Shadow AI is employee or team use of AI tools, models, or AI-enabled features at work without the knowledge, approval, or governance oversight of IT, security, or compliance functions, typically through personal ChatGPT, Claude, Gemini, or Copilot accounts, or AI features quietly switched on inside everyday SaaS applications. It differs from sanctioned enterprise AI in one critical respect: no one accountable for risk in the organisation can see what data went in, what came out, or which business decisions the output touched. MIT Project NANDA's July 2025 report, "The GenAI Divide: State of AI in Business 2025," found that employees at over 90% of surveyed organisations use personal AI tools for work even though only around 40% of those organisations have purchased an official enterprise LLM subscription, a gap subsequently described in press coverage as the "shadow AI economy." Verizon's 2026 Data Breach Investigations Report tracked the security consequence of that gap: unauthorised AI tool use on corporate devices roughly tripled in twelve months, from about 15% to about 45% of employees, making it one of the most common non-malicious causes of data loss in its incident dataset. For governance teams, shadow AI matters because it is now probably the single largest unmanaged category of AI risk inside most organisations, larger in volume than any sanctioned AI deployment they are actively governing.
Run the free AI Health CheckShadow AI, Employee use of AI tools without organisational authorisation, oversight, or governance, typically through personal accounts or browser-based consumer AI services.
Shadow AI is one of the most common AI risks in enterprise environments: MIT Project NANDA's "The GenAI Divide: State of AI in Business 2025" (July 2025) found that over 90% of employees at surveyed organisations use personal AI tools like ChatGPT or Claude for work tasks, even though only around 40% of those organisations have purchased an official enterprise LLM subscription. Industry analyses of the Verizon DBIR 2026 data show unauthorised AI use on corporate devices roughly tripled in a year (from about 15% to about 45%), making it the third most common non-malicious insider action in the report's data-loss-prevention dataset, with source code the most frequently leaked data type into external AI tools. In Australia, APRA's Prudential Standard CPS 230 (Operational Risk Management) -- in force since 1 July 2025, with transitional arrangements for existing third-party and service-provider contracts that extended to 1 July 2026 -- now applies in full across all regulated entities and contracts, and carries AI-inventory-adjacent obligations by requiring institutions to identify material business processes and material third-party/service providers. Mitigation combines enterprise AI tooling (so employees do not need shadow tools), policy, and detection.
Source: MIT Project NANDA, "The GenAI Divide: State of AI in Business 2025" (July 2025); Verizon DBIR 2026 (via corroborating industry analyses); APRA Prudential Standard CPS 230 (Operational Risk Management)
The core driver is a speed mismatch. Employees need help with a task today; official enterprise AI rollouts move on procurement, security review, and budget cycles measured in months. A twenty-dollar-a-month consumer AI subscription already works, so people reach for it. MIT Project NANDA's 2025 study, based on 52 executive interviews, 153 survey responses, and a review of more than 300 public AI implementations, framed this directly: employees at over 90% of surveyed organisations use personal AI tools for work, while only around 40% of those organisations had bought an official LLM subscription at the time of the study.
Shadow AI takes several forms in practice: personal chatbot accounts used for drafting, research, or coding; AI features built into everyday SaaS tools (meeting transcription, writing assistants, spreadsheet copilots) that get switched on by a team without any IT review; and developers or analysts calling AI APIs directly in scripts or internal tools outside any approved architecture. None of these require malicious intent, they are almost always a rational response to slow-moving official alternatives.
Data exposure and retention
Prompts and pasted documents sent to a consumer AI account may be retained or used to improve the vendor's models, depending on account tier and settings, exposing information the organisation never intended to share externally.
Confidentiality and contract breach
Client data, personal information, or trade secrets shared with an ungoverned tool can breach NDAs, procurement contracts, or sector confidentiality obligations, regardless of whether the disclosure was accidental.
Security blind spot
Verizon's 2026 DBIR found unauthorised AI use tripled to around 45% of employees in a year and is now one of the most common non-malicious causes of data loss in its dataset, with source code the most frequently leaked data type.
