Shadow AI Explained: Why Employees Use Unapproved Tools and What to Do
Shadow AI is AI used for work without approval. In IBM's 2025 study, 1 in 5 breached firms reported a shadow AI breach. Why it happens and what beats a ban.

Shadow AI is the use of AI tools for work without the knowledge or approval of the organization: a free chatbot on a personal account, a browser extension that rewrites emails, an AI feature nobody responsible for data has reviewed. The UK’s National Cyber Security Centre (NCSC) treats it as one form of shadow IT, which it says rarely stems from malice and usually from people trying to get their work done.1
The risk is still real. In IBM’s 2025 Cost of a Data Breach Report, one in five of the 600 breached organizations studied reported a breach due to shadow AI.2 A ban is the reflex, but the response official guidance favors has five parts: find out, without blame, which tools people use; offer an approved tool for the same jobs; name the data that never goes in; make asking for a new tool quick; and make it safe to report a slip. Each becomes a step, with a checklist, after a look at why people reach for their own AI; our other explainers on AI at work cover policy and law.
What shadow AI is, and why the “shadow” matters
Shadow AI is defined by what the organization does not know, not by the tool. One chatbot can be approved at one firm and count as shadow AI at the next, simply because nobody accountable for the second firm’s data knows it is in use.
Definition
Shadow AI is the use of AI tools, extensions or features for work without the knowledge or approval of the organization, so the data they handle sits outside its security, privacy and record-keeping controls.
The NCSC’s guidance, updated in August 2026, lists unmanaged AI services, such as chatbots used with corporate data, among the unknown tools it calls shadow IT. It separates this from “bring your own device” schemes, where the organization keeps some control over company data on a personal phone; with shadow IT, it simply does not know whether there is a risk.1
Shadow IT researchers draw the same line. A 2019 systematic review of 107 papers, led by Stefan Klotz, contrasts covert shadow IT with “business-managed IT”: tools a team picks and runs itself, but openly and with IT’s agreement.3 That second kind is where AI use should end up.
An illustrative case: a recruiter in Johannesburg pastes interview notes, including a candidate’s name and salary expectations, into a free chatbot to draft a summary. The summary is good, but the notes now sit with a provider the company has no agreement with, and nobody knows. The question to ask of any AI tool at work, then, is whether someone accountable knows which data goes into it.
How common is bring-your-own AI at work?
Company surveys across dozens of countries agree that bringing your own AI tools to work is common. The largest is Microsoft and LinkedIn’s 2024 Work Trend Index, which asked knowledge workers who use generative AIgenerative AI: AI systems that produce new text, images, audio or code in response to a request, by generating output that resembles the data they were trained on. Chatbots built on large language models are the best-known kind.Full entry in the glossary at work whether their tools came from their employer.
The study
Limited evidence
Among AI users in a 31,000-person survey, bringing their own AI was the norm
Among knowledge workers who used generative AI at work, 78% were bringing their own AI tools to work, meaning tools their organization had not provided. The report found the habit in every age group, and about half of AI users said they were reluctant to admit using AI for their most important tasks.4
The answers are self-reportedself-report: A measure in which people describe their own behavior, feelings or circumstances, usually by answering a questionnaire. When the same person supplies both of the things being compared, shared habits of answering can make the link between them look stronger than it is.Full entry in the glossary, and Microsoft sells AI tools for work, so it has an interest in showing demand. Other surveys point the same way, though: in a 2023 Salesforce survey run with YouGov across 14 countries, from Brazil and India to Japan and the UAE, more than half of the workers using generative AI at work did so without formal approval.5 Exact shares vary with the year and the question; the habit itself is widespread.
The reluctance matters as much as the share: a manager who asks a team meeting “does anyone here use ChatGPT?” will hear less than the truth. So plan as if your team already uses outside AI tools, because a policy built on the belief that nobody does is built on a guess.
Why employees bring their own AI tools
Employees mostly turn to their own AI tools because the tools help with real work and the approved route is missing, slow or weaker. In Software AG’s 2024 survey of 6,000 knowledge workers in Germany, the UK and the US, the most common reason was preferring their independence, and a third said their IT team did not offer the tools they needed.6
The NCSC’s list of causes reads like an ordinary week: no sanctioned tool for a task, a slow or broken request process, and approved tools that lack a needed feature. Its example of a missing feature is AI for admin work such as rewriting documents or summarizing meetings. It adds a quieter cause: people often do not realize a personal tool carries risk.1
Shadow IT research from before generative AI tells the same story: the Klotz review names a gap between what users need and what official systems offer, slow IT departments and highly motivated employees, and notes that staff often do not know the rules.3 A 2025 University of Melbourne survey across 47 countries, part-funded by KPMG, found that more than half of employees who use AI at work had done so without knowing whether that was allowed.7
Picture a finance analyst in Singapore with supplier invoices to reconcile by Friday. The approved software has no AI help, a new tool needs a business case, and a public chatbot opens in the next tab. Using it feels like diligence, not rule-breaking.
