What your staff are already doing with AI (and why no policy is the real risk)

Date

August 9 2026

mr club

Date

August 9 2026

Shadow adoption is already happening in your firm. The risk is not the tool; it is the absence of a decision about what data may leave, what output can be relied on, and who is responsible.

Walk through most Mauritian professional firms and you will find the same pattern: at least one person is using a consumer AI tool to draft an email, summarise a document, or check a clause. Often they are doing it well. Almost as often, they are doing it without anyone senior knowing, without a record, and without a rule about what can and cannot be pasted into a chat window.

This is shadow adoption. It is not a technology problem. It is a governance problem wearing a technology mask.

What "shadow" actually looks like

It is not dramatic. It is a junior associate asking a chatbot to rephrase a client letter. It is a manager pasting a contract summary into a tool to get a quick translation. It is a fee-earner using an AI writing assistant for a memo because the firm has not approved or supplied an alternative.

Each case shares three features:

  • No log. Nobody can reconstruct what was entered, what was produced, or what was sent on.
  • No classification. The user decides, in the moment, whether the information is sensitive.
  • No review. The output is used without the checks the firm would apply to work produced by a human.

Why the absence of a policy is the real risk

A bad policy is at least visible. A missing policy means every decision is made ad hoc by the person who happens to be holding the file. That is where privilege, confidentiality and data-protection obligations start to fray.

For Mauritian law firms, the problem is sharpened by the Data Protection Act 2017 and by the rules on professional secrecy. A firm cannot say it took reasonable steps to protect client information if it never told its staff what reasonable steps were.

What a partner should do this week

  1. Ask. Run a short, anonymous survey asking which tools staff have used for work in the last month and what they used them for. [DECISION, survey design and whether to run internally or with support.]
  2. Decide. Draft a short acceptable-use statement: approved tools, prohibited uses, and what must never leave the firm.
  3. Provide. Give people a better option for the legitimate uses they have already found. Prohibition without provision simply pushes the behaviour further into the shadows.
  4. Record. Keep a register of approved tools, data-flow decisions and incidents. Regulators and clients increasingly ask for this.

The right first document

Most firms do not need a forty-page policy on day one. They need a one-page statement that the partnership can stand behind, plus a training session that makes the rules real. We have published a starting template for professional firms in Mauritius, which you can adapt to your own obligations and risk appetite.

The firms that get ahead of this are not the ones with the most advanced AI. They are the ones with the clearest rule about who decides what data goes where.