Generative AI entered everyday workflows faster than many companies were able to define rules for using it. Employees now use AI to analyze documents, build presentations, process research findings, draft emails, and review code. From an employee's perspective, the appeal is obvious: when a tool can reduce several hours of routine work to a few minutes, it is difficult to ignore.
At the same time, the company may have no idea which service has gained access to its documents, which account an employee used to sign in, where the information is being processed, or what data-retention terms apply to a particular product. The nature of work has already changed, while the corporate environment-where the organization controls access, data storage, and activity history-still covers only a fraction of the tools employees use every day.
According to Netskope, the median share of employees using AI applications on a weekly basis rose from 34% to 59% in a single year. At the same time, 30% of users work exclusively through personal applications and accounts, while another 14% combine them with company-managed tools.
This use of AI outside official corporate oversight is known as Shadow AI. The issue goes beyond the potential for data leakage. When employees independently choose models, services, and automations, the organization may not fully understand which technologies have already become embedded in its workflows, how much is being spent on them, which data they can access, and where AI is already influencing decision-making.
How AI Moved into the Shadows
Shadow AI refers to employees' use of AI tools, models, applications, or agents that the organization has not formally approved or does not control. This might mean a personal account on a popular chatbot, a specialized marketing or coding service, a self-built automation, or an AI agent connected to internal work systems.
The phenomenon has a predecessor: Shadow IT, in which employees adopted their own cloud storage, software, or devices without approval from the IT department. Generative AI has expanded the scale of the issue dramatically. In just a few seconds, an employee can now send an external service source code, financial data, customer correspondence, a contract, research materials, or an internal presentation.
A standalone chatbot is far from the only source of Shadow AI. AI features are increasingly embedded into familiar workplace applications: search tools, meeting transcription, text editors, developer platforms, and many other services. An employee may begin using a new data-processing model without ever opening a dedicated AI product. From the company's perspective, the questions remain the same: Has this functionality been approved? What data does it receive? And what rules apply to that data?

The way companies adopt technology has changed as well. In the past, employers usually selected the main tools used at work and then gave employees access to an already configured system. Generative AI first became widely available through consumer products, and users themselves began finding ways to apply it to work. In many organizations, formal policies only started taking shape after these practices had already become established.
Business Insider describes the case of an employee at a biotech company who helped develop internal AI policies while continuing to use an unauthorized personal NotebookLM account. According to the employee, a task that would have taken roughly 150 hours manually took about 30 minutes with AI. Meanwhile, the company spent several months approving its own rules for the technology.
The situation exposes a conflict between two expectations employers place on staff: follow restrictions while also improving productivity. If no approved tool exists, or access requires a lengthy approval process, employees may already know a much faster way to complete the same task.
Personal vs. Corporate AI Services
It would be reasonable to assume that once enterprise versions of popular AI services became available, unofficial use would gradually decline. In the first few months, that did appear to be happening. By March 2026, however, the decline had stopped.
According to Netskope, 56% of AI users now work exclusively with company-managed applications, 30% rely only on personal tools, and another 14% use both.
Even after a company introduces an official AI assistant, employees continue looking for specialized products for programming, data analysis, video, recruiting, or marketing. Business Insider notes that as basic enterprise AI solutions become more common, professionals are increasingly turning to additional tools designed for specific tasks.
That means simply deciding to "allow AI" is not enough. The more useful management question is: Which specific tool is being used, for what task, with what data, and in which corporate or personal environment?
From Chatbots to Agents
Shadow AI is not limited to prompts typed into a chatbot window. It also includes independently connected AI agents, local models, and automations that give AI access to workplace applications and data.
Unlike a conventional chatbot, an agent may do more than generate an answer. It can connect to multiple systems, gather information, and carry out a sequence of actions.
According to Microsoft, 29% of employees already use unauthorized AI agents for work tasks, while only 47% of organizations have implemented dedicated generative AI security controls. The findings are based on an international survey of more than 1,700 data-security professionals.
The old question-"What data did the employee upload into an AI tool?"-is therefore no longer enough. Companies also need to know what the AI is connected to, which permissions it has been granted, and what actions it can perform.
What Companies Can No Longer See
Confidential data leakage remains the most obvious risk associated with Shadow AI, but it is far from the only one. Technology spending, the logic behind individual workflows, data histories, and even the origins of decisions influenced by AI can all fall outside corporate visibility.
Data Outside the Corporate Environment
Asking an AI tool to edit text that has already been published on a company website is very different from uploading an unpublished financial report. Between these two extremes lies a large gray area: customer emails, candidate résumés, research materials, commercial proposals, contracts, sales figures, and internal presentations.
Without a clear data-classification system, employees are left to decide for themselves which information may safely be shared with an external service. For the company, that means losing control over where business data is stored and processed.

