
A developer pastes source code into ChatGPT to debug a function. A recruiter runs a stack of resumes through an AI screening tool. A salesperson drops a client contract into a chatbot to draft a follow-up. None of it went through security review. None of it appears in your tool inventory. All of it is shadow AI.
Here is the number that should worry you, though. According to Verizon's 2026 Data Breach Investigations Report, 45% of employees are now regular AI users on corporate systems, up from 15% a year earlier. But the more revealing figure is the next one: 67% of those users are accessing AI services from corporate devices using non-corporate accounts. They are not waiting for provisioning. They are working around it, on your hardware, into systems you have no agreement with.
This guide covers what shadow AI is, how it differs from shadow IT, why it is spreading faster than governance can move, the risks it introduces, and how to manage it without destroying the productivity your employees have already found. It also covers something most guides skip: why the monitoring you already own cannot see most of it, and what signal can.
Shadow AI is the use of AI tools, platforms, or models by employees without formal approval from their organization's IT or security teams. It is a subset of shadow IT, the broader practice of using any unsanctioned technology at work, but it carries a distinct risk profile that traditional IT controls were not built for.
Shadow AI takes a few common forms:
What separates shadow AI from an ordinary unauthorized app is what happens to the data. When an employee uses an unapproved file-sharing tool, the data sits in an unmanaged container. It is exposed, but it is inert. When an employee uses an unapproved AI tool, the data is actively processed, potentially retained for model training, and may surface in outputs for users outside your organization entirely. The exposure does not end when the session does.
The distinction matters for governance, because shadow AI needs controls that traditional IT security frameworks do not provide.
The short version: shadow IT is an access and inventory problem. Shadow AI is also a data processing, output quality, and compliance problem. That is why standard SaaS discovery tools routinely miss it.
Shadow AI is not a technical-team phenomenon. It shows up in every department, and it is almost always driven by someone trying to do their job better.
The common thread is intent. In none of these cases is the employee trying to cause harm. That is precisely what makes shadow AI structural rather than disciplinary, and it is why policy alone does not fix it. Once data enters an external model, though, intent stops mattering. You lose control of how long it is retained, who can reach it, and whether it reappears in a future output.
Shadow AI is not evidence that your policy failed. It is evidence of a gap between what employees are asked to deliver and what they have been given to deliver it with. Several forces are widening that gap at once.
That last pairing is the mechanism, and it is worth sitting with. Employees are absorbing a constant message that AI fluency is now survival, while the systems around them (metrics, incentives, review cycles) still reward the old way of working. High pressure to adopt plus no legitimate path to adopt does not produce patience. It produces shadow AI.
There is also a way to see, in advance, where shadow AI is most likely to take root. Worklytics outcome-driver research on AI adoption quantifies the conditions that raise or lower the probability that an employee becomes a heavy user of sanctioned AI. Tenure over five years lowers the probability by 22 percent. Having no domain-specific AI tool lowers it by 11 percent, and having no Slack bot available lowers it by 10 percent. On the other side, having a manager who is a heavy AI user raises the probability by 75 percent, more than any other single factor. Read as a risk map rather than an adoption playbook, the left-hand column describes the teams where sanctioned adoption is structurally suppressed. Demand for AI does not disappear on those teams. It goes underground, which makes them the natural habitat of shadow AI.

