What is Shadow AI?

Right now, employees at your organisation are almost certainly using AI tools you haven't approved. An employee may be pasting a client brief into ChatGPT. A colleague in finance may be using a free AI tool to draft a report. Someone in HR may be asking Claude to summarise a set of CVs. None of them were doing anything intentionally malicious or dangerous, but none of them asked for permission.

This is shadow AI: the use of AI tools that haven't been approved, vetted, or sanctioned by the organisation.

The scale of the problem

Multiple pieces of research show that this is a significant and growing problem, and the scale of it may surprise you. Microsoft's UK research, published in October 2025 and based on a survey of 2,003 UK employees, found that 71% have used unapproved consumer AI tools at work, and 51% do so every week.

This isn't primarily a story about employees who don't know what they're doing or who are deliberately flouting the rules. In most cases, people are simply trying to do their jobs better and more efficiently, using tools they know work. Research by BlackFog, based on a survey of 2,000 UK and US employees conducted by Sapio Research in November 2025, found that 60% of employees accept the security risks of unsanctioned tools because they help them work faster or meet deadlines. 28% of UK employees using unapproved tools told Microsoft the reason is simply that their organisation doesn't provide a sanctioned alternative. There's no malice here, just momentum and a lack of approved alternatives. Understanding these reasons matters if you want to respond to it effectively.

The organisational risks

The problem is that the stakes are considerable. When an employee pastes a client brief or a financial dataset into a consumer AI tool, that data leaves the organisation's control entirely. It's transmitted to a third-party provider, processed on infrastructure the organisation doesn't own, and in some cases retained for model training purposes. The Samsung incident in 2023, in which engineers fed proprietary source code into ChatGPT for debugging help, only to have that code potentially surface in responses to other users, is the most widely cited example of how quickly this can go wrong.

IBM's Cost of a Data Breach Report 2025 found that shadow AI contributed to 20% of all data breaches and added an average of $670,000 to breach costs. IBM's IBV report "Go further, faster with AI," published in December 2025, found that 62% of senior executives say shadow AI risk has increased over the past two years. The risks don't stop at data either, with regulatory exposure, IP loss, reputational damage, and compliance failures all on the table when AI tools operate outside any governance framework.

Why banning unapproved tools doesn't work

The instinctive organisational response to shadow AI is to prohibit it. Block the domains, issue a policy, send a reminder about acceptable use. It's understandable, but I’m sorry to say, it doesn't work.

The Awareways Trend Report 2025, drawing on over 38,000 responses from employee training sessions, found that 89% of employees know they're supposed to seek approval before using new software, yet fewer than half actually do so.

You can write the policy, and most of your workforce will nod and carry on as before, just with a little more discretion about it. The BlackFog research reinforces the point from a different angle: 49% of employees are already using unsanctioned AI tools, and that figure is drawn from organisations with more than 500 employees, where policies and IT oversight are more likely to exist.

Banning tools doesn't just fail to eliminate shadow AI, it drives it underground, which is the worst possible outcome, because at least visible use can be monitored and addressed. When the Microsoft research found that only 32% of employees using unapproved AI tools are concerned about data privacy, and only 29% about IT security, the lesson isn't that employees are careless. It's that they haven't been given the context, the tools, or the alternatives that would make responsible use the path of least resistance. The real cause of shadow AI isn't employee recklessness, it's the governance gap, and banning tools doesn't close it.

What good governance actually looks like

The practical response to shadow AI isn't prohibition, it's making the legitimate route easier than the illegitimate one. That means:

  • having a clear, published AI acceptable use policy that explains what data can and can't be shared with which tools.

  • giving employees access to enterprise-grade AI tools that actually meet their needs, because if the sanctioned option is good enough, most people will use it.

  • naming someone who owns AI governance, so there's a clear point of accountability and a person employees can go to with questions.

  • building a swift, accessible approval process for new tools, so that when a team finds something useful, there's a realistic route to making it official quickly.

None of this requires a lengthy compliance programme before anything moves. Start with a few high-risk categories, define clear rules around data handling for those, and build from there. IBM's IBV research found that organisations with strong governance report 52% improved time to value on AI projects, and that one in four unsuccessful AI projects stems directly from weak governance. The goal with good governance is a framework that's live and evolving, not a policy document that nobody reads.

The Red Giant says...

If you're a leader reading this, the question worth asking isn't "are my employees using unapproved AI tools?" The data shows they almost certainly are. The question is whether you've made it easy enough for them to use appropriate AI tools responsibly, or whether the path of least resistance in your organisation still runs straight through the governance gap.

Shadow AI exists because people are trying to do their jobs well, and AI helps them. The answer to that isn't restriction, it's direction: clear policies, good tools, named ownership, and a fast enough approval process that doing things properly doesn't feel like more trouble than it's worth.


References

Awareways (2026) Trend Report 2025: The Rise of the Invisible Colleague: Shadow AI. Author: Sjoerd van Veldhuizen, MSc. Co-authors: dr. Jan-Willem Bulée and Remy Dijkstra, MSc. Awareways B.V., Utrecht. Published March 2026. Available at: https://www.awareways.com

BlackFog (2026) Shadow AI Threat Grows Inside Enterprises. Research conducted by Sapio Research on behalf of BlackFog, Inc., November 2025. Published 27 January 2026. Available at: https://www.blackfog.com/blackfog-research-shadow-ai-threat-grows/ (Accessed: 8 May 2026).

IBM Institute for Business Value (2025) Go further, faster with AI: How governance increases velocity. IBM Institute for Business Value. December 2025. Available at: https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/ai-governance-trends (Accessed: 8 May 2026)

IBM Security (2025) Cost of a Data Breach Report 2025. IBM. Available at: https://www.ibm.com/reports/data-breach (Accessed: 8 May 2026).

Microsoft (2025) Rise in 'Shadow AI' tools raising security concerns for UK organisations. Microsoft UK Stories. 13 October 2025. Available at: https://ukstories.microsoft.com/features/rise-in-shadow-ai-tools-raising-security-concerns-for-uk/ (Accessed: 8 May 2026).