Every shadow tool you find is also a request in disguise: it shows you work the approved tools are failing to support. Read it that way before deciding how to respond.
What shadow AI puts at risk
Shadow AI’s main risk is that company or personal data goes somewhere the organization cannot see, protect or get back. In IBM’s 2025 Cost of a Data Breach Report, which the Ponemon Institute ran and IBM sponsored, breached organizations with high levels of shadow AI had breach costs about USD 670,000 higher on average than those with a low level or none. The comparison covers only organizations that had a breach between March 2024 and February 2025, and it is an association: organizations with a lot of shadow AI could also be unlike the rest in ways that push costs up. IBM also sells security products.2
The NCSC notes that controls such as encryption are unlikely to be applied effectively to shadow IT, so you cannot be sure where your data is, where it is processed or where it ends up.1 Picture a sales rep who pastes a client’s draft contract into a personal chatbot account: if the client later asks where its data went, the company has nothing to check.
Data protection law adds a second layer, and it differs by country:
- In the Netherlands, applying the EU’s GDPR, the Dutch data protection authority warned in 2024, after several breach notifications, that personal data entered into a chatbot contrary to the employer’s agreements amounts to a data breach. It adds that most chatbot providers store everything entered.8
- In Australia, the privacy regulator’s 2024 guidance says the Privacy Act 1988 applies to all uses of AI involving personal information by organizations it covers, and recommends as best practice that organizations keep personal information, especially sensitive information, out of publicly available generative AI tools.9
Elsewhere, check what your own data protection regulator says. The lesson here is timing: shadow AI does its damage out of view, so find it before an incident does.
Why banning AI tools can push the use out of sight
Blanket bans on AI tools can move the use out of sight rather than end it, because the work that drove it is still there. In Software AG’s 2024 survey, almost half of knowledge workers said they would not give up their own AI tools even if their employer banned them.6
In the Melbourne and KPMG survey, uploads of company information to public AI tools were reported most often by staff whose employer had banned generative AI.7 One survey cannot prove that bans cause uploads, and our guide to writing an AI use policy treats the finding with the same caution. The NCSC offers a reason the two could go together: blaming or punishing staff makes their colleagues reluctant to mention their own unsanctioned tools, leaving you with even less visibility. It also advises against unnecessary lockdowns of company IT.1
It’s important to acknowledge that shadow IT is rarely the result of malicious intent.
The Klotz review agrees: given the benefits reported, a complete prohibition does not seem reasonable, and controlled use looks more promising.3 Its sources are mostly pre-chatbot conference papers, and no trial has compared a ban with managed use, so treat this as expert judgment, not tested proof.
- Myth
- Blocking public chatbots on the company network ends shadow AI.
- Fact
- People can still reach them on personal phones. A block can simply hide the use, and blame makes staff less likely to report it.
Some limits are still right. The Dutch authority asks organizations to prevent both unauthorized chatbot use and approved use that the law does not permit.8 A firm line such as “no patient records in any chatbot” is a data rule, not a ban on AI, and people can follow it.
How to respond to shadow AI without banning everything
The NCSC’s approach to shadow IT gives a workable sequence for AI: find out what people use without blame, meet the needs behind it, and bring the tools above board, with data regulators adding a clear line on what may go in. It is expert guidance, not trial evidence, so watch how it works for you.
- Find out, without blame: ask which AI tools people use and for what
- Offer an approved option: one that does the job people turned to the outside tool for
- Draw a clear data line: which information never goes into a public tool
- Make asking fast: a simple, quick route to request a new tool
- Keep the door open: train people and welcome reports of mistakes
1. Find out what people use, without blame
Ask teams which AI tools they use and for what, and say in advance that nobody will be punished for the answer; the NCSC calls a positive, no-blame approach the most important part. Network tools help only partly: the NCSC notes that a cloud access security broker can spot unapproved cloud services but, without intercepting encrypted traffic, cannot see personal accounts on approved ones.1 An anonymous short survey tends to get truer answers than a show of hands, our inference from the reluctance the Work Trend Index found. A full shadow AI audit is the topic of a later guide.
2. Offer an approved tool that does the same job
The NCSC’s advice is to anticipate what users need, which may stop shadow IT from starting at all.1 Choose the approved tool for the tasks found in step 1, such as drafting, summarizing or translating, and if an outside tool keeps winning, ask what it does better.
3. Draw a clear line on data
The Dutch authority advises employers to decide whether staff may use chatbots and, if so, to tell them which data they may and may not enter; it also suggests agreeing with the provider that entered data will not be stored.8 Begin with a few named kinds of data that never go into a public tool, such as customer records, health information and other sensitive personal details. Sorting all company information into sensitivity levels comes later, in a planned guide on data classification.
4. Make asking for a new tool fast
The NCSC recommends a simple process for users’ requests, put in place quickly, and a way to give people controlled access to a service outside the usual set, which can be tightened later. Where a team already relies on an outside tool, the NCSC suggests bringing it under control, for example by moving its data onto a supported platform.1 In practice, that could be a one-page request form, a named owner and a reply promised within a week.
