Guide · Updated September 2026

Shadow AI: what it is, what it actually risks, and how to manage it

Shadow AI is the AI your people use for work without the company’s approval or knowledge: the personal chatbot account, the notetaker nobody vetted, the agent wired to a work inbox. It is already happening at your company. The useful questions are what it puts at risk, and why the obvious response, a ban, tends to make it worse.

43%of breached organizations had a security incident involving shadow AIUp from 20% a year earlier. IBM, 2026. Source
48%of employees who use AI have uploaded company information into a public AI toolFinancial, sales, or customer data. KPMG and University of Melbourne, 2025. Source
47%of generative AI users at work use a personal AI accountDown from 78% a year earlier, as companies issued managed accounts. Netskope, 2026. Source
38%of organizations have a formal, comprehensive AI policyUp from 28% in 2025; 25% have none. ISACA, 2026. Source

What counts as shadow AI

The definition is simple: AI used for work that the organization has not approved and cannot see. Both halves matter. An approved tool used carelessly is a training problem. An unapproved tool is a visibility problem, because you cannot protect, audit, or even inventory what you do not know exists.

Most writing on the subject stops at employees pasting text into ChatGPT. That is one form of six, and no longer the one that should worry you most.

Personal chatbot accounts

The original and still the most common: a free or personally paid ChatGPT, Claude, or Gemini account used for work, with company material pasted in. Consumer terms often allow training on what is submitted, and the company has no record that any of it happened.

AI features inside tools you already approved

The CRM, the design suite, the help desk, and the document editor have all shipped AI features since the original security review. Nobody re-approved them. This is shadow AI that arrives through a vendor update rather than an employee decision.

Meeting notetakers and browser extensions

A notetaker joins a client call because one attendee installed it. A writing extension reads every page the browser opens, including the ones behind your login. These have the widest data access of anything on this list and the least scrutiny.

Coding assistants

Engineers paste proprietary code into personal assistants, or accept generated code with unclear licensing into the codebase. The Samsung incident in 2023 was this.

Tools bought on a team card

A department buys an AI product that falls under the procurement threshold. It gets connected to the shared drive. It is now a system of record that IT has never heard of.

Shadow agents

The 2026 version. An employee wires an agent to their email, calendar, and CRM using their own credentials or a personal API key. Unlike a chatbot, it does not only read and suggest: it sends, updates, and deletes, as them, unattended.

Why it is not just shadow IT again

Security teams have dealt with unapproved software for twenty years, and it is tempting to file this under the same heading. Three differences make the old playbook a poor fit.

There is nothing to install and often nothing to buy. Shadow IT left a trail: an installer, an invoice, a new domain in the firewall log. A free chatbot in a browser tab leaves almost none, and the data leaves inside the prompt itself.

The output comes back. An unapproved file-sharing tool stores your data. An unapproved AI tool also writes your proposals, your code, and your analysis, so its mistakes enter your work product. No amount of data protection addresses that.

Agents act. A growing share of shadow AI does not just hold information; it sends email, edits records, and merges code under a real employee’s identity. Controls are not keeping pace: in IBM’s 2026 breach study, the share of organizations requiring IT approval for AI deployments fell to 38% from 45% the year before.

The risks, in the order they tend to bite

1

Confidential data leaves, and you cannot get it back

The main event. Customer records, financials, source code, and deal terms go into a system whose retention and training terms nobody read. IBM’s 2025 study found that shadow AI incidents compromised personal data and intellectual property at higher rates than breaches generally.

2

Contract and regulatory exposure

You have probably promised clients, in writing, that their data stays within named systems. Health, financial, and legal data carry their own rules on top. None of those promises has an exception for a helpful chatbot, and in about one in five shadow AI incidents in IBM’s 2026 data the organization reported paying a fine.

3

Unchecked output in finished work

The quieter risk, and possibly the larger one. In the KPMG study, 66% of employees who use AI said they had relied on its output without evaluating it and 56% said they had made mistakes in their work because of it. A fabricated citation in a client deliverable is a shadow AI incident even though no data leaked.

4

Agents with real credentials

An agent acting under an employee’s login inherits everything that employee can do, and can be steered by instructions hidden in the content it reads. Among organizations that suffered an AI-related breach, IBM found 92% lacked proper AI access controls.

