TL;DR: Your staff are already using AI tools that nobody at your company approved, and most of the time nobody knows it is happening. This is called shadow AI. In 2026 it stopped being a theoretical worry and became one of the biggest causes of real data leaks. The fix is not to ban AI, because bans do not work. The fix is to see what people are actually using, give them a safe approved tool that is good enough to prefer, and set simple rules about what information must never be typed into an outside AI.
A marketing person drops a client brief into a free chatbot to speed up a first draft. A developer pastes a chunk of company code into an AI assistant to fix a bug faster. A finance analyst uploads a spreadsheet to summarise it before a meeting. None of them mean any harm. They just want to finish the work and go home. Added up across a whole company, though, these small private decisions have become one of the fastest growing security holes in business today.
What Shadow AI Actually Means
Shadow AI is the use of any AI tool at work without the knowledge or approval of the people responsible for security, IT, and legal. The word "shadow" is the point. It happens in the dark, outside company view.
It is the younger cousin of a problem companies already know, called shadow IT, which is when employees use software or apps that the IT department never signed off on. Shadow AI is worse in one specific way, and this difference is the whole reason it deserves its own name.
With old shadow IT, an unapproved app mostly just stored your data somewhere the company did not choose. With shadow AI, the tool sends your data out to an AI system run by an outside company. That system may keep the data, process it, or even use it to train future versions of the AI. Once your customer records or your source code have gone into someone else's AI, you often cannot get them back. Think of shadow IT as leaving your files in the wrong drawer, and shadow AI as reading them out loud to a stranger who never forgets.
Shadow AI is not only chatbots. It also includes AI coding assistants, AI note takers that join video calls and write summaries, and browser add-ons (small tools you install into Chrome or Edge) that read the web pages you look at so they can help you. Each of these can quietly send company information outside.
Why It Happens So Easily
The honest answer is that people are trying to do good work, not to cause harm. A few forces push them toward unapproved AI.
- Pressure to be faster. AI genuinely saves time, so people reach for it the moment they feel busy or stuck.
- No clear rule to follow. Most companies still have no written policy on AI, so employees are not breaking a rule they were never given. They are filling a silence.
- The free version is right there. The easiest tools to grab are the free ones, and free tools are usually the ones that reserve the right to reuse whatever you type in.
- Convenience always wins. The same instinct that once made people email work files to their personal Gmail now makes them paste work into a personal AI account. If the safe path is slower, most people take the fast one.
The Numbers That Made 2026 the Turning Point
For a couple of years shadow AI was talked about as a risk that might cost you one day. In 2026 three major security reports put hard figures on it, and the figures are large.
| Source | What it measured | 2026 figure |
|---|---|---|
| IBM, Cost of a Data Breach Report | Breached organisations where unapproved AI use was involved | 43%, up from 20% |
| IBM, Cost of a Data Breach Report | Average cost of a breach involving shadow AI | 5.39 million dollars, against a 4.99 million dollar overall average |
| Verizon, Data Breach Investigations Report | Employees regularly using AI tools on company devices | 45%, up from 15% |
| Netskope | Workplace AI use partly or wholly outside company control | Close to 44% |
Shadow AI now shows up in almost half of all breaches
IBM runs a yearly study called the Cost of a Data Breach Report. A breach simply means an incident where data was exposed, stolen, or leaked. The 2026 edition looked at 602 organisations that suffered a breach. It found that unapproved AI use was involved in 43% of those breached organisations, more than double the 20% seen the year before. Breaches that involved shadow AI cost more than the average, around 5.39 million dollars each. The overall average cost of any breach also hit a record high of 4.99 million dollars.
The report also found the gap that lets this happen: 68% of the breached organisations had no policy for managing or spotting AI use, and 92% of those hit by an AI related breach had no proper controls over who or what could access their AI systems.
Unapproved AI use on work devices tripled in a single year
Verizon publishes a widely read yearly study called the Data Breach Investigations Report. Its 2026 edition found that the share of employees regularly using AI tools on company devices jumped from 15% to 45% in just twelve months. Two out of three of those people were signed in with personal accounts, which means the company had no way to see or control what was being shared. The single most common type of information being fed into these outside tools was source code, the underlying instructions that make a company's software work.
Nearly half of all workplace AI use sits outside company control
Netskope, a security firm that watches how company data moves to cloud and AI services, reported in 2026 that only about 56% of workplace AI use happens fully inside tools the company manages. Another 14% is a mix of approved and personal tools, and 30% runs entirely through personal accounts. Put together, close to 44% of AI activity is partly or wholly beyond the company's view. In plain terms, for every ten things your staff do with AI, roughly four are happening somewhere you cannot watch.
Who Is Most at Risk
Shadow AI can touch any team, but a few groups carry more risk than others.
