Shadow AI Agents Are Already Inside Your Firm
Your junior associates are running AI agents right now. So are your paralegals. They installed a Chrome extension last week that “summarizes depositions in one click” or signed up for a tool that “auto-drafts discovery responses.” They didn’t ask IT. They didn’t check your security policy. They saw a demo on LinkedIn, clicked install, and connected it to your firm’s Google Workspace or Microsoft 365 account.
That agent now has access to client files, matter correspondence, and privileged work product. It’s sending data to a third-party API you’ve never heard of. If that vendor gets breached or the agent logs sensitive information for training purposes, you’re looking at a bar complaint, a malpractice claim, and a very uncomfortable conversation with your malpractice carrier.
This isn’t a hypothetical. Shadow AI agents are multiplying across law firms because the barrier to deployment is zero. A paralegal can add a browser extension in fifteen seconds. An associate can sign up for a SaaS tool with their firm email and start feeding it client data before lunch. Most of these tools are legitimately useful, which is why your team adopted them. But useful doesn’t mean secure, and adoption without oversight is how firms end up in front of a disciplinary board.
The Shadow AI Problem Is Structural
Shadow IT has been a problem for years. Shadow AI is worse because the tools are designed to ingest and process sensitive information. A paralegal using Dropbox without permission is a policy violation. A paralegal using an AI agent that reads every email in a client matter and sends summaries to an external server is a data breach waiting to happen.
The typical firm has no idea how many of these agents are running. IT doesn’t see them because they’re browser-based or accessed through personal accounts. Partners don’t see them because associates and staff are trying to keep up with workload without asking for more budget. The agents sit in the background, quietly processing documents, drafting emails, and accessing shared drives.
Here’s what we see when we audit firms: browser extensions with “read and change all your data on the websites you visit” permissions, SaaS tools that authenticate via OAuth and request access to email and calendar, and desktop apps that scan local folders for PDFs and Word files. Most were installed in the last six months. None were approved by anyone with authority to evaluate data security.
The risk isn’t that your team is malicious. It’s that they’re trying to do their jobs faster and the tools they’re finding don’t come with a security review. An associate who’s drowning in document review will install anything that promises to cut the work in half. A paralegal managing intake for three partners will sign up for a tool that auto-responds to new leads. They’re solving real problems, but they’re creating bigger ones.
What These Agents Actually Do
Shadow AI agents fall into a few categories. The first is browser extensions. These sit in Chrome or Edge and offer features like “summarize this webpage,” “draft a response to this email,” or “extract key terms from this contract.” They’re marketed to professionals who spend all day in a browser. Installation takes one click. Permissions are buried in a dialog box most people don’t read.
The second category is SaaS tools that integrate with your firm’s existing platforms. An associate finds a tool that connects to Outlook and “automatically triages your inbox.” They authenticate with their firm email, grant the tool access to read and send messages, and it starts processing everything. The tool might be hosted overseas. It might log every email for training data. Your firm has no contract with the vendor, no data processing agreement, and no way to audit what’s happening to client information.
The third category is desktop apps. These are tools that run locally but scan your file system or sync with cloud storage. An associate downloads an app that “uses AI to organize your research memos.” The app requests access to their Documents folder, which includes matter files synced from the firm’s shared drive. Now client data is sitting in an app’s database, and you have no idea where that database lives or who can access it.
All three categories share the same problem: they’re designed to be frictionless. No procurement process, no IT approval, no security review. That’s the feature. It’s also the vulnerability.
The Bar Complaint You Don’t See Coming
Most firms think about cybersecurity in terms of ransomware or phishing attacks. Those are real threats, but shadow AI agents are a different risk profile. The breach doesn’t come from an attacker. It comes from a tool your team installed on purpose.
When a shadow AI agent leaks client data, the fallout is immediate. If the agent was processing privileged communications and those communications end up in a vendor’s training dataset or get exposed in a breach, you’ve potentially waived privilege. If the agent was handling matter files and the vendor’s terms of service include a clause that grants them a license to use uploaded content, you’ve given a third party rights to your client’s information.
The state bar won’t care that your associate was trying to be efficient. They’ll care that you failed to supervise the use of technology in a way that protects client confidentiality. Rule 1.6 and Rule 1.1 (the duty of competence, which now includes understanding technology) don’t have an exception for “we didn’t know the tool existed.”
Your malpractice carrier will ask why you didn’t have controls in place. They’ll want to see your technology use policy, your training records, and evidence that you monitored third-party integrations. If you can’t produce those, you’re arguing that you had no system to prevent exactly this kind of exposure. That’s not a strong position when you’re trying to avoid a coverage denial.
How to Find Shadow AI Agents Before They Cause a Problem
The first step is an inventory. You need to know what’s running. Start with browser extensions. Most firms use Chrome or Edge in a managed environment, which means IT can pull a report of every extension installed across the organization. If you’re not managing browsers centrally, you’ll need to audit manually. Ask every attorney, paralegal, and admin to screenshot their extensions page and send it to IT.
