Exploring Shadow AI
Exploring Shadow AI

When did Grammarly become “AI”… and why does it suddenly feel risky?

annette wilson

Written by Annette Wilson, Microsoft Implementer & TrainerShackleton Technologies

Exploring Shadow AI

This topic came up in a conversation recently.

“We’ve used Grammarly for years… but now it’s AI? Does that mean it’s learning from what I write? Is that still secure?”

Nothing about the tool had changed overnight.
 
But the way we were thinking about it definitely had.

The reality: it was always AI (we just didn’t call it that)

Tools like Grammarly haven’t suddenly become intelligent.
 

They’ve always relied on things like:

  • Machine learning
  • Natural language processing
  • Pattern recognition
 
That’s how they:
 
  • Spot grammar and spelling issues
  • Suggest tone improvements
  • Help rephrase sentences
 
In many ways, these features have been quietly embedded into tools for years. Spellcheck evolved into grammar suggestions, which evolved into tone and style recommendations.
 
What’s different now is the label. 

We’re calling it AI — and that changes how people feel about it.
 
It turns something familiar into something that suddenly feels… new, more powerful, and perhaps slightly less understood.

So…is Grammarly using your data?

This is the question that usually follows.
 
The answer isn’t black and white — it sits somewhere in the middle.
 
  • Grammarly analyses your text while you’re using it to provide suggestions
  • It may use content for **“product improvement and model training”**¹
  • For many individual users, this has historically been enabled by default¹
  • There are now settings where you can turn this off¹
 
They also state that:
 
  • You keep ownership of your writing
  • They don’t sell your content
  • Data is protected and encrypted²
 
So no, it’s not doing anything particularly unusual compared to many modern tools.
 
But the important shift is this:

Once you realise AI is involved, you start asking questions you perhaps didn’t ask before.

And quite rightly. 
 
Because the moment people hear “AI”, the assumption often becomes:
 
  • “Is this being stored somewhere?”
  • “Is it being reused?”
  • “Could someone else see this?”
 
Even if the answers haven’t fundamentally changed, the level of scrutiny has.

Why it suddenly feels different

If you’ve happily used Grammarly for years, the functionality hasn’t really changed.
 
But your awareness has.
 
And with that awareness comes a new level of scrutiny:
 
  • Where is my data going?
  • Is anything being stored or reused?
  • Would I still paste sensitive content into this tool?
 
These are perfectly valid questions. In fact, they’re the right questions.
 
What’s interesting is that many of these questions probably should have been asked before — just without the urgency.
 
AI hasn’t necessarily created the risk. It has simply made the risk more visible.

 

The bigger issue: Shadow IT (and now… Shadow AI)

This is where the conversation gets more interesting — especially for organisations.
 
Shadow IT is essentially:

Technology being used at work without formal approval or visibility from IT³

And AI tools are accelerating this in a big way.
 
Think about what’s actually happening day to day:

  • A browser extension like Grammarly gets installed “to help with writing”
  • Someone pastes content into an AI tool to tidy up wording
  • A quick summary gets generated using a free online tool
  • A document gets uploaded to an external service for translation or rewriting
 
A simple, very real example might be this:

A draft report gets pasted into a free online tool to “tidy it up” — without much thought about what’s in it or where that content is going.

All with good intentions. All genuinely useful.
 
But often:

  • IT teams don’t know these tools are in use
  • Data may be leaving controlled environments
  • Security and compliance policies are being bypassed
 
And importantly…

This isn’t people being reckless — it’s people trying to work more efficiently.

That’s why simply blocking tools rarely works. People will always find something that helps them get their job done faster.

Not all AI tools are equal

This is where it’s helpful to introduce a bit of nuance.
 
There’s a big difference between:
 
Approved, integrated tools
 
For example:
 
  • Microsoft Word Editor (spelling, grammar, rewrite suggestions)
  • Microsoft Copilot within M365
 
In fact, many people don’t realise that Microsoft Editor has been providing AI-powered spelling, grammar and writing suggestions within Word, Outlook and Edge for some time⁴. Because it sits quietly within familiar Microsoft applications, many users don’t necessarily think of it as “AI” in the same way they would Grammarly or Copilot.  

 
These are typically:
 
  • Within your organisation’s tenant
  • Covered by existing security, compliance, and data policies
  • Visible to IT and administrators
 
In this case, the AI capability is brought to the data, within an environment the organisation already controls.
 
Unapproved or external tools
 
For example:
 
  • Browser extensions like Grammarly (depending on deployment)
  • Public AI tools accessed via a web browser
  • Free rewriting or summarisation services
 
These may:
 
  • Sit outside your organisation’s controlled environment
  • Process data outside standard organisational controls
  • Not be covered by corporate policies or protections
 
This is where the risk isn’t necessarily the tool itself — but the lack of visibility and control.

Productivity vs control: the real tension

This is the balancing act most organisations are facing right now.
 
What users see
What organisations see
“This saves me time”
“We don’t know where our data is going”
“It’s just helping me write better”
“Is this content leaving our environment?”
“It’s only a small thing”
“Multiply that across hundreds of users…”

From a user perspective, it feels harmless. From an organisational perspective, it becomes a scale issue.
 
One person using one tool occasionally isn’t the concern. Hundreds of people using multiple tools daily, with potentially sensitive content, is a very different picture.
 
Blocking everything isn’t realistic. Ignoring it isn’t either
The important realisation

Grammarly isn’t really the issue here. It’s just the example that brings everything into focus.
 
Because once you start thinking about it, the question quickly becomes:
 
  • How many tools like this are already being used?
  • Which ones are interacting with company data?
  • Do we actually have visibility of them?
 

And often, the honest answer is: 

“We don’t fully know.”

 
That’s when organisations begin to recognise:

We don’t just have AI — we have unmanaged AI.

A more practical way forward

The answer isn’t to ban tools or create long policies that nobody reads.
 
It’s about being a bit more intentional.
 
For organisations:
 
  • Accept that these tools are already in use
  • Start with visibility — understanding what’s being used and why
  • Provide clear, simple guidance (not overly technical)
  • Offer approved alternatives where possible (e.g. Copilot within M365)
  • Focus on education and awareness rather than restriction

For users:

  • Be mindful of what you paste into external tools
  • Pause before sharing anything confidential or sensitive
  • Check settings around data usage and training
  • Use approved tools where available
  • Ask the question if you’re unsure
 

Final thought

The most interesting part of all this isn’t Grammarly itself.
 
It’s what it reveals. We didn’t suddenly start using AI. We just started noticing it.
 
And that awareness brings a slightly uncomfortable — but important — question:

Makes you wonder… how many tools like this are already in use across your organisation, without anyone really thinking about it?

 

Sources

  1. Grammarly Support – Product Improvement and Training Control
  2. Grammarly Support – Privacy and Security
  3. IBM – What is Shadow IT
  4. Microsoft Support – Microsoft Editor 

#M365Academy #AIAcademy #AILearning #ArtificialIntelligence #AIAdoption #Microsoft365 #CopilotCowork #FutureOfWork  #ShackletonTechnologies

Click below and ‘share’ this article!

Facebook
Twitter
LinkedIn