Loading
Loading
Loading
Loading
Loading
Loading
Loading
Loading
Loading
BackIT & DevOps

Shadow AI in the Enterprise: Detecting and Governing Unsanctioned Tools

Informat Team· 2026-07-20 01:30· 6.7K views
Shadow AI in the Enterprise: Detecting and Governing Unsanctioned Tools

Shadow AI in the Enterprise: Detecting and Governing Unsanctioned Tools

Shadow AI is the use of artificial intelligence tools — chatbots, code assistants, translation engines, meeting transcribers, and AI browser extensions — by employees without the approval, oversight, or knowledge of IT and security teams. It is the direct successor to shadow IT, and in 2026 it has become the fastest-spreading category of unsanctioned technology in enterprise history. Effective shadow AI governance rests on three pillars: discovering hidden AI usage, assessing and tiering its risks, and redirecting employee demand toward approved channels instead of issuing blanket bans that workers quietly ignore.

The urgency is measurable. IBM's 2025 Cost of a Data Breach Report, released on July 30, 2025, found that 20% of organizations have already suffered a breach linked to shadow AI, and those incidents added an average of $670,000 to breach costs, according to IBM's Cost of a Data Breach Report 2025. Meanwhile, research published by BlackFog on January 27, 2026 shows that 49% of employees at companies with more than 500 staff admit to using unsanctioned AI tools. This guide explains how shadow AI took hold, why it evades the controls that eventually caught shadow IT, and how to govern it without destroying the productivity gains that drove employees to it in the first place.

What Is Shadow AI and Why Is It Everywhere in 2026?

Shadow AI covers every AI interaction that happens outside sanctioned corporate channels. An analyst pasting quarterly figures into a free ChatGPT session, a developer wiring an unapproved code assistant into an IDE, a manager uploading a supplier contract to a public translation model — each is a shadow AI event, and each moves company data beyond the reach of enterprise security controls.

The phenomenon exploded because generative AI delivers immediate, personal productivity gains. Employees do not wait for procurement cycles when a browser tab solves their problem in seconds. According to LayerX Security's Enterprise AI and SaaS Data Security Report, published in October 2025, 67% of enterprise AI usage flows through personal, non-corporate accounts that bypass single sign-on, identity management, and data loss prevention entirely.

The most common shadow AI behaviors observed across enterprises include:

  • Pasting emails, reports, and source code into free consumer chatbots for drafting, debugging, or summarization.
  • Installing AI coding assistants, IDE plugins, or browser extensions without any security review.
  • Running contracts, HR documents, and internal strategy files through public translation or summarization models.
  • Connecting AI meeting notetakers to calendars and video calls where confidential matters are discussed.
  • Granting OAuth permissions to AI apps that gain standing access to corporate email, files, or chat history.

The Reco State of Shadow AI Report, summarized in the company's analysis of 400-plus days of hidden AI tool usage, found that 71% of knowledge workers use AI tools without IT approval, and 91% of enterprise AI tools operate outside IT control. Shadow AI is not an edge case. It is the default way most employees now experience artificial intelligence at work.

Shadow AI vs. Shadow IT: Why Unsanctioned AI Tools Are Harder to Catch

Shadow IT — unapproved SaaS subscriptions, rogue servers, personal file-sharing accounts — plagued IT departments for two decades. However, shadow IT eventually left a paper trail. A subscription surfaced on an expense report, a credit card statement, or a vendor invoice, and finance or IT could trace it back to the offending team.

Shadow AI leaves no such trail. BlackFog's research, published on January 27, 2026, found that 58% of employees using non-approved AI tools rely on free versions that never touch procurement, never generate an invoice, and never appear in expense audits, as detailed in the BlackFog shadow AI research announcement. A free ChatGPT session in a personal browser profile looks like ordinary web traffic, and the data leaves through a paste event rather than a monitored file transfer.

DimensionShadow IT (2005–2022)Shadow AI (2023–2026)
Typical costPaid subscriptions and hardwareFree or freemium tiers
Discovery trailExpense reports, invoices, license auditsOften none; personal accounts and browser sessions
Primary riskUnpatched software, data sprawlData leakage into model training, ungoverned outputs
Data movementFile uploads and folder syncsCopy-paste into prompts, API calls, OAuth grants
Detection approachAsset inventory, firewall logsCASB/SSE, browser telemetry, DNS analysis, prompt-aware DLP

The copy-paste point deserves emphasis. As SC World reported in October 2025, clipboard activity has overtaken file transfer as the leading corporate data exfiltration vector. Traditional data loss prevention tools were built around files, so a paragraph of source code pasted into a prompt sails straight past them. This structural blindness is why shadow AI governance demands new detection instruments, not just stricter enforcement of old ones.

How Widespread Is Shadow AI? The 2025–2026 Numbers

Every major study published between mid-2025 and mid-2026 converges on the same conclusion: shadow AI is pervasive, persistent, and frequently led from the top. CIO.com's reporting on unsanctioned AI adoption found that roughly half of employees use unapproved tools — and that enterprise leaders are among the worst offenders. BlackFog's January 2026 data agrees: 69% of C-suite executives believe speed trumps security when adopting AI tools.

