Shadow AI in EHS: The safety risk no one Is talking about

Your employees may already be using AI to make safety decisions, and you may have no idea when, where, or how it is happening

Shadow AI in EHS: The safety risk no one Is talking about
Abiola Ayodele

Much of the discussion around artificial intelligence in occupational health and safety has focused on formal adoption: AI-powered safety software, computer vision, predictive analytics, connected devices, and other technologies organizations deliberately select, implement, and govern. These applications are visible. They can be evaluated through procurement, risk assessments, cybersecurity reviews, training, and management-system controls. The organization knows the technology exists, understands its purpose, and can establish responsibility for its use. The less visible form of AI adoption is fundamentally different.

The visibility gap

An employee does not need an enterprise AI implementation to incorporate a large language model into safety-related work. A supervisor can use a publicly available tool to structure a job hazard analysis. An engineer can ask AI to identify potential safeguards. An EHS professional can use generative AI to summarize legislation, compare regulatory requirements, or organize incident findings. A worker can describe an unfamiliar task and ask an AI assistant to identify hazards or precautions.

None of these activities may register as an AI implementation. There may be no software purchase, project charter, change-management process, or notification to EHS. Yet AI has entered the workflow and may be influencing how a safety decision is formulated. This creates a visibility gap. The difference between where an organization believes AI is being used and where it is actually influencing work.

That gap matters because safety management depends on knowing how decisions are made, what information informs them, and who exercises professional judgment. If AI enters that process outside formal governance, EHS can lose visibility into an increasingly important part of the decision chain. This is where Shadow AI in EHS becomes consequential: AI may be quietly entering workplace safety decision-making before the organization has determined how its use should be controlled, verified, and governed.

Shadow AI doesn't always look like shadow AI

Shadow AI is often described as the unauthorized use of artificial intelligence tools in the workplace. While technically accurate, that definition can make the issue sound more deliberate than it usually is. In practice, Shadow AI often emerges through ordinary work behavior. An employee encounters a task that is difficult or time-consuming, discovers that an AI tool can help, and begins incorporating it into the workflow. There may be no intention to circumvent policy and no awareness that a governance issue has been created.

That distinction is particularly important in EHS. Safety professionals already work with regulatory information, incident data, procedures, risk assessments, and training materials. Generative AI can make it easier to summarize, compare, organize, and draft information. The concern begins when those uses move from administrative assistance into safety-critical reasoning.

Consider a supervisor preparing a job hazard analysis. They enter a description of the task into an AI system and ask it to identify hazards and recommend controls. An engineer might use AI to explore safeguards for a process. An EHS professional might ask it to compare regulatory requirements. A worker could use an AI assistant to identify precautions before performing an unfamiliar task. Individually, these actions may appear insignificant. Collectively, they represent something more consequential: AI is beginning to participate in the safety management process without necessarily being recognized as part of it.

Unlike a formally deployed AI system, Shadow AI may have no defined owner, approved purpose, user training, performance criteria, or governance controls. It can enter the workplace through individual initiative rather than organizational strategy. The issue, therefore, is not simply whether employees are using AI. It is whether EHS leaders understand where AI is entering the work, what decisions it is influencing, and what happens to human judgment when it does.

Who is accountable when AI is wrong?

The most important EHS question may not be whether an AI system can produce a useful answer. It is what happens when that answer is wrong, incomplete, or inappropriate for the conditions in which it is applied. In safety management, an error in an AI-generated recommendation is not simply a technology failure. It can become a failure in hazard recognition, risk assessment, control selection, or regulatory compliance.

Consider a job hazard analysis generated with AI that overlooks an interaction between two energy sources. Or an AI-generated recommendation that identifies a hierarchy-of-controls measure that is technically sound but impractical for the actual process. A regulatory summary may omit an important qualification, or an incident analysis may fail to recognize an organizational factor that was not evident in the information provided to the system. In each case, the output may appear credible while still being unsuitable for the decision.

This is where human judgment and professional competence remain essential. AI does not understand a workplace in the same way an experienced EHS professional, supervisor, or worker does. It cannot independently observe changing conditions, recognize informal work practices, or assume accountability for the consequences of a decision. There is also a second, less visible risk. If employees routinely rely on AI to identify hazards, develop controls, or interpret requirements, they may have fewer opportunities to practice those skills themselves. Over time, this can contribute to the safety capability drift.

The result is a two-sided risk. AI can produce an incorrect answer, while overreliance on AI can reduce our ability to recognize that the answer is incorrect. The question is, when AI influences a safety decision, who owns the decision? The answer cannot be the algorithm.

From AI use to AI governance

The answer is not to keep artificial intelligence out of EHS. A blanket prohibition is unlikely to prevent employees from using tools that are readily accessible and increasingly embedded in everyday work. It may simply drive that use further underground, widening the visibility gap rather than closing it. The more practical approach is to move from AI use to AI governance, creating a framework that allows organizations to benefit from the technology while establishing appropriate controls around its use.

For EHS, that governance should begin with visibility. Organizations need to understand where AI is being used, what information is being entered into AI systems, and whether those applications are supporting administrative activities or influencing safety-critical decisions. From there, clear expectations can be established around approved tools, sensitive information, human verification, and decision-making authority.

This does not mean requiring EHS professionals to become AI engineers. It means developing sufficient AI literacy to understand how these systems work, where their limitations lie, and when their outputs require independent verification. An AI-generated risk assessment, procedure, or recommendation should be treated as an input to professional judgment—not as a substitute for it.

The same principle should extend to organizational accountability. Where AI influences a safety decision, someone must remain responsible for reviewing the output, validating its applicability, and making the final determination. That responsibility should be explicit rather than assumed.

The future of AI in EHS will therefore depend less on whether organizations adopt artificial intelligence and more on whether they develop the capability to govern its use responsibly. Shadow AI is a signal that employees are already finding ways to incorporate the technology into their work. EHS leaders should pay attention to that signal rather than simply trying to eliminate it.

The objective is not to remove AI from safety. It is to ensure that as AI becomes part of safety work, human competence, critical thinking, and accountability remain firmly in the system.