What it is
Shadow AI is the recruitment-desk version of shadow IT: any AI tool a consultant uses on the job that nobody at the agency has reviewed, approved or can even see. Personal ChatGPT or Claude accounts, browser extensions bolted onto LinkedIn or Outlook, free copilot trials picked up from a LinkedIn post, home-built automations wired through Zapier or Make. Individually each one looks harmless. The point is that none of it runs through the agency's data protection, security or quality-control process, it sits entirely outside any reviewed workflow.
The term borrows directly from shadow IT, the older problem of staff spinning up unsanctioned software or cloud tools on their own. Shadow AI is the same failure mode with a sharper edge: instead of a spreadsheet living on someone's laptop, it is a CV, a client's confidential search brief or a candidate's salary history, pasted into a public model the agency has no contract with and no visibility into.
Banning AI does not stop shadow AI. Giving consultants one they do not need to hide does.
Why it matters
Three things break at once. Data leakage: CVs, search briefs and salary data pasted into consumer AI tools leave the agency's control, usually with no data processing agreement in place, which puts a recruitment agency squarely at odds with GDPR's data minimisation and purpose-limitation principles, and with the EU AI Act, which classes recruitment as a high-risk AI use case. Compliance exposure follows directly: if a client or candidate ever asks what happened to their data, or how a message was generated, an agency running on shadow AI has no log to answer with. Quality control is the third casualty, since nobody reviewed the output before it reached a client's inbox, so tone, accuracy and consistency depend entirely on whichever tool one consultant happened to trust that week. Multiply that across a desk where every consultant is quietly running a different unapproved tool, and no two clients experience the same agency.
This is not hypothetical. Workforce surveys consistently find that a majority of employees already use AI tools their employer has never sanctioned, and that share is highest in exactly the data-heavy, deadline-driven roles recruitment sits in. A blanket ban rarely fixes it, it just pushes the behaviour further out of sight. What actually works is giving consultants an approved system good enough that reaching for a personal tool stops being worth the risk.
How boilr handles it
boilr removes the reason shadow AI exists in the first place. Instead of a dozen consultants each experimenting with a different unapproved tool, every consultant gets one AI sales employee that already does the work they might otherwise hand to a personal account: finding and enriching companies, sourcing candidates, watching for buying signals and drafting outreach. It runs inside the agency's own approved system, not a browser extension nobody signed off on, and every action it takes is logged and auditable.
The design is human-in-the-loop by default: drafted tasks land in a shared inbox for the consultant to review, edit and send, so nothing leaves the building unchecked, and there is always a record of what was sent and why. Whatever a consultant's employee learns, from a winning subject line to a tricky account, is captured in the Company Brain instead of trapped in a private tool or account, so it stays with the agency instead of walking out when that consultant does.