5

Duplicate spend and scattered knowledge

Six teams paying for four overlapping tools, each holding a fragment of how the company works. Not a security problem, but usually the one that gets finance to care.

The cost is measurable. IBM’s 2025 study found that organizations with high levels of shadow AI paid an average of $670,000 more per breach than those with little or none. Its 2026 edition put the average cost of a security incident involving shadow AI at $5.39 million. Telemetry from Cyberhaven suggests why: 39.7% of the data its customers’ employees move into AI tools is sensitive.

One risk belongs on the other side of the ledger. A company that responds by shutting AI out entirely takes on a different cost, paid in speed and in the people who leave for employers that let them use modern tools. The goal is managed use, not zero use.

Why your people do it

Not out of malice, and mostly not out of carelessness. They do it because the tools make them faster and the company has not given them a sanctioned way to get the same result.

The Microsoft and LinkedIn Work Trend Index put numbers on this in 2024: 78% of people using AI at work were bringing their own tools, rising to 80% at small and medium-sized companies, and 52% were reluctant to admit using AI for their most important tasks. That figure is two years old and has not been updated, but the newer evidence points the same way. In the KPMG and University of Melbourne study, 56% of employees had used AI at work without knowing whether it was allowed, and only 40% said their workplace had any policy or guidance on generative AI.

Read that last pair of numbers again. For a large share of employees, shadow AI is not rule-breaking. There is no rule. Seen this way, unapproved use is a demand signal: a list, compiled for free, of the tasks your people most want help with.

Why bans backfire

The best-known ban is Samsung’s. In May 2023, after staff uploaded sensitive code to ChatGPT, the company restricted generative AI on company devices. What usually goes unmentioned is how Samsung described it at the time: as temporary, in place “until these measures are ready,” while it built internal AI tools for the same work. Even the canonical ban was a holding action while the company arranged a sanctioned alternative.

The survey evidence is blunter. In the KPMG study, employees at organizations that had banned generative AI were about twice as likely to report breaking AI policy as those at organizations with no policy at all: 67% against 33%. Some of that is definitional, since under a ban any use is a breach. But that is the point. The ban did not stop the use. It converted it into concealed use, which is the version you cannot see, coach, or secure.

Provision has the opposite record. Netskope watched personal AI app use fall from 78% to 47% of generative AI users in a single year. No wave of bans explains that. Over the same period, the share using accounts managed by their employer rose from 25% to 62%. People moved to the company tool when the company supplied one.

None of this argues against restrictions. Some data should never enter any AI tool, and some tools should be blocked. It argues about sequence: supply the approved route first, then restrict, and people will take the route.

A 30-day plan for a company without a security department

This assumes a few hundred employees, an IT lead, and no one whose full-time job is AI risk. Larger and regulated companies will need more, but not something different in kind.

Week 1

Find out what is actually in use

  • Run a short, anonymous survey that promises no consequences for honest answers, and means it. Ask what people use, for which tasks, and what they wish they had. This gets you more truth in a week than any tool.
  • Pull what your systems already know: single sign-on and OAuth grants, expense reports and card statements for AI vendors, browser extension inventories, and DNS or proxy logs if you have them.
  • List the AI features that have appeared inside software you already pay for. Your vendors’ release notes are the fastest source.

Week 2

Decide what is allowed, in plain terms

  • Sort your data into three tiers people can remember: fine anywhere (public material), approved tools only (internal and customer data), and never in any AI tool without sign-off (regulated data, credentials, unreleased financials, anything under a client restriction).
  • Pick the approved tools. Favor business tiers that contractually exclude your data from training and give you admin controls. For most companies this is two or three products, not twenty.
  • Write it down in two pages. Our editable acceptable use policy template covers the full structure.

Week 3

Make the sanctioned path the easy one

  • Issue the approved tools to everyone who needs them, behind single sign-on, before you announce any restriction. A rule with no alternative attached is a rule people route around.
  • Turn on the admin settings you are now paying for: retention limits, training opt-outs, connector restrictions, audit logs.
  • Open a request route for new tools with a published turnaround of days. If the answer takes a quarter, the tool is already in use by the time you give it.

