InsightsAI Governance & Compliance

Shadow AI: The Hidden Risk of Employees Using Unapproved AI Tools

Idrak Insights TeamAugust 3, 202612 min read

Discover · Sanction · Govern

Key takeaways

  • Shadow AI, employees using AI tools without organizational approval, has become common enough that Verizon's 2026 DBIR ranks it the third most common non-malicious insider action detected in enterprise environments, up fourfold in a year.
  • IBM's Cost of a Data Breach Report 2025 found shadow AI was a factor in 20% of breaches, adding an average of $670,000 to the cost of those incidents.
  • Estimates for exactly how many employees use unapproved AI tools vary enormously across surveys, from roughly 41% to over 90%, a reminder to treat any single dramatic statistic with some caution.
  • Banning AI tools outright tends to push usage toward personal devices and accounts, making it less visible rather than eliminating it.
  • The more effective response is governance, not prohibition: discover actual usage, provide sanctioned alternatives, define clear data rules, and train employees.

Introduction

Somewhere in most organizations right now, an employee is pasting a client proposal, a chunk of source code, or an internal spreadsheet into a free AI tool that IT has never seen, approved, or reviewed. Not out of malice, usually out of a deadline. This is shadow AI, and it presents a genuinely different problem than the shadow IT that came before it: the barrier to entry is a browser tab, not a purchase order, which means it spreads faster than most organizations' governance processes can keep pace with. This guide covers what shadow AI actually is, what the data genuinely shows (as opposed to the more dramatic numbers circulating), what's actually at risk, and a practical framework for managing it.

What Is Shadow AI, Actually?

Shadow AI refers to AI tools and applications used by employees for work purposes without explicit approval or oversight from the organization. It's a direct descendant of "shadow IT," the older problem of employees adopting unsanctioned software and cloud services, but it spreads faster and is harder to detect, since AI capability now shows up in places that were never flagged as "new software" at all.

What counts as shadow AI

01

Personal accounts

Personal AI accounts

An employee's own ChatGPT, Claude, or Gemini account, used for work tasks.

02

Browser

Browser AI extensions

Third-party add-ons that summarize, rewrite, or analyze content directly in the browser.

03

Consumer tier

Free-tier AI tools

Consumer-grade versions of tools that may lack enterprise data controls, even when the paid tier is otherwise approved.

04

SaaS

Embedded AI features

AI capabilities quietly built into everyday SaaS tools employees already use, often enabled by default.

05

Engineering

Unauthorized coding assistants

Developers connecting AI tools directly to internal codebases without security review.

Why It's Growing So Fast

The pull here is straightforward: AI tools genuinely make people faster at their jobs, and consumer-grade AI products are a browser tab away, free, and require no procurement process. Formal enterprise AI rollouts, by contrast, involve vendor review, security assessment, budget approval, and training, a process that can take months. That gap, between how quickly useful AI tools become available and how slowly organizations can formally evaluate and approve them, is the entire reason shadow AI exists. Employees aren't waiting for permission because the tools that would help them today are already sitting open in another tab.

The Real Data: How Big Is This, Really?

Worth pausing on before going further. Search for "shadow AI statistics" and the numbers span an enormous range, anywhere from roughly 41% of employees to over 90%, depending on which survey, which population, and which definition of "unapproved" is being used. Rather than repeating whichever figure sounds most alarming, it's more useful to anchor on the handful of numbers that come from named, credible, methodologically transparent sources.

What the credible data actually shows

01
4x

increase in shadow AI detections year-over-year, making it the third most common non-malicious insider action in enterprise environments (Verizon 2026 DBIR)

02
45%

of employees are now regular AI users on corporate devices (Verizon 2026 DBIR)

03
20%

of data breaches involved shadow AI as a contributing factor (IBM Cost of a Data Breach Report 2025)

04
$670,000

average additional cost of a breach when shadow AI was a factor, compared to breaches without it (IBM 2025)

Beyond these, Microsoft's 2024 Work Trend Index and Salesforce's State of IT research both independently found a majority of knowledge workers already bringing their own AI tools to work, consistent directionally with Verizon's findings even if exact percentages differ by survey design. The point isn't which single number is most precise, it's that multiple independent, credible sources agree on the direction and scale: this is now a mainstream behavior, not an edge case.

What's Actually at Risk

Where the risk actually sits

01

Data exfiltration

What happens
Sensitive data (customer records, financials, source code) leaves organizational control the moment it's entered into a third-party tool.
02

Training data exposure

What happens
Free-tier AI products may retain or train on submitted data, depending on the provider's terms of service, which employees rarely read closely.
03

Compliance violations

What happens
Personal data entered into unapproved tools can breach data protection regulations, especially where cross-border processing or specific consent requirements apply.
04

No audit trail

What happens
Unlike sanctioned enterprise tools, there's typically no log of what was entered, when, or by whom, making incident response far harder if something goes wrong.

