What is shadow AI?
Shadow AI is any AI tool used for work that the organization has not approved or reviewed. It runs on personal accounts, free browser tools, and AI features switched on inside software the company already pays for. That last one is the part most IT teams miss. A lot of shadow AI arrived through a vendor update nobody read. The people using it are usually the ones doing the most work.
How is shadow AI different from shadow IT?
Shadow IT is an employee using an unapproved application. Shadow AI is an employee feeding company information into a model that learns, stores, or forwards it. The difference is what leaves the building. An unsanctioned project tracker holds your data in one place you did not choose. An unsanctioned AI tool can put it into a training set, a vendor's logs, or an answer given to somebody else. Shadow IT is a control problem. Shadow AI is a control problem plus a disclosure problem.
What are the risks of shadow AI?
The risk people name first is data leaving the company, and it is real. IBM's 2025 Cost of a Data Breach Report found that 20% of breached organizations had a breach involving shadow AI. Those breaches cost up to $670,000 more than average. Behind that number is somebody who pasted a customer list into a chatbot on a deadline. The second risk gets less attention. Unreviewed AI output ends up in a contract or a hiring decision, and afterward nobody can say who checked it.
What are some examples of shadow AI?
A salesperson runs call notes through a personal AI account to write follow-ups. A finance analyst uploads a draft budget to a free chatbot for a sanity check. An engineer pastes production code into an assistant security has never seen. A manager builds a hiring rubric with a model and tells nobody it helped. Every one of these people is trying to do good work faster. That is what makes shadow AI hard to police and worth studying.
How widespread is shadow AI in enterprises?
Widespread enough that treating it as an exception is a mistake. Microsoft and LinkedIn's 2024 Work Trend Index surveyed 31,000 knowledge workers in 31 countries. It found that 78% of AI users bring their own AI tools to work. The same study found 52% are reluctant to admit using AI on their most important tasks. That second number is the one to sit with. Any estimate you have is built from the people who told you.
How do you stop employees from using shadow AI?
You mostly do not, and the attempt teaches people to hide it better. Start with discovery. Single sign-on logs and expense reports will show you most of the AI tools already in use, and who is using them for what. Then close the gap. Approve the tools people are actually reaching for and put a reviewed path around them. Say plainly what is off limits and why. A ban with no sanctioned alternative buys silence and calls it compliance.