Definition
What Is Shadow AI?
Staff using an unsanctioned model on firm work. The case system never sees the prompt. The model still answers.
Updated September 9, 2026.
Written by Jonathan Mahler · Reviewed by Jonathan Mahler, Founder of FirmOps. Operator notes, not legal advice.
Shadow AI is staff using a generative model the firm did not approve, on work the firm is responsible for, usually in a personal ChatGPT or Claude tab. The case system never sees the prompt. The model still answers. The owner finds out when a made-up citation lands in a draft, or never finds out at all.
Key Takeaways
- Shadow AI is unsanctioned generative AI on firm work, usually a personal tab with a pasted fact pattern.
- It is not "staff being creative." It is a second, invisible stack with no system of record, no log, and no approval gate.
- ABA Formal Opinion 512 requires competence, confidentiality, and supervision when lawyers use generative AI.[1]Formal Opinion 512
- A read-first firm brain is the alternative: the file is in view, drafts park, a human sends.
- A policy without a path staff will actually use is how shadow AI wins on a Tuesday afternoon.
How shadow AI works
Someone has a letter to write. Clio is slow. The model in the browser is fast. They paste a chronology, a medical summary, a demand outline. They get a draft in sixty seconds. They clean it up. They send it, or they drop it into Word and send it from there.
Nothing in the matter notes says a model was used. Nothing in the document store holds the prompt. If the output cites a case that does not exist, the first person to notice may be the other side.
That is the mechanism. Speed plus no official path. You do not need a rogue employee. You need a bottleneck and a browser.
Why firms get it
Legal AI adoption is not even. ABA TechReport figures on office use sit well below "any tool" surveys. The gap is not mystery. It is shadow use. Seats go unused because they are the wrong surface. Personal tabs get used because they are the surface staff already live in.
Opinion 512 does not ban generative AI. It says lawyers remain responsible for the work: competence with the tool, confidentiality of client information, candor to tribunals, supervision of nonlawyers, and reasonable fees.[1]Formal Opinion 512 A personal ChatGPT session with a pasted medical chronology is the confidentiality problem in one screenshot.
Hallucinated citations are the version that makes the news. The quieter version is a conflict fact, a Social Security number, or a child's name sitting in a consumer log the firm cannot delete.
Example
A paralegal is behind on provider follow-ups. She pastes five matter summaries into a free account because the firm "has not picked a tool yet." Three drafts are fine. One invents a date of service. She does not catch it. The letter goes out. The CMS still shows the correct date. The letter does not. That is shadow AI: two files, only one of them is the system of record.
The read-first version of the same job reads the matter and the last letter, parks a draft, and waits for a person. The CMS stays the file. The model never holds send.
The thing people get wrong
Banning ChatGPT does not end shadow AI. It hides it. Staff will use whatever finishes the pile. The control that works is an approved path that is faster than the personal tab: a firm brain on the stack they already run, approval gates on the way out, and a policy that names the allowed tools instead of a PDF nobody opens.
Informed consent for generative AI belongs in that policy when the use affects the representation. It is not a separate product page. It is a conversation the attorney owns. FirmOps does not give legal advice on that call. We wire the path so the unsanctioned tab is no longer the fastest way to do the job.
Shadow AI vs a managed firm brain
Shadow AI lives in a personal account. It sees a paste. It can send if the human treats the output as done. There is no log the firm owns.
A Managed Firm Brain lives on approved systems. It sees the file read-first. Drafts park. A named human releases anything that leaves the building. The CMS remains the system of record.
CMS AI inside Clio or Filevine is not shadow AI if the firm turned it on on purpose. It is still not a firm brain. It sees one app. Comparison: CMS AI vs a firm brain.
Frequently Asked Questions
What is shadow AI in a law firm?
Staff using an unsanctioned generative model on firm work, usually a personal ChatGPT or Claude tab, with no log in the case system.
Is ChatGPT at work always shadow AI?
No. If the firm approved the tool, set a data boundary, and named who reviews output, it is sanctioned use. If it is a personal account and a paste, it is shadow AI.
Does ABA Formal Opinion 512 ban generative AI?
No. It requires competence, confidentiality, candor, supervision, and reasonable fees when lawyers use it.[1]Formal Opinion 512
How do we reduce shadow AI without slowing the firm?
Give staff a faster official path. Read-first on the real file, drafts that park, human approval before send. A ban with no path loses.
The Bottom Line
Shadow AI is the firm running AI without running AI. The work still happens. The file just is not in the room. Put the file in the room. Request a demo around one job staff currently finish in a personal tab.
Related terms
- Read-first
- Approval gates
- Law firm AI policy
- What is a firm brain?
- Legal AI adoption
- Managed Firm Brain
- Glossary
Article Sources
- Formal Opinion 512 Accessed September 9, 2026. ↩
Get the Managed Firm Brain Notes
Follow the practical path: live workflow builds, CRM-aware automation when the data is ready, and supervised work after approval.
Demo Context
What to watch for in the Managed Firm Brain walkthrough
Live-Lab Proof
How Conduit informs the first external deployments
Fit Criteria
API-ready systems, workflow scope, and approval gates
Next step
Bring the job staff currently finish in a personal tab.
If the official path is slower than ChatGPT, shadow AI wins. The demo is one recurring workflow on the stack you already run.