The most immediate risk, and the easiest to underestimate. When employees submit proprietary information, customer data, source code, or financial records to external AI systems, that data leaves your control. Many platforms retain inputs for training or product improvement, which means sensitive information can persist outside your perimeter indefinitely.
The trend line here is the story. Cyberhaven's research has tracked the share of data going into AI tools that qualifies as sensitive: 10.7% in 2023, 27.4% in 2024, and 39.7% of all AI interactions by their 2026 report. That is not a stable risk that needs managing. That is a curve. In the 2024 breakdown, the largest sensitive category was customer support data (16.3%), the confidential details customers themselves put into support tickets, followed by source code (12.7%).
Unauthorized AI can create exposure under GDPR, HIPAA, the EU AI Act, and financial services regulation, particularly where regulated data is involved. In regulated industries that means fines, mandatory disclosure, and audit. The compounding problem is discovery: organizations frequently do not learn about a violation until a regulator or auditor finds it for them. (For a breakdown of the specific regimes involved, see our guide to compliance laws for employee data and monitoring.)
Employees tend to treat AI output as authoritative. It can be factually wrong, it can reflect bias in training data, and it can be manipulated through prompt injection. When that output shapes a hiring decision, a customer communication, or a financial analysis, the error does not announce itself. It just becomes part of the record.
Shadow AI produces decisions without documentation. When an outcome is questioned later, there is no way to reconstruct what data went in, how it was processed, or why the tool produced what it did. In regulated industries, where audit-readiness is not optional, that gap is itself the violation.
IBM's 2025 Cost of a Data Breach Report (conducted by Ponemon across 600 organizations, covering breaches from March 2024 to February 2025) found that breaches involving shadow AI cost an average of $4.63 million, against $3.96 million for breaches without it. That is $670,000 in additional cost per incident.
Two findings from the same report sharpen the picture. Shadow AI was a factor in 20% of breaches, compared to 13% for sanctioned AI systems. And 65% of shadow AI breaches involved compromise of customer PII, against a global average of 53%. Shadow AI breaches are not just more expensive. They are more likely to be the kind you have to tell customers about.
This is the part most shadow AI guidance skips, and it is the reason the problem persists in organizations that are genuinely trying.
Optro's 2026 Risk Intelligence Report, The AI Oversight Gap, surveyed 822 audit, GRC, cyber risk, and IT decision-makers across the US, Canada, Germany, and the UK. It found that shadow AI is moderate or pervasive in 80% of organizations, while only 25% have comprehensive visibility into how employees actually use AI. That is a four-to-one gap between the problem and the ability to see it, among people whose job is seeing it.
That gap is not a diligence failure. It is architectural. Each detection method has a blind spot in exactly the place shadow AI is growing fastest:
Put those together and you get the actual shape of the problem. The methods that work well catch the shadow AI that was easy to catch anyway: someone going directly to a public chatbot from a corporate laptop. The fastest-growing category, AI arriving inside approved software, falls into the seam between all four.
This is the seam a people-analytics view is built to close. Because platforms like Worklytics read adoption from the admin and audit APIs of the tools themselves, assistive AI embedded in approved software (Microsoft 365 Copilot, Google Workspace AI, Slack AI) shows up as a first-class category alongside standalone tools like ChatGPT and Claude, rather than disappearing into allowlisted traffic. The AI feature your vendor switched on last quarter becomes visible as usage, not as an anomaly you have to go looking for.

Because no single method sees everything, detection in practice means reading signals. It helps to sort them by who in your organization can actually see each one.
The second list matters more than it looks, because it is the only one that reaches into the seam.
The most reliable single signal is the gap between expected AI usage and actual output. You know how many seats you have provisioned, when they were activated, and how much they are being used. You also know what each team is producing, and what they produced before. When output moves and provisioned usage does not, something is closing that gap, and it is not the tool you paid for.
This works precisely where network monitoring fails. It does not depend on identifying the tool, catching the traffic, or the AI being a separate application at all. It reads the shadow rather than the object: the work looks different, so something changed how the work gets done. A security vendor cannot offer this, because the signal does not live in network traffic. It lives in collaboration metadata, and that requires a different kind of instrumentation entirely. It is also the same signal set that powers ordinary AI adoption measurement, which means the tooling you use to encourage sanctioned AI is the tooling that surfaces the unsanctioned kind.
The instinct to ban is understandable and it backfires. Prohibition without a replacement does not remove demand. It relocates demand to personal devices and home networks, where your visibility is not partial. It is zero. The goal is governed enablement.
One step comes first, and the ordering is the whole strategy.
Verizon's finding that 67% of AI users on corporate devices are working through non-corporate accounts is the clearest evidence available that demand exists independent of provisioning. Those employees are not choosing risk. They are choosing the only path they have to finish the work. Until a capable sanctioned path exists, every restriction you add just pushes usage further out of view, and every control below does less than you think it does.
What a sanctioned deployment actually does to usage is visible in adoption trend data. In the illustrative example below, the share of employees using an AI tool in the past 30 days roughly doubled in the months following an organization-wide ChatGPT release. That jump is not new demand being created. It is existing demand, previously scattered across personal accounts and unapproved tools, moving into a channel the organization can see and govern. The plateau that follows is just as instructive: deployment converts shadow demand into governed usage, but adoption stalls without the enablement and policy work that the rest of this section describes.