A 2025 IBM and Ponemon Institute study surveyed 600 organizations that had experienced data breaches. Of those organizations, 63% either lacked a comprehensive AI governance policy or were still developing one. One in five reported a data breach linked to Shadow AI, and companies with high levels of Shadow AI use faced an average incident cost that was $670,000 higher than organizations with little or no Shadow AI activity.
The information affected in these incidents frequently included personal data and intellectual property.
The risk also cannot be reduced to a single question such as whether a particular service uses submitted data to train its models. Terms differ across products, pricing plans, and versions. A corporate deployment may have entirely different retention and access settings from a personal account on the same service. The central Shadow AI problem is that companies may not even know which terms apply in a particular work scenario.
A Personal Account on an Approved Service
A list of approved products does not provide full control either. An employee may use the same service through a corporate account for one task and through a personal account for another.
From the user's perspective, the difference may be little more than selecting a different login. From the company's perspective, the consequences can be much broader: data-retention settings, access rights, activity history, the ability to centrally disable an account, and the ability to remove corporate information after an employee leaves may all change.
A policy that simply says "this service is approved" is therefore too broad. What matters is not only the name of the product, but also which version is being used, who owns the account, and which corporate controls apply to it.
Duplication and Hidden Costs
Shadow AI also creates costs unrelated to security. If a company cannot see which tools and automations individual teams are building, multiple departments may end up solving the same problem in parallel.
One department buys a specialized subscription, another hires a contractor to build something similar, and a third independently creates an equivalent workflow using a different model. The company ends up paying for essentially the same solution several times, while a successful practice remains isolated within one team instead of being transferred to other areas where it could create additional value.
According to a Nutanix study cited by Fast Company in an article on Shadow AI, 79% of 1,600 surveyed IT and engineering leaders had encountered AI implementations initiated by employees outside the IT function.

For businesses, this is no longer only an information-security issue. It is also about the quality of technology investment. Without a company-wide view, it becomes difficult to understand which solutions the organization is paying for more than once, which processes have already been automated in individual departments, and which successful approaches should be scaled across the business.
Decision Provenance and Accountability
Another risk arises when AI influences not only the form of an output, but also its substance.
If an analytical memo was prepared using a service the company knows nothing about, it may later be difficult to reconstruct which source data was used, what instructions were given to the AI, and what the employee actually verified. For a routine email draft, that degree of reproducibility may rarely matter. For candidate assessments, financial calculations, client recommendations, or software code, the standards are different.
With AI agents, companies must track not only where an answer came from, but also which actions the system performed. Microsoft recommends maintaining a centralized inventory of such systems, including the agent's owner, access rights, connected applications, and the set of actions it is authorized to take.
Shadow AI therefore now includes not only invisible prompts sent to AI models, but also workflows in which AI receives data, analyzes it, and independently moves on to subsequent actions.
Why a Ban Does Not Restore Control
Banning unfamiliar services is easier than integrating a constantly changing ecosystem of AI tools into corporate systems. In certain industries, for certain tasks, and for specific types of data, strict restrictions are entirely justified. But a ban does not eliminate the work that led the employee to an external tool in the first place.
If analyzing a document regularly takes several hours and an AI tool can produce a first-pass review in minutes, the incentive to find a faster method remains. The longer a company takes to approve a new service, the more likely it is that at least some experimentation will happen outside the official corporate environment.
An effective policy therefore needs to answer more than one general question-"Can employees use AI?"-and instead address several much more practical ones.
Rules Based on Risk Level
Employees need to understand which services are approved and through which accounts; which data can be shared with AI without additional approval and which data must remain inside the corporate environment; where AI may be used to produce a draft and where its output must be reviewed by a human.
Agents and automations need separate rules. Editing text and giving a system access to corporate email should not be governed in exactly the same way simply because both involve artificial intelligence.
An accessible process for requesting a new tool is equally important. If approval takes weeks or months, employees have a stronger incentive to bypass the process. One practical approach is to classify AI products by risk level and accelerate reviews for services that work only with non-sensitive data or do not receive access to internal systems.
A Corporate Alternative to External Services
Security requirements alone are not enough if the official company tool is significantly worse than external products in terms of quality or usability. In that situation, employees are comparing restrictions with a very tangible benefit: the amount of time another product can save them.
Cisco addresses this challenge through its own AI assistant, CIRCUIT. The tool gives employees access to appropriate language models and internal data sources within a managed corporate environment. According to the company, by the end of fiscal 2025 more than 92,000 employees were using the tool, and users reported saving an average of about five hours per week.
In this model, employees do not have to choose between the convenience of an external service and security requirements. The official tool has to solve a real business problem quickly and effectively enough that employees do not feel the need to find a workaround.

Shadow AI as a Signal of Demand
Unofficial AI use is worth analyzing not only as a policy violation. It can also reveal where existing workflows are already failing to meet employees' needs.
If several teams independently adopt the same service for the same task, that may be a sign that the company should automate the task centrally. If employees repeatedly supplement the official AI assistant with an external product, it is worth asking which functionality the approved tool is missing. If new products are constantly adopted without approval, the problem may lie not only in employee discipline, but also in the speed of the approval process itself.
Unofficial use cases can show where sustainable demand for automation already exists inside the organization. Employees are experimenting with new ways of working, and some of those solutions may ultimately benefit the entire business. Management's task is to separate useful applications from those where the benefits do not justify the risks-and then move the solutions that genuinely work into a controlled corporate environment.
Shadow AI is often framed primarily as a violation of corporate policy. But the scale of unofficial AI use also depends on the companies themselves: whether their tools reflect the reality of employees' work, how quickly they evaluate new technologies, and whether employees clearly understand what is and is not allowed.
The more tasks AI takes on, the less effective a policy based solely on prohibition becomes. A ban alone is not enough: the simpler, faster, and more useful the safe official path is, the less reason employees have to look for a workaround.