Shadow AI

Shadow AI: What Your Employees Already Use Without Approval

Why your best people already use AI tools nobody approved, and what a real response looks like.

Alex's Take

I have never once seen a policy outrun a shortcut. Give smart people a slow official tool and a fast unofficial one, and they will pick fast every time, then keep quiet about it. Shadow AI is that same instinct with sharper software behind it. Your policy says one thing. Your workforce does another. That is the say/do gap, running upward instead of down. Read your shadow AI usage as a product review and you learn what people actually need. Read it as a discipline problem and you learn who hides it better.

— Alex Goryachev, former Managing Director of Innovation, Cisco

All articles on Shadow AI

No items found.
Work with Alex

Get ahead of the shadow AI already in your organization

Keynote presentations · Executive briefings · Workforce AI adoption workshops

310+ Keynotes, Workshops & Advisory Engagements

Frequently asked questions

If you don't see what you need, message Alex directly via the form below — answers usually within one business day.

What is shadow AI?

Shadow AI is any AI tool used for work that the organization has not approved or reviewed. It runs on personal accounts, free browser tools, and AI features switched on inside software the company already pays for. That last one is the part most IT teams miss. A lot of shadow AI arrived through a vendor update nobody read. The people using it are usually the ones doing the most work.

How is shadow AI different from shadow IT?

Shadow IT is an employee using an unapproved application. Shadow AI is an employee feeding company information into a model that learns, stores, or forwards it. The difference is what leaves the building. An unsanctioned project tracker holds your data in one place you did not choose. An unsanctioned AI tool can put it into a training set, a vendor's logs, or an answer given to somebody else. Shadow IT is a control problem. Shadow AI is a control problem plus a disclosure problem.

What are the risks of shadow AI?

The risk people name first is data leaving the company, and it is real. IBM's 2025 Cost of a Data Breach Report found that 20% of breached organizations had a breach involving shadow AI. Those breaches cost up to $670,000 more than average. Behind that number is somebody who pasted a customer list into a chatbot on a deadline. The second risk gets less attention. Unreviewed AI output ends up in a contract or a hiring decision, and afterward nobody can say who checked it.

What are some examples of shadow AI?

A salesperson runs call notes through a personal AI account to write follow-ups. A finance analyst uploads a draft budget to a free chatbot for a sanity check. An engineer pastes production code into an assistant security has never seen. A manager builds a hiring rubric with a model and tells nobody it helped. Every one of these people is trying to do good work faster. That is what makes shadow AI hard to police and worth studying.

How widespread is shadow AI in enterprises?

Widespread enough that treating it as an exception is a mistake. Microsoft and LinkedIn's 2024 Work Trend Index surveyed 31,000 knowledge workers in 31 countries. It found that 78% of AI users bring their own AI tools to work. The same study found 52% are reluctant to admit using AI on their most important tasks. That second number is the one to sit with. Any estimate you have is built from the people who told you.

How do you stop employees from using shadow AI?

You mostly do not, and the attempt teaches people to hide it better. Start with discovery. Single sign-on logs and expense reports will show you most of the AI tools already in use, and who is using them for what. Then close the gap. Approve the tools people are actually reaching for and put a reviewed path around them. Say plainly what is off limits and why. A ban with no sanctioned alternative buys silence and calls it compliance.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.