Regulatory blind spot
Under regimes such as the EU AI Act and GDPR, an organisation cannot assess, disclose, or control AI use it does not know exists. Shadow AI defeats AI inventories and risk registers before they are even built.
Output quality and liability
Unvalidated AI output used in real decisions, advice, code, or analysis, can introduce hallucination, bias, or error, and the organisation remains accountable for the outcome regardless of which tool produced it.
Build a live AI use inventory
A refreshed register of AI tools and models in use, built from employee surveys, procurement records, and technical discovery, is the precondition for every other control.
Offer a sanctioned alternative
Providing an enterprise-licensed AI tool with equivalent capability removes the main incentive for shadow use, directly addressing the gap MIT Project NANDA identified.
Monitor the network and endpoints
CASB, DLP, and browser-extension controls can detect traffic to consumer AI domains and flag sensitive data leaving the organisation before it reaches an ungoverned tool.
Set and enforce policy
A clear, communicated AI acceptable-use policy, paired with training on what can and cannot go into an AI prompt, turns an abstract risk into a concrete, followable rule.
Align with the applicable regime
In Australia, APRA's CPS 230 operational risk standard (commenced 1 July 2025, with transitional arrangements for existing third-party/service-provider contracts extending to 1 July 2026 -- a deadline that has now passed, bringing the standard into full effect across all regulated entities and contracts) already requires regulated entities to identify material business processes and material third-party providers, which extends naturally to knowing where AI, sanctioned or not, actually sits in the business.
What is shadow AI?
Shadow AI is the use of AI tools, models, or AI-enabled features at work without the knowledge, approval, or oversight of an organisation's IT, security, or compliance functions. It typically takes the form of employees using personal ChatGPT, Claude, Gemini, or Copilot accounts for work tasks, teams switching on AI features inside everyday SaaS tools without review, or developers calling AI APIs directly. The defining feature is not that the AI is bad, it is that nobody responsible for risk in the organisation can see what data went in, what came out, or which decisions the output touched.
How common is shadow AI in the workplace?
Very common, and growing fast. MIT Project NANDA's July 2025 report, "The GenAI Divide: State of AI in Business 2025," found that employees at over 90% of surveyed organisations use personal AI tools for work, while only around 40% of those organisations have an official enterprise LLM subscription. On the security side, Verizon's 2026 Data Breach Investigations Report found unauthorised AI tool use on corporate devices roughly tripled in a year, from about 15% to about 45% of employees.
Is shadow AI the same thing as shadow IT?
Shadow AI is best understood as a fast-growing subset of shadow IT (unsanctioned technology use generally), but it carries distinct risks that older shadow IT categories did not. Consumer AI tools can retain or learn from submitted prompts and documents depending on account settings, meaning a single pasted document can expose data far beyond what a single unsanctioned spreadsheet or app ever could.
What is the biggest risk of shadow AI?
Two risks compound each other. First, data exposure: information pasted into a consumer AI account may be retained by the vendor or used to improve its models, and Verizon's 2026 DBIR found source code is the most frequently leaked data type into external AI tools from enterprise environments. Second, a regulatory and governance blind spot: an organisation cannot assess, disclose, or control AI use it does not know exists, which undermines AI inventories, risk registers, and obligations under frameworks like the EU AI Act or GDPR before they even start.
How can an organisation detect shadow AI use?
Common detection methods include maintaining a live AI use inventory refreshed through employee surveys and procurement review, network and endpoint monitoring (CASB and DLP tools flagging traffic to consumer AI domains and sensitive data leaving the network), browser extension controls, and reviewing expense/subscription records for personal AI tool charges. Providing a sanctioned enterprise AI tool that matches what employees actually need is widely considered the most effective way to reduce the incentive for shadow use in the first place.
Does using shadow AI break the law?
Using an AI tool without authorisation is not automatically illegal, but it can easily create a legal or contractual breach depending on what data is involved. Pasting client data, personal information, or trade secrets into a consumer AI account can breach data protection law such as GDPR, sector-specific confidentiality obligations, employment contracts, or client NDAs, none of which depend on whether IT knew the tool was in use.
Last reviewed July 2026