Look for anything that mentions AI, automation, summarization, or drafting. Read the permissions. If an extension can “read and change all your data on the websites you visit,” it can see everything you do in your practice management system, your email, and your document management platform. That’s too much access for a tool you didn’t vet.
Next, audit SaaS integrations. If your firm uses Google Workspace, go to the admin console and check third-party app access. You’ll see every app that’s been granted OAuth access by anyone in the organization. If you’re on Microsoft 365, check the enterprise applications list in Azure AD. Look for tools you don’t recognize, especially anything that has permissions to read email, access files, or send messages on behalf of users.
For desktop apps, this is harder. You’ll need endpoint management software that can inventory installed applications, or you’ll need to ask users directly. Focus on roles that handle high volumes of documents: associates doing discovery, paralegals managing intake, and anyone who works with contracts or pleadings. Ask what tools they’re using that weren’t provided by the firm.
Once you have the inventory, evaluate each tool. Does it process client data? Where is that data stored? Does the vendor have a data processing agreement? Is the tool hosted in a jurisdiction with strong data protection laws, or is it routing information through servers you can’t audit? If you can’t answer those questions, the tool needs to be disabled until you can.
What Authorized AI Agents Look Like
The goal isn’t to ban AI. It’s to replace shadow agents with tools you control. When we build AI agents for law firms through the AI audit for law firms, we start with the same pain points your team is trying to solve with unauthorized tools: intake delays, document review backlogs, and matter triage.
An Intake Voice Agent answers every call, even at midnight on a Saturday. It asks the caller about their legal issue, runs a conflict check against your matter database, captures their contact information, and books a consultation directly into the right attorney’s calendar. It doesn’t send data to a third-party API you’ve never heard of. It runs on infrastructure you control, with logging and access controls that meet bar requirements.
A Matter Triage Agent processes new form submissions and emails, classifies them by practice area, scores them for fit, and routes them to the appropriate partner with a brief summary attached. It doesn’t require a paralegal to install a browser extension that reads every email. It integrates with your existing systems through APIs you’ve approved, and it doesn’t store client data in a vendor’s training dataset.
A Document Review Agent performs first-pass review on contracts, discovery batches, and matter files. It flags key clauses, summarizes positions, and produces an associate-grade memo. It doesn’t run in a Chrome extension with permissions to “read and change all your data.” It operates in a secure environment with audit trails, version control, and the ability to produce work product that’s defensible if challenged.
The difference between these agents and the shadow tools your team is installing is governance. You know where the data goes. You have a contract with the vendor. You can audit what the agent does. If something goes wrong, you have recourse. With a shadow AI agent, you have none of that.
The Omni Audit Finds What You Don’t Know Is Running
Most firms don’t have time to manually audit every browser extension, SaaS integration, and desktop app. That’s where the Omni Audit comes in. It’s a 60-minute session where we map your current workflow, identify where shadow AI is most likely to be running, and show you what controlled AI agents would look like in those same spots.
We don’t hand you a deck. We give you three outputs: a process map of your highest-risk workflows, a shadow AI exposure assessment that prioritizes what to fix first, and a build plan for the agents that replace the unauthorized tools your team is already using. Book a 60-min Omni Audit and we’ll show you exactly where the gaps are.
The audit starts with intake because that’s where most shadow AI shows up first. Paralegals and junior associates are drowning in after-hours calls and web form submissions. They’re installing tools that promise to auto-respond or route leads. Those tools work, which is why they spread. But they’re also processing prospective client information without any oversight. If you’re a personal injury or family law firm, that’s sensitive data from people who haven’t signed an engagement letter yet. If that data leaks, you’re explaining to the bar why you let an unapproved tool handle it.
We also look at document review. Associates are using AI tools to summarize depositions, extract terms from contracts, and draft discovery responses. Some of these tools are good. Most weren’t evaluated by anyone who understands your ethical obligations. The audit identifies which tools are running, what data they’re accessing, and how to replace them with agents that do the same work under your control.
If you want a practical starting point before the audit, we’ve built a worksheet that walks through the most common intake vulnerabilities. The AI Client Intake Checklist for Law Firms covers the questions you should be asking about any tool that touches prospective client data, including the shadow agents your team is already using. It’s a 10-minute exercise that will surface risks you didn’t know you had.
The Dollar Cost of Waiting
Firms in the 1M-25M range typically lose between 80K and 250K per year to the inefficiencies that shadow AI is trying to solve. That’s billable time spent on work that never makes it onto an invoice, intake that converts at half the rate it should, and document review that costs $300 per hour when it should cost $50.
