The quiet rise of Shadow AI in legislative drafting
Artificial intelligence has arrived in legislative offices long before most organisations have decided what to do about it.
Used by the people doing the work, not approved through procurement processes or strict policies that simply cannot keep apace with developments.
It could be a legislative drafter facing a deadline. A policy adviser trying to compare amendments. A committee clerk summarising consultation responses. A lawyer looking for a clearer way to explain a complex provision. For work that is so based in the world of words, temptation is understandable. Public AI tools promise to save minutes on every task, and those minutes add up.
The problem is that convenience often arrives before governance.
This phenomenon is known as Shadow AI: employees using publicly available AI tools without organisational approval or oversight. It is no longer a niche behaviour. More than half of Americans have already used an AI assistant, while one in three uses one every day. In the workplace, 38% of employees surveyed admitted to sharing sensitive information with AI tools, and one in five UK organisations has already experienced data leakage linked to employees using generative AI.
For governments, the implications are different from almost every other sector.
Legislative AI is not simply generating marketing copy or meeting notes. It may be exposed to draft Bills, unpublished amendments, Cabinet instructions, legal advice, policy options or correspondence that shapes legislation before the public ever sees it. Even asking a public AI system to explain, restructure or improve draft legislative text can mean sensitive government information is processed outside approved environments.
This is one of the emerging AI risks to governments. Not because public AI is inherently unsafe, but because legislative drafting depends on confidentiality, public trust and the integrity of the lawmaking process. Citizens expect legislation to be debated in parliament before it appears anywhere else.
Most legislative organisations are already thinking seriously about AI. The challenge is that staff cannot always wait for enterprise strategies to catch up with day-to-day pressures. When approved legislative AI tools are unavailable, people naturally reach for whatever is easiest. The result is a quiet shift towards Shadow AI, often with the best of intentions, but without the safeguards that government drafting demands.
What really happens when draft legislation enters a public AI system
A draft Bill is not like an internal memo. It is not another document waiting for approval before being filed away.
Long before legislation reaches a parliament or assembly, it passes through dozens of conversations and revisions. Instructions are refined. Legal advice is sought. Policy decisions change. Whole sections are written, removed and written again. Every version says something about where a government is heading.
That information has value because it has not yet become public.
When a legislative drafter copies part of a Bill into a public AI tool, it is easy to think of it as a simple request for help. Rewrite this clause. Summarise these amendments. Explain this provision in plain English. The task itself feels harmless. What is less obvious is what happens once that text leaves the government’s own environment.
Depending on the service being used, organisations may have limited visibility over where information is processed, how long it is retained, or who ultimately has access to it. Even where providers have introduced stronger privacy controls, government organisations still need certainty. Legislative drafting deals with material that can affect markets, influence public policy and shape political debate before any official announcement has been made.
The risks extend beyond data protection.
An unpublished amendment could reveal a change in government policy. Draft regulations might expose decisions that ministers have not yet approved. Internal legal advice may contain competing interpretations of legislation that were never intended for public scrutiny. None of these documents are classified in the traditional sense, yet each depends on confidentiality while the legislative process runs its course.
Public trust is part of this conversation too. Citizens expect laws to emerge through established democratic processes, not through systems that governments cannot fully oversee. If sensitive drafting material is handled carelessly, confidence in those processes begins to erode, even if no breach is ever confirmed.
This is why discussions around legislative AI cannot begin with productivity alone. They also have to consider governance, accountability and control over government information. Before organisations ask what AI can do for legislative drafting, they first need to ask where their legislative content is going, and who remains responsible for it once it leaves their hands.
Giving lawmakers AI they can actually trust
Legislative teams should not have to choose between working efficiently and protecting the integrity of the lawmaking process.
The real solution is AI that stays inside government-controlled environments, works from trusted legislative content, and gives organisations confidence in how information is used, stored and governed. When secure legislative AI becomes part of drafting workflows, the appeal of unlicensed AI quickly fades.
The future of legislative AI is not about limiting what drafters can do. It is about giving them tools they can trust.