Shadow AI in Finance: When Draft Quarterly Numbers End Up in ChatGPT
Most employees use AI; few use approved tools. Pasting draft financials into public chatbots triggers data leaks. A governed numbers layer replaces the shadow tool.
By The Rexfin team
A financial analyst has a deadline at 6 p.m. and a board pack that won’t reconcile. The approved BI tool can’t answer the question fast enough, so she copies three columns of unreleased quarterly revenue into a public chatbot and asks it to find the discrepancy. Two minutes later she has an answer. She also has a problem she doesn’t know about yet: material non-public financial data has left the building, into a system her company doesn’t control, doesn’t log, and can’t recall.
That scene plays out far more often than most finance leaders assume. Survey after survey through 2025 landed on the same uncomfortable picture. A November 2025 UpGuard report found that more than 80% of workers use unapproved AI tools at work, and that security professionals do it at an even higher rate. Roughly half say they use unsanctioned tools regularly, while fewer than one in five say they stick only to company-approved AI. The gap between “people using AI” and “people using AI we sanctioned” is the entire problem in one sentence.
The paste is the breach
The risk isn’t abstract. It’s the clipboard.
LayerX Security reported that 77% of employees paste sensitive company data into generative AI tools, and that 82% of those pastes come from unmanaged personal accounts. Read that second number again. When the paste happens through a personal ChatGPT or Gemini login, the employer has no visibility, no audit trail, and no contractual data-processing relationship with the AI vendor. Cyberhaven’s analysis of real enterprise prompts found that about 11% of what employees paste into ChatGPT is confidential. The categories that show up most: source code, internal financials, customer PII.
Finance is uniquely exposed here, for three reasons.
First, the data is the crown jewels. Draft consolidations, unannounced margins, pre-release earnings, M&A models. This is exactly the material that securities regulators treat as inside information.
Second, the work is repetitive and formula-heavy, which is precisely the kind of task an analyst is tempted to offload. “Reconcile these two trial balances.” “Explain why this variance is off by 4%.” “Reformat this cash flow.” All reasonable asks. All dangerous when the input is a live ledger extract going to a public endpoint.
Third, finance sits inside a compliance perimeter most other departments don’t. Under the GDPR, pasting customer or employee personal data into a public chatbot can constitute an unlawful transfer with no legal basis and no processing agreement. If the figures are unreleased and the company is listed, you’ve potentially layered an insider-information leak on top of the privacy violation. One paste, two regulatory exposures.
Why bans don’t work
The instinct is to prohibit. Block the domains, write a policy, run a training module. It rarely holds, and the data says so plainly: a Software AG study of 6,000 knowledge workers found 46% would keep using AI tools even if their employer banned them outright. People aren’t being reckless for sport. They’re being measured on output, the tool is genuinely faster, and the official stack didn’t give them an answer they could trust in time.
So shadow AI isn’t really a discipline problem. It’s a product gap. The analyst reached for ChatGPT because nothing inside the sanctioned environment let her interrogate the numbers conversationally and get a reliable answer. Close that gap and the incentive to paste disappears. Leave it open and no policy survives a 6 p.m. deadline.
What a governed numbers layer actually replaces
The goal isn’t to give finance a “safe ChatGPT.” A chatbot pointed at your ledger is still a language model guessing at arithmetic, which is its own failure mode. The goal is to make the fast, conversational way to query your numbers also be the governed, accurate, auditable way. That removes the reason to go outside.
This is the layer Rexfin is built to be. It connects to the systems where the numbers already live, QuickBooks, Xero, NetSuite, Sage, SAP, Oracle, your warehouse, or to statements you upload, and builds one reconciled financial model that ties out to the ledger. See the supported integrations for the connectors. From there the mechanics matter, because the mechanics are what make it safe to use instead of the shadow tool:
- The data stays inside your governance boundary. Figures are queried within a controlled environment, not pasted into a third-party consumer endpoint. There’s no unmanaged personal account in the loop, and every request is logged. That’s the part a public chatbot can never offer, and it’s covered in more depth on the security page.
- Calculations run on a deterministic engine, not the model. When someone asks for a variance, a margin, or a what-if scenario, the math is computed by a calculation engine, not generated as plausible text by an LLM. The model retrieves and explains; it doesn’t invent the number. How it works walks through that separation.
- Every figure traces to source. Because the model is reconciled to the ledger, an answer can be followed back to the underlying transaction. That’s the difference between an output you can put in front of an auditor and a paragraph from a chatbot you have to take on faith.
There’s an honest limit worth stating. A governed layer doesn’t make the chatbot temptation vanish by decree, and it won’t retroactively unleak anything already pasted last quarter. What it does is remove the practical reason analysts reach outside in the first place, and give security and finance the logs to see usage that previously happened in the dark. Governance you can enforce beats governance you can only declare.
The takeaway
Shadow AI in the finance team is not a story about careless people. It’s a story about a sanctioned toolset that was slower and dumber than the unsanctioned one, on data that happens to be the most regulated material in the company. You don’t fix that with another policy memo. You fix it by making the governed path the fastest path, so the clipboard stays inside the perimeter.
If draft numbers are already moving through tools you don’t control, see what a reconciled, auditable numbers layer looks like in practice and book a demo. Then read the rest of the AI in finance, GoBD and the AI Act pillar, including how your auditor will scrutinize AI-assisted financial figures under IDW PS 861 and what the 2025 GoBD amendment means for your process documentation.
Part of AI in Finance, Audit-Proof: GoBD- and AI-Act-Defensible Models With Traceable Numbers