Knowledge · AI at work · 7 minutes
Shadow AI: what it is, how to spot it and how to reduce it
Shadow AI means AI tools used at work without the company knowing. Examples, research figures, how to detect it in your company and reduce it without bans.
Last updated: October 5, 2026
What is shadow AI?
Shadow AI is any use of an AI tool for company work without the knowledge or approval of the people responsible for data and systems. The name comes from shadow IT, meaning software and services employees set up on their own.
The difference is that an AI tool usually receives content: documents, emails, code, meeting recordings. Once that content reaches an external service, it is hard to take back.
Shadow AI rarely comes from bad intent. People want to finish work faster, and the company has not given them a tool or told them what to use.
Increasingly, shadow AI does not even need an employee's decision. Vendors of software the company already uses add AI features in updates. Meeting notes, email summaries or an editor assistant can start sending content to a new subprocessor nobody in the company knows about.
Examples of shadow AI at work
An employee pastes a contract into a personal AI chat account to get a summary. A salesperson uploads a customer list so the AI can write personalised emails. Someone invites a bot to a client meeting that records it and takes notes.
Less obvious cases: a browser extension with an AI assistant that reads every open page, including the HR system. An AI feature switched on automatically in software the company already uses. An AI agent connected to a mailbox or drive, which we cover in AI agent security. A developer pasting a log containing an API key into a chat.
Shadow AI can also sit on your website: an AI chat widget added by an agency or plugin that sends customer conversations to an external service. You can check for free which third parties your site shares data with.
How common is shadow AI?
According to the Microsoft and LinkedIn Work Trend Index 2024 (a survey of 31,000 people in 31 countries), 78% of AI users bring their own AI tools to work, rising to 80% in small and medium businesses.
According to IBM's Cost of a Data Breach Report 2025 (600 organisations, breaches from March 2024 to February 2025), one in five organisations reported a breach involving shadow AI, and only 37% had policies to manage AI or detect shadow AI. Organisations with high levels of shadow AI paid about USD 670,000 more per breach on average.
IBM published the 2026 edition on 29 July 2026. We did not find new shadow AI figures in IBM's own press materials, so we quote the 2025 edition.
Why is shadow AI a risk for companies?
Data leaves without a contract. Personal accounts come with no data processing agreement, which Article 28 of the GDPR requires, and on some individual plans conversations can be used to train models. We cover ChatGPT in detail in can you paste company data into ChatGPT.
There is no trail. The company does not know what was sent and when, so after an incident it cannot assess the scope or notify the people affected.
Decisions rest on unchecked output. Models make mistakes, and a tool that reads web pages and emails can be manipulated by hidden instructions, as explained in what is prompt injection.
It is harder to show compliance with Article 4 of the EU AI Act, which requires companies using AI to support their staff's AI literacy. You cannot train people on tools you do not know exist.
How to detect shadow AI in your company
1. Ask. A short anonymous survey (which AI tools you use, for what, on which account) tells you more than weeks of log analysis. Say upfront that answers will not lead to sanctions.
2. Review app consents in Google Workspace or Microsoft 365. AI tools often request access to mail, calendar and drive through sign-in with a company account.
3. Check browser extensions on company computers and the admin panels of software you already use. AI features are sometimes switched on by default in an update.
4. Look at expenses. AI subscriptions paid with a company card or claimed back show what your team actually needs.
5. If you run DNS filtering or a proxy, check traffic to popular AI service domains. It shows scale, not content, and it does not cover personal phones.
What to do with the AI tools you found
Put every tool you found into one of three groups. Keep: move it to a business plan, sign a data processing agreement and add it to the approved list. Replace: people need the function, but the tool does not meet your conditions, so point them to an approved alternative. Remove: the tool is not needed or the risk is too high, so revoke access and app consents.
Separately, check what has already left. If personal data went into a tool, whoever is responsible for data protection assesses whether it is a breach that must be reported to the supervisory authority within 72 hours (Article 33 GDPR). If keys, passwords or tokens went in, revoke them and issue new ones. Deleting a conversation does not undo the exposure.
Finally, record the outcome: which tools were found, what was decided and when. That record shows the company is in control of the AI systems it uses, which helps in an audit and when a customer asks about your rules.
How to reduce shadow AI without banning it
A ban without an alternative moves usage to personal phones, where you see even less. It works better to give people what they are looking for on the company's terms.
Step 1. Approve one or two tools on a business plan with a data processing agreement. Step 2. Write a short policy: what may be pasted, what may not, who checks output. There is a ready template in AI use policy for companies. Step 3. Set up a fast way to request new tools, with an answer in days, not months.
Step 4. Train the team and record who completed the training. Step 5. Announce that reporting your own mistake, such as pasting customer data, does not lead to sanctions. Without that, nobody mentions a problem until it is too late. Step 6. Repeat the survey after a quarter.
Measure two things: how many people use the approved tools and how many requests for new tools come in. Growing use of approved tools and a steady flow of requests mean shadow AI is shrinking. Silence usually means people are doing it their own way again.
In short
- Shadow AI is AI tools used for work without the company's knowledge or approval. Most often that means personal AI chat accounts, browser extensions and note-taking bots.
- According to the Microsoft Work Trend Index 2024, 78% of AI users bring their own tools to work.
- The fastest ways to detect it are an anonymous survey, a review of app consents on company accounts and a look at expenses.
- Bans without alternatives do not work. An approved tool on a business plan, a short policy and a fast request path do.
Have a website, app or email address that looks suspicious?
Frequently asked questions
Shadow AI vs shadow IT: what is the difference?
Shadow IT is any software used without IT approval. Shadow AI is the part of it where the tool receives company content to process, so the risk is mainly about data rather than the installation itself.
Is shadow AI illegal?
Not in itself. It becomes a legal problem when personal data goes into a tool without a legal basis and a data processing agreement (GDPR), or when trade secrets or information under an NDA are shared.
Can you block shadow AI completely?
No. Blocking websites on the company network does not cover personal phones. You can reduce it by providing an approved tool and clear rules.
Who is responsible for shadow AI in a company?
The company is responsible for data as the controller, so ultimately management. In practice, name one person to keep the tool list and receive reports.
Sources
- Microsoft and LinkedIn: 2024 Work Trend Index on the state of AI at work (08.05.2024)
- Microsoft WorkLab: 2024 Work Trend Index, AI at work is here. Now comes the hard part
- IBM: Cost of a Data Breach Report 2025, press release (30.07.2025)
- IBM: Cost of a Data Breach 2026, press release (29.07.2026)
- Regulation (EU) 2016/679 (GDPR), EUR-Lex
- European Commission: AI Literacy, Questions & Answers
Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.