Once that path exists, the remaining controls run in parallel.
Write a policy people can act on. A list of prohibitions with no permitted alternative gets ignored. An effective AI policy defines approved tools by role and function, specifies what data may never enter any AI system (sanctioned or not), gives a real process for requesting new tools, and sets expectations for verifying output before it informs a decision.
Make approvals fast. If review takes three months, nobody waits. A lightweight intake capturing tool, use case, and data types, reviewed on a weekly cycle, removes most of the incentive to skip the process.
Extend DLP into AI interfaces. Standard DLP was designed for email and file transfer. It needs to flag regulated data categories heading to AI endpoints, and it needs to cover sanctioned tools too, since an approved tool will happily accept data that should never have been pasted into it.
Build visibility deliberately. Use network analysis for known endpoints, SaaS discovery for OAuth grants and activations, and behavioral analytics for the seam the other two cannot reach. For organizations that take employee privacy seriously, metadata-based approaches surface shadow AI signals without invading privacy.
Train on risk, not rules. EY's 2025 Work Reimagined Survey (15,000 employees and 1,500 employers across 29 countries) found that 88% of employees use AI at work, while only 12% say they receive enough training to do anything beyond basic search and summarization. That is not a compliance gap. It is a capability gap, and it is the reason people improvise. Explain how retention and training reuse actually work, and what the threshold for asking should be. Concrete mechanics land better than a policy PDF.
The practical tension in managing shadow AI is that the obvious solution, watch everything employees do, is the one that destroys the trust you need to govern anything.
Behavioral analytics resolves this by changing what gets collected rather than what gets displayed. People analytics platforms can surface shadow AI signals from metadata across collaboration tools, calendars, code repositories, and communication systems, without reading message content. The method compares expected AI usage (from license activation, provisioning, and historical baselines) against actual output and work patterns. A persistent gap between the two is an early warning.
This answers questions network monitoring cannot reach:
A department-level adoption view makes the second question concrete. The teams at the top of a chart like this are not necessarily avoiding AI. They are often the teams using it somewhere you cannot see.

That last question is the one that turns governance from a defensive exercise into a useful one. A team showing a large license-to-output gap is not a compliance problem to be closed down. It is a team telling you, through their work, exactly where your AI strategy has a hole.
Worklytics approaches shadow AI as an AI adoption measurement problem rather than a surveillance one. Three capabilities map directly onto the blind spots above:

The point is to give HR and IT leaders enough data to govern shadow AI responsibly, without reverting to surveillance-style monitoring that costs more trust than it recovers in risk. It also reframes the finding: a department with a large adoption-to-output gap is usually not a policy violator to shut down, but the clearest signal of where your sanctioned rollout has left a hole worth filling.

What is shadow AI in simple terms? Shadow AI is when employees use AI tools at work that their IT or security team has not approved. It usually starts with someone trying to work faster, not trying to break a rule.
What is the difference between shadow AI and shadow IT? Shadow IT is any unsanctioned technology at work, and the risk is mainly that data sits somewhere uncontrolled. Shadow AI is specific to AI tools, and the data is actively processed and may be retained or reused in model training, so the exposure continues after the session ends.
How common is shadow AI? Optro's 2026 research across 822 risk and IT decision-makers found shadow AI is moderate or pervasive in 80% of organizations, while only 25% have comprehensive visibility into employee AI use.
What are the biggest risks of shadow AI? Data leakage, regulatory violation, inaccurate or biased outputs entering real decisions, and the absence of any audit trail. IBM found breaches involving shadow AI cost $670,000 more on average and were more likely to expose customer PII.
How do you detect shadow AI? No single method catches everything. Network analysis finds known AI endpoints, SaaS discovery finds OAuth grants, and behavioral analytics finds AI use embedded in approved tools that the first two miss. The most reliable single signal is a gap between provisioned AI usage and actual work output.
Should we just ban AI tools? Bans without a sanctioned alternative move usage to personal devices, where there is no visibility at all. Providing a capable approved path first is what makes every subsequent control work.
Shadow AI is already in your organization. The only real question is whether you find out through a deliberate governance effort, or through the incident that surfaces it for you.