5. Train people, and make reporting safe
The Melbourne and KPMG authors conclude that clear guidance and education on responsible use are needed alongside any policy.7 Training should cover the data line and the request route, not only how to write prompts. Then name one contact for reporting a slip, and thank the people who use it: a mistake you hear about on day one leaves time to act.
Bringing shadow AI into view
When shadow AI becomes a legal question
Some moments depend on your country’s law and your contracts, not on management alone.
- Now: if personal data has gone into an unapproved AI tool, bring in your data protection officer or legal adviser straight away. In the Netherlands, the Dutch authority says that in many such cases it must be told, and so must the people whose data it was; elsewhere in the EU and beyond, check what your own regulator requires.8
- Soon: before approving a tool that will handle customer or staff personal data, check what the provider stores and where. Australia’s regulator, for example, lists cross-border disclosure among the obligations that organizations covered by its Privacy Act must consider.9
- Routine: before monitoring how staff use AI, ask a legal adviser whether that monitoring is allowed where you operate; the rules on watching employees differ by country.
The bottom line
Shadow AI is a symptom: people found AI useful before their organization gave them a safe way to use it. Treat it as information about unmet needs, not as a discipline problem. Start with a no-blame look at what is in use, offer an approved tool for the work people are doing, and agree on the few kinds of data that stay out of every public tool.
This article is general information, not legal advice. Rules differ by country and change over time; for your own situation, speak to a qualified lawyer or an official advice service where you live.
Frequently asked questions
Can an employer see when staff use unapproved AI tools?
Partly. The UK's National Cyber Security Centre says tools called cloud access security brokers can spot the use of unapproved cloud services by watching network traffic, but without breaking into encrypted connections they cannot see personal accounts on approved services. Use on a personal phone off the company network stays out of view. Whether and how an employer may monitor staff differs between countries, so check local rules and take legal advice first.
Is it against the law to use ChatGPT for work?
Not as such, in the guidance reviewed here; what matters is which data goes in and what your employer allows. In 2024 the Dutch data protection authority called personal data entered into a chatbot against the employer's agreements a data breach, and said even approved use is often not lawful. Australia's privacy regulator advises keeping personal information out of public AI tools. Elsewhere, check your own regulator.
I already put work data into an unapproved AI tool. What now?
Tell your manager or your organization's data protection contact as soon as you can, and say what data went in. The Dutch data protection authority said in 2024 that in many such cases it must be told, and so must the people whose data it was, which only works if the mistake surfaces quickly; elsewhere, check your own regulator. The UK's National Cyber Security Centre urges employers to respond to shadow IT without blame.
Sources
- Shadow IT: Managing 'unknown assets' that are used within an organisation. National Cyber Security Centre, UK (published 27 July 2023; last modified 14 August 2026)
- IBM Report: 13% Of Organizations Reported Breaches Of AI Models Or Applications, 97% Of Which Reported Lacking Proper AI Access Controls. IBM (30 July 2025). Cost of a Data Breach Report 2025, conducted by Ponemon Institute, sponsored and analyzed by IBM; not peer reviewed
- Causing factors, outcomes, and governance of Shadow IT and business-managed IT: a systematic literature review. Klotz, S., Kopper, A., Westner, M. & Strahringer, S. (2019). International Journal of Information Systems and Project Management, 7(1), 15-43
- AI at Work Is Here. Now Comes the Hard Part (2024 Work Trend Index Annual Report). Microsoft and LinkedIn (8 May 2024). Survey run by Edelman Data & Intelligence; company research, not peer reviewed
- More than Half of Generative AI Adopters Use Unapproved Tools at Work. Salesforce (15 November 2023). Survey run with YouGov; company research, not peer reviewed
- Half of all employees are Shadow AI users, new study finds. Software AG (22 October 2024). Survey conducted by TEAM LEWIS; company research, not peer reviewed; archived copy, original page offline
- Trust, attitudes and use of artificial intelligence: A global study 2025. Gillespie, N., Lockey, S., Ward, T., Macdade, A. & Hassed, G. (2025). The University of Melbourne and KPMG; funded by KPMG and the University of Melbourne; not peer reviewed
- Caution: use of AI chatbot may lead to data breaches. Autoriteit Persoonsgegevens, the Dutch Data Protection Authority (6 August 2024)
- Guidance on privacy and the use of commercially available AI products. Office of the Australian Information Commissioner (published 21 October 2024; updated 17 January 2025)
How we researched this
We read the UK National Cyber Security Centre's shadow IT guidance (updated August 2026), IBM's 2025 and 2026 breach report releases, company surveys by Microsoft and LinkedIn, Salesforce and Software AG, a 2025 University of Melbourne and KPMG survey, a 2019 systematic review of shadow IT research, and guidance from Dutch and Australian privacy regulators, checked on 26 September 2026. Main limitation: prevalence figures come from company surveys, and no trial compares bans with managed use.



