not stop a staff accountant who just watched Claude cut a memo from two hours to twenty minutes. It moves her to a personal account on her phone, where you have zero visibility instead of partial. Shadow AI is not a discipline problem. It is a product problem: your sanctioned option is losing to a consumer app.
The proof sits in the same Netskope data. Where organizations provided managed AI accounts, usage on them jumped from 25% to 62% in a year. People are not trying to sneak. They are taking the fastest route to done. When the firm account is as capable as the personal one and easier to reach, the personal one loses on its own.
So the firm-admin play is two moves. One: give staff a sanctioned tool under business terms. Claude Team or Enterprise, Copilot under your Microsoft 365 tenant, whichever fits your stack. Business terms mean the provider does not train on your data, you control retention, and you can see usage. Two: write a one-page AI policy in plain language. What can be pasted, what can't, which account to use, who to ask. Client names and identifiers: managed account only. Credentials: never, anywhere. Fourteen pages of legalese gets skimmed once and ignored. One page gets followed.
The AICPA's 2026 Top Issues Survey (Journal of Accountancy, June 2026) put technology change management, with AI at its center, at the top of the list for every firm segment, with staffing close behind. If AI governance is not on your ops agenda yet, your peers just voted it there.
Anthropic's July update gives Team and Enterprise admins usage and cost analytics by user and group, model-level entitlements, spend alerts, and a Compliance API for programmatic audit and retention. Translation for firm admins: the visibility argument for the managed account just got stronger.
Nudge Security in May became the first platform to discover shadow AI agents through the browser, beyond what APIs expose. An unsanctioned chatbot leaks what someone pastes. An unsanctioned agent acts: filing, emailing, reconciling. Inventory both.
The Journal of Accountancy's July issue walks through what agents that draft returns, run reconciliations, and assemble memos mean for firms. The governance point: an agent holds credentials and takes actions, so "which account is it running under" stops being an IT detail and becomes a control.
The trend is the story. A year ago 78% of workplace AI ran on personal accounts; now it is 47%, and managed-account usage climbed from 25% to 62%. The number moved because organizations provided sanctioned tools, not because anyone wrote a sterner memo. The half still in the shadows is the half whose employer has not given them a better option yet.
What it is: A SaaS and AI discovery platform that inventories every app and account in use across the firm, including the shadow ones, by reading signals like OAuth grants and sign-up emails instead of requiring agents on every device. In May it added browser-based discovery of shadow AI agents.
What it does well: Turning "I think people are using things" into a named list: who signed up for what, with which email, when. Its signature move, the nudge, steers users toward the sanctioned alternative automatically instead of routing everything through a disciplinary conversation. For a firm admin who wants adoption without playing cop, that posture is the product.
What it doesn't do well: It discovers and nudges; it does not decide. It will not write your AI policy, pick your Claude tier, or tell you whether a tool's terms are safe for client data. And a five-person firm does not need a platform for this: an anonymous staff survey plus your Google Workspace or Microsoft 365 OAuth log surfaces most of the same list for free.
Pricing: Quote-based per-employee SaaS with no public price list, and reviewers flag it as steep for smaller teams. Get a real quote against your headcount before assuming it fits a sub-10-seat budget, and price it against the hours you would spend building the same inventory by hand.
Shadow AI ends the same way in every firm I've watched: not with a ban, with a better sanctioned path. First, the standing rule, tax-software parity: client-identifying data goes into Claude on Team or Enterprise only, the same trust posture you already extend to your tax software and client portal. Credentials are the only bright line. No portal logins, no EFINs tied to passwords, no banking credentials, on any tier. A personal Pro account fails the parity test on terms, not model quality: no admin visibility, no firm-controlled retention, consumer data defaults.
(1) SSO + domain capture: anyone signing up with a firm email lands in the managed workspace, not a personal account.
(2) Retention: set the firm's policy explicitly. Don't inherit defaults.
(3) Analytics: turn on per-user usage and cost reporting. Review monthly.
(4) Entitlements: limit models and settings to what your one-page policy covers.
Why the July update matters: the weakest part of the managed-account pitch used to be that admins could not see much. That is gone. Usage and cost by user and group, spend alerts, and a Compliance API that lets Enterprise firms pull usage data into whatever monitoring their carrier or peer reviewer wants to see. The tooling now backs the governance story your renewal questionnaire is asking for.
The rule: you do not beat shadow AI with a memo. You beat it by making the sanctioned account the fastest way to get work done, then reading the usage report monthly. Every firm I've watched shrink its shadow-AI number did it with a better tool, not a sterner policy.
Run a shadow AI amnesty this week. Send staff three anonymous questions: Which AI tools did you use in the last 30 days? On a personal or firm account? For what kind of work? Promise no consequences and mean it. Then compare the answers against what your admin console and OAuth logs show. Thirty minutes to send, and you will know your real number before your carrier, or a client, asks for it.
P.S. Firm admins: reply with your shadow-AI number once the amnesty answers land. I'm collecting them, anonymized, for a future Security Desk on what firms actually found.