Your team knows this. That’s why they’re installing tools without asking. They’re trying to close the gap between the work that needs to be done and the hours available to do it. The problem is that every unauthorized agent they install increases your exposure. If one of those tools causes a breach, the cost isn’t just the lost revenue from inefficiency. It’s the malpractice claim, the bar complaint, the notification letters to affected clients, and the reputational damage that comes with being the firm that couldn’t keep client data secure.
The firms that are handling this well aren’t banning AI. They’re giving their teams authorized tools that solve the same problems. They’re running audits to find shadow agents before they cause a breach. And they’re treating AI governance as a risk management issue, not an IT project.
What Happens After You Find Them
Once you’ve identified shadow AI agents, you have three options. The first is to disable them immediately and accept the productivity hit. That works if the tool was marginal, but if your team was relying on it to keep up with workload, you’ll just push them toward a different unauthorized tool.
The second option is to evaluate the tool and bring it under governance. That means getting a data processing agreement from the vendor, reviewing their security practices, and ensuring the tool meets your ethical obligations. This works for tools that are well-designed and come from vendors who understand legal compliance. It doesn’t work for the majority of shadow AI agents, which were built for a general audience and don’t have the controls a law firm needs.
The third option is to replace the shadow agent with a controlled one that does the same job. This is the approach we take with Omni for law firms. We don’t tell your team to stop using AI. We build agents that solve the same problems under a governance framework you can defend. The agent does the work your team needs done, but it does it in a way that protects client data and meets bar requirements.
Most firms end up with a mix of all three. Some shadow agents get disabled immediately because they’re too risky. Some get evaluated and brought under governance if the vendor is willing to meet your requirements. And the most critical workflows get replaced with controlled agents that your team actually wants to use.
Building a System That Prevents the Next Wave
Finding and fixing shadow AI agents is the first step. Preventing the next wave requires a system. That means a technology use policy that’s specific about AI, training that explains why unauthorized tools are a problem, and a process for evaluating new tools before they get deployed.
The policy should be clear: no AI tool that processes client data can be installed or accessed without IT and management approval. That includes browser extensions, SaaS tools, and desktop apps. It should also define what counts as client data, because your team won’t always recognize that a “summarization tool” is processing privileged communications.
Training should cover the risks in concrete terms. Don’t talk about “data security” in the abstract. Walk through a scenario where an associate installs a tool that leaks a client’s medical records, and explain what happens next. Show them the bar rule they violated. Show them the malpractage claim. Make it real.
The evaluation process should be fast. If your team has to wait three months for IT to approve a tool, they’ll install it anyway. Build a workflow where someone can submit a tool for review, IT evaluates it within a week, and the decision is communicated with reasoning. If the tool doesn’t meet your requirements, explain why and offer an alternative. If your team is asking for a document summarization tool, don’t just say no. Point them to the Document Review Agent you’ve already built.
You’ll also need monitoring. Even with a policy and training, some people will install unauthorized tools. Use endpoint management software to track installed applications. Use your email and identity platform to monitor OAuth grants. Set up alerts for new integrations. The goal isn’t to catch people violating policy. It’s to catch tools before they cause a breach.
The Firms That Get This Right
The firms handling shadow AI well are treating it as a governance problem, not a technology problem. They’re not trying to lock down every endpoint. They’re giving their teams better tools and making it easier to use authorized agents than unauthorized ones.
One mid-sized litigation firm we work with had 14 shadow AI agents running when we did the audit. Most were browser extensions installed by associates doing document review. The firm didn’t disable them immediately. They built a Document Review Agent that did the same work, trained the associates on how to use it, and then deprecated the extensions. Adoption was fast because the authorized agent was better than the shadow tools.
Another firm focused on intake. Paralegals were using an unauthorized tool that auto-responded to web form submissions. The tool worked, but it was sending prospective client data to a server in a jurisdiction with weak data protection laws. The firm replaced it with an Intake Voice Agent and a Matter Triage Agent that handled the same volume with better accuracy. The paralegals preferred the new system because it integrated with the firm’s calendar and practice management platform.
Both firms now have a process for evaluating new tools. When someone asks for an AI feature, IT checks whether an authorized agent already does it. If not, they evaluate the tool and either approve it or build an alternative. The key is speed. If the evaluation takes two weeks instead of two months, people don’t bypass the process.
Start With the Audit
If you’re not sure whether shadow AI agents are running in your firm, the answer is yes. The only question is how many and how much client data they’re accessing. The fastest way to find out is to run an audit that’s designed for law firms. Book my Omni Audit and we’ll map your exposure in 60 minutes.
You’ll walk away with a clear picture of where shadow agents are running, what data they’re accessing, and how to replace them with controlled agents that do the same work without the risk. No deck, no sales pitch. Just a process map, an exposure assessment, and a build plan you can act on immediately.
The firms that wait until after a breach are explaining to the bar why they didn’t have controls in place. The firms that act now are building systems that let them use AI without the exposure. If you want to see what’s running before it becomes a problem, the audit is where you start.