Week 4

Teach, then watch

  • Train on the three data tiers using examples from people’s real work, and on checking output before it goes out the door. An hour is enough if it is specific.
  • Where you have data loss prevention or a secure browser, set it to warn and coach rather than block. A prompt that says “this looks like customer data; use the company account” changes behavior. A blocked page sends people to their phones.
  • Put a quarterly review on the calendar: re-run the survey, review the request log, and re-read your vendors’ release notes.

The documents behind weeks two and four already exist: the AI acceptable use policy template is free and editable, and governance training and AI literacy training cover the teaching. If you are unsure where your gaps are, the readiness assessment will show you in a few minutes.

What detection can and cannot do

Vendors will offer to find your shadow AI for you, and the tools are real. Identity logs show which AI services employees have signed into with a work account. Expense data shows what is being bought. Browser management shows extensions. Data loss prevention and secure browsers can inspect what is heading to an AI service and flag customer records or source code on the way out. Netskope reports its average customer logging 223 generative AI data policy violations a month, which tells you both that the tools catch things and that there is plenty to catch.

Be clear about the limit. None of it sees a personal phone on a mobile network, which is where use goes when the office network gets hostile. Detection tells you the size of the problem and whether your fix is working. It is not the fix. Of the breached organizations in IBM’s 2025 data that had an AI policy, only 34% regularly audited for unsanctioned AI, so there is room to do better here, but audit what your policy promised, in that order.

Shadow AI is a symptom

Every company that discovers shadow AI has discovered the same underlying thing: AI arrived faster than anyone decided who was responsible for it. Gartner expects more than 40% of enterprises to suffer a security or compliance incident linked to unauthorized AI by 2030. The companies that avoid that outcome will mostly be the ones that treated the first discovery as a reason to settle ownership, not just to clean up.

That larger job is AI governance: an inventory of where AI is used, rules sized to the risk, review before launch, and a named owner. Our guide covers a version built for companies without a compliance department. If nobody on your team has the capacity to own it, a fractional AI leader can stand it up in a quarter and hand it over.

Shadow AI: common questions

What is shadow AI?

Shadow AI is any use of artificial intelligence tools for work that the organization has not approved and cannot see. The typical case is an employee pasting company information into a personal chatbot account, but it also covers AI features switched on inside approved software, meeting notetakers and browser extensions, coding assistants, tools bought on a team card, and agents connected to company systems with personal credentials.

How is shadow AI different from shadow IT?

Shadow IT is unapproved software. Shadow AI adds three things. Data leaves in the prompt itself, with nothing to install and often nothing to buy, so there is no procurement or installation trail. The tool’s output flows back into finished work, so errors travel as well as data. And agents can take actions under an employee’s credentials rather than only storing information. Controls built for shadow IT catch little of this.

How common is shadow AI?

Common enough to assume it is happening. In the KPMG and University of Melbourne 2025 study, 48% of employees who use AI said they had uploaded company information into public AI tools and 44% said they had used AI in ways that contravene policy. Netskope’s 2026 telemetry found 47% of generative AI users at work using personal AI apps, down from 78% a year earlier. Gartner reported in 2025 that 69% of organizations suspect or have evidence of employees using prohibited generative AI.

Should we ban ChatGPT and similar tools?

A ban with no alternative rarely works and removes your visibility. In the KPMG study, employees at organizations that banned generative AI were more likely to report breaking AI policy than those with no policy at all. The measure with evidence behind it is provision: Netskope recorded personal AI app use falling from 78% to 47% of users over the year in which company-managed account use rose from 25% to 62%. Restrict specific data and specific tools, and hand people an approved option first.

How do you detect shadow AI?

Start with a no-blame survey, then check single sign-on and OAuth grants, expense and card data, browser extension inventories, and network or proxy logs. Data loss prevention and secure browser tools can flag sensitive content heading to AI services. None of this sees a personal phone on a mobile network, which is why detection only supports the real control: an approved tool that is easier to use than the unapproved one.

Who should own shadow AI in a mid-sized company?

One named executive, usually whoever owns security or operations, supported by a small working group spanning IT, legal or compliance, and a business lead who uses AI daily. Shadow AI is the most visible symptom of missing AI governance, so the same group should own the broader framework rather than treating this as a one-time cleanup.

Need someone to own this?

We match companies with vetted AI leaders and consultancies who have set up AI policy, tooling, and training before, and we will tell you if what you need is a two-page policy rather than a project.