Why Banning It Doesn't Work

The instinctive response, blocking AI tools at the network level, tends to backfire in a predictable way: employees who need the productivity gain simply move to a personal device or personal account, where IT has zero visibility rather than partial visibility. The underlying need doesn't disappear because access was blocked; it just becomes invisible to the people responsible for managing the risk.

Ban vs enable

01

Banning AI tools

Employee behavior
Moves to personal devices and accounts
IT visibility
Drops to near zero
Productivity impact
Employees route around the policy anyway
Risk outcome
Risk continues, now invisible
02

Providing sanctioned alternatives

Employee behavior
Uses approved tools with visibility intact
IT visibility
Maintained through approved channels
Productivity impact
Productivity gains are captured, not lost
Risk outcome
Risk is managed, not eliminated, but visible

A Practical Governance Framework

Shadow AI governance checklist

  • 01Start with discovery, not policy. Understand what AI tools employees are actually using today, through anonymous surveys, network and SaaS usage monitoring, before writing rules about tools you don't yet know are in use.
  • 02Provide sanctioned, enterprise-grade alternatives. If employees are using a consumer AI tool to draft emails or summarize documents, the fastest way to reduce shadow usage is offering an approved version with proper data controls, not just removing the option.
  • 03Define what data can and cannot go into AI tools. A short, specific, plainly written policy beats a long one nobody reads. Name the categories that matter: customer data, financial data, source code, personal data covered by regulation.
  • 04Train employees on why, not just what. Most shadow AI use comes from productivity pressure and unclear rules, not malicious intent. Explaining the actual risk (data retention, compliance exposure) tends to change behavior more than a rule with no context.
  • 05Treat this as ongoing, not a one-time policy. New AI tools and embedded AI features launch constantly. Governance needs a recurring review cycle, not a policy document written once and left untouched.

How This Connects to Broader AI and Data Governance

Shadow AI sits at the intersection of two things already covered on this blog. Identity and access management governs who can reach your systems and data in the first place, but shadow AI often bypasses that entirely, since the "access" happens through an employee's personal account rather than a company-provisioned one. And because data sovereignty depends on which laws govern data wherever it ends up, data pasted into an unapproved AI tool can land under a jurisdiction and data-handling policy nobody at the company ever reviewed. Formal AI governance frameworks, including ISO 42001 and NIST's AI Risk Management Framework, exist largely to close exactly this kind of gap.

Sources

  • Verizon, 2026 Data Breach Investigations Report (verizon.com/business/resources/reports/dbir)
  • IBM, Cost of a Data Breach Report 2025 (ibm.com/reports/data-breach)
  • Microsoft, 2024 Work Trend Index (microsoft.com/worklab)
  • Salesforce, State of IT Report

This article reflects publicly available research as of July 2026. Shadow AI adoption figures vary significantly by survey methodology; figures above are drawn from named, dated, primary sources rather than compiled or unattributed estimates.

Frequently Asked Questions

What is shadow AI?+

Shadow AI refers to AI tools and applications used by employees for work purposes without explicit approval or oversight from the organization, the AI-era evolution of shadow IT.

How common is shadow AI in the workplace?+

Verizon's 2026 DBIR found shadow AI detections rose fourfold in a year, with 45% of employees now regular AI users on corporate devices, making it the third most common non-malicious insider action detected in enterprise environments. Other surveys report figures ranging from roughly 41% to over 90%, depending on methodology.

What data is most at risk from shadow AI?+

Customer data, financial information, source code, HR records, and internal documents are most commonly exposed, typically through free-tier AI tools that may lack enterprise-grade data governance controls.

Does banning AI tools actually reduce shadow AI usage?+

Not reliably. Blocking approved access tends to push usage toward personal devices and accounts, reducing visibility rather than eliminating the underlying behavior. Providing sanctioned alternatives is generally more effective.

How much does shadow AI actually cost when things go wrong?+

IBM's Cost of a Data Breach Report 2025 found shadow AI was a contributing factor in 20% of breaches, adding an average of $670,000 to the cost of those breaches.

How should a company start governing shadow AI?+

Start with discovery to understand actual usage, then provide approved enterprise-grade alternatives, define clear data rules, and train employees, treating governance as an ongoing process rather than a one-time policy.

Advisory

Governing AI use across your organization? We help build practical AI governance frameworks.

Talk to our team