- Software developers. They paste source code into AI assistants to debug or improve it, and code is the most leaked data type of all. Losing it can mean handing rivals the recipe for your product.
- Regulated industries such as finance, healthcare, and law. These sectors are bound by strict data laws, for example GDPR in Europe (the rulebook on handling personal data), HIPAA in US healthcare, and the EU AI Act. Leaking protected data through an unapproved tool can bring fines on top of the breach itself. IBM found that about one in five AI related breaches led to a regulatory fine.
- Anyone in confidential meetings. HR, legal, finance, and executives increasingly let AI note takers record and summarise calls. Those recordings can capture staff issues, strategy, and trade secrets, which then live on an outside server.
- Companies with no rules at all. If there is no policy and no approved tool, every employee is left to improvise, and improvised security is not security.
How to Get It Under Control
The clear message from every 2026 source is the same: banning AI does not work. When companies block the popular tools, employees simply switch to a personal phone or find a workaround, and the activity goes even deeper into the dark. The goal is not to stop AI. It is to give people a safe path and make that path the easy one. Here is a practical order to follow.
- See what is really being used. You cannot protect against tools you do not know exist. Start by finding which AI tools, accounts, and browser add-ons are already in play across the company.
- Sort tools and data by risk. Decide which tools are approved, which are restricted, and which are banned. Just as important, decide which kinds of information must never go into any outside AI, such as customer records, passwords, and source code.
- Offer a good enough approved tool. This is the step most companies skip, and it is the one that actually works. If the sanctioned tool is as good as the free one people already like, they will use it. If it is clunky, they will go back to the shadows.
- Enforce at the moment data moves. Use data loss prevention software, often shortened to DLP, which watches for sensitive information leaving the company and can warn the user or block the action before it happens.
- Keep watching and name an owner. Give one senior person, usually the security or IT lead, clear responsibility, and keep monitoring, because the tools people use change every month.
- Lean on an existing framework. You do not have to invent the rulebook. Recognised guides such as the NIST AI Risk Management Framework (a free US government structure for managing AI risk), ISO/IEC 42001 (an international AI management standard), and the EU AI Act all point to the same basics: know your tools, rank them by risk, and monitor them.
What It Looks Like in Real Life
The statistics land harder when you see the human version. The stories below are individual accounts and public incidents, not survey data, but they show exactly how shadow AI plays out.
The most famous case happened at Samsung. Engineers pasted confidential source code and internal material into ChatGPT to fix problems faster, and in doing so leaked that material outside the company. Samsung responded by restricting AI tools on company devices. The lesson was not that the engineers were reckless, but that smart, well meaning people will hand over secrets without realising where the data goes.
On the professional forum Blind, one worker described a colleague pasting the company's entire codebase into ChatGPT, including secret keys and passwords, out of pure laziness, and then asked whether that could get the colleague in trouble. The replies split between people urging him to warn a manager and rotate the exposed keys, and others attacking him for even raising it. That argument captures the real tension inside teams: everyone wants the speed, and nobody wants to be the one who says stop.
The risk is not limited to programmers. In discussions about AI note takers, professionals who handle sensitive calls keep repeating a simple rule of thumb: if you would not want anyone else to know what was said in a meeting, do not put that meeting into an AI transcriber. Clients often accept a junior colleague sitting in on a call, yet object the moment an AI recorder appears, because they sense the conversation is about to leave the room and never come back.
The Bottom Line
Shadow AI is not a sign that your people are careless. It is a sign that AI is useful and that your company has not yet given them a safe way to use it. The organisations that come out ahead will not be the ones that tried to ban it. They will be the ones that shone a light on what was already happening, offered a trusted tool, set a few clear rules, and made the safe choice the easy choice.
If you want help mapping what your teams are already using and putting safe rules around it, our cybersecurity consulting and AI readiness audit teams do exactly this work.
Resources
- IBM Cost of a Data Breach Report 2026 (via Help Net Security)
- IBM 2026 breach report, AI governance analysis (Kiteworks)
- IBM Cost of a Data Breach, official IBM overview
- Ungoverned AI and rising breach costs (Cybersecurity Dive)
- Verizon DBIR 2026, shadow AI findings (LayerX)
- Verizon DBIR 2026 findings summary (Mimecast)
- Netskope AI Report 2026 (official)
- Shadow AI enterprise playbook, Netskope figures explained (Seimless)
- What shadow AI is, risks and governance (Wiz)
- Understanding shadow AI risks and the Samsung case (Adaptive Security)
- Shadow AI governance framework, NIST and enforcement (Strac)
- Samsung AI ban after source code leak (Business Insider via Yahoo)
- Shadow AI creates headaches for IT teams (Axios)




