Logo
Decide better.Live better.
Logo
Decide better.Live better.

Shadow AI is tripling at your company. Here is how to stay safe. Stop covert data leaks by shifting from rigid restrictions to a 'Guided Adoption' framework

A responsible workplace technology team identifies unapproved AI activity and builds clear, human-centered safeguards around sensitive information.

Understanding the 'shadow AI' trend helps professionals navigate the evolving workplace without risking their jobs or company security. By advocating for better corporate tools, employees can enjoy the productivity gains of AI while ensuring their data remains protected and their work practices remain compliant.

banner

Your colleagues are likely using ChatGPT or Claude to summarize meetings, draft emails, and write code, often without telling IT. That is more than a minor policy breach. It can create a data security gap that puts proprietary information, customer trust, and employees’ jobs at risk.

In an announcement about its 2026 Data Breach Investigations Report, Verizon reported that employee use of unapproved “shadow AI” had tripled year over year, reaching 45% of employees who regularly used AI on corporate devices. Verizon also reported that roughly 67% of employee generative AI traffic took place through personal or noncorporate accounts. These figures describe Verizon’s reported findings, not a universal measure of every workplace.

Why restrictive AI tools push people toward shadow AI

The main driver is usually process friction, not malice. When a corporate AI tool is slow to approve, difficult to access, or missing the flexibility of public models, workers look for a faster route. The convenience is understandable. The problem is that personal accounts can remove the organization’s ability to manage access, retention, and data use.

Freshworks reported that 27% of U.S. mid-market IT leaders selected slow approval processes as the primary reason employees bypass IT and use unapproved AI tools. That is a reported survey response, not proof that approval delays cause every instance of shadow AI. It still points to a practical lesson: if the approved path makes work harder, employees are more likely to avoid it.

What employees may be putting at risk

Public AI tools can be useful, but pasting company information into an unapproved service may expose it to handling, retention, or reuse practices the organization has not reviewed. Depending on the information involved, a leak can create contractual, privacy, intellectual-property, or regulatory problems. Customer data should never be entered into a public model unless the organization has approved the service and put suitable contractual and technical controls in place.

Cyberhaven Labs’ 2025 telemetry analysis found that 34.8% of the corporate data employees put into AI tools was classified as sensitive, including source code, research and development material, and sales or marketing data. This is vendor telemetry, so it should not be treated as a measurement of every corporation or every AI tool.

A June 11, 2026 PagerDuty survey of 500 U.S. respondents found that 88% said they had shared work-related information with public AI tools. Among the respondents, 43% said they had shared work-related emails, 40% meeting notes, 34% customer data, and 31% financial or confidential documents. These are survey responses about reported sharing, not continuous monitoring of all employees. The customer-data finding is especially important: employees should follow their organization’s data-handling rules and use only approved AI services for such material.

1. Give employees a sandbox that is safe enough to use

A secure tool that nobody wants to use will not close the gap. Organizations should provide sandboxed AI tools with the practical flexibility people value in public services such as ChatGPT or Claude. That can include approved access to useful models, clear limits on what data may be entered, and controls that help the company protect sensitive information.

The goal is not to make every task pass through a rigid approval queue. It is to give employees a fast, understandable way to work without having to choose between productivity and security.

2. Make approval faster than the workaround

Procurement and security reviews should reflect the way employees actually work. Companies can create a short path for low-risk use cases, publish approved tools in one place, and explain what information is off-limits. Higher-risk use cases can receive deeper review without forcing every experiment into the same process.

This approach gives IT visibility while preserving momentum. Employees get an answer quickly, and leaders gain a clearer picture of which AI uses are creating genuine value.

3. Replace fear with transparent reporting

Employees are more likely to report an AI use case when doing so does not feel like admitting misconduct. Leaders should invite questions, explain why certain data is restricted, and provide a clear route for requesting a new tool or workflow. Reports should lead to guidance and risk reduction wherever possible, not automatic punishment.

For business leaders, the decision is straightforward: if the official AI environment is less useful than the unofficial one, shadow AI will remain attractive. A Guided Adoption strategy makes the safer choice the easier choice. That protects company information while allowing employees to keep the productivity benefits that brought them to AI in the first place.

Feed