The headline statistics paint a consistent picture:

  • 77% of employees who use generative AI paste data into prompts, and 82% of paste events originate from unmanaged personal accounts (LayerX Security, October 2025).
  • 71% of knowledge workers use AI tools without IT approval, with OpenAI services accounting for 53% of all shadow AI activity (Reco, 2025).
  • 60% of employees say using unsanctioned AI is worth the security risk if it helps them meet deadlines (BlackFog, January 27, 2026).
  • Shadow AI tools persist for more than 400 days on average before discovery, quietly becoming embedded infrastructure (Reco, 2025).
  • Only 37% of organizations have policies to manage AI or detect shadow AI (IBM, July 30, 2025).
  • 31% of shadow AI users have received no employer-provided AI training at all, according to Help Net Security's May 1, 2026 coverage.

The governance gap is the real story inside these numbers. Adaptive Security's survey, covered by Cybersecurity Insiders, found that 80% of employees use unapproved generative AI apps while only 12% of companies operate formal AI governance programs. Chirag Joshi, Chief Information Security Officer and founder of 7 Rules Cyber and President of the ISACA Sydney Chapter, captured the danger precisely.

We're seeing the rise of 'shadow AI' — the unsanctioned, untracked use of AI tools by employees. It's a massive blind spot. You wouldn't let every staff member install and run software at will, but that's exactly what's happening with generative AI. And the risk exposure is exponentially greater.

— Chirag Joshi, CISO and Founder, 7 Rules Cyber; President, ISACA Sydney Chapter

What Are the Real Risks of Unsanctioned AI Tools?

Unsanctioned AI tools create four distinct risk categories: data leakage, model training exposure, compliance violations, and ungoverned decision-making. Each operates silently, and each compounds the others. The table below maps the major shadow AI tool categories to their principal risks.

Shadow AI categoryTypical examplesPrimary risks
Consumer chatbotsFree ChatGPT, Gemini, DeepSeek sessionsPrompt data leakage, inputs used for model training, zero audit trail
AI code assistantsUnapproved IDE plugins and copilotsSource code exposure, license contamination, insecure code suggestions
Translation and summarization toolsPublic document translators, browser TL;DR extensionsContract and PII exposure, cross-border data transfer violations
AI meeting notetakersUnsanctioned transcription bots joining callsRecording of confidential discussions, third-party data retention
Agents and browser extensionsPersonal AI agents with OAuth grantsStanding access to email and files, uncontrolled autonomous actions

Data Leakage and Model Training Exposure

The canonical cautionary tale remains Samsung. In April 2023, engineers in Samsung's semiconductor division pasted proprietary source code and an internal meeting transcript into ChatGPT in three separate incidents within roughly 20 days. Because consumer terms at the time allowed inputs to feed model training, Samsung acknowledged it could not retrieve or delete the data, and in May 2023 the company banned generative AI tools on company devices, as Business Insider reported on May 2, 2023.

The 2025–2026 data shows the pattern has scaled, not shrunk. IBM found that shadow AI breaches compromised personally identifiable information in 65% of cases versus a 53% global average, and intellectual property in 40% of cases versus 33%. In other words, shadow AI incidents disproportionately expose exactly the data classes enterprises can least afford to lose.

Compliance Violations Without a Paper Trail

When employees route regulated data through personal AI accounts, they can breach GDPR, HIPAA, and sector-specific rules without any record existing for auditors. The European Union's AI Act regulatory framework raises the stakes further, with obligations for general-purpose AI models applying from August 2, 2025 and penalties tied to global revenue. Moreover, Gartner predicted on February 17, 2025 that more than 40% of AI-related data breaches will arise from improper cross-border use of generative AI by 2027. An unsanctioned translation tool hosted in another jurisdiction is a cross-border transfer no one approved.

Hallucinations and Decisions With No Guardrails

Risk is not limited to data leaving the building. Ungoverned AI outputs also flow back in: fabricated statistics pasted into board decks, hallucinated legal citations in client documents, and AI-generated code with subtle vulnerabilities merged into production. Sanctioned deployments typically mandate human review, grounding, and logging. Shadow AI has none of these guardrails, so a single confident hallucination can travel from a free chatbot into a signed contract without any checkpoint in between.

How Can Enterprises Detect Shadow AI Usage?

Shadow AI detection requires layered instrumentation, because no single control sees the whole picture. A practical program combines network-level discovery, browser-level telemetry, endpoint scanning, identity audits, and — perhaps surprisingly — simply asking employees. A TNGlobal analysis published on June 29, 2026 found that anonymous employee surveys typically reveal 15–20% more shadow AI tools than technical scans alone.

CASB and SSE Platforms

Cloud Access Security Brokers (CASB) and Security Service Edge (SSE) platforms are the workhorses of shadow AI detection. They classify outbound traffic against catalogs of known AI services and score each application's risk. For example, Cato Networks introduced generative AI security controls for Cato CASB on April 15, 2025, including a shadow AI dashboard covering more than 950 generative AI applications, granular access policies, and real-time data loss prevention for prompts. Microsoft Defender for Cloud Apps offers comparable discovery for Microsoft-centric estates, and in May 2026 Microsoft extended discovery to unmanaged AI agents on Windows endpoints.

Network Traffic and DNS Analysis

Even without a full CASB deployment, security teams can mine existing telemetry. DNS logs, secure web gateway records, and firewall data reveal connections to AI service domains and API endpoints. The goal at this stage is inventory, not punishment: build a ranked list of which AI services are being used, by how many users, and with what data volumes. Frequency spikes and after-hours usage patterns often indicate workflow-embedded tools rather than casual experimentation.

Browser-Level Monitoring and the Copy-Paste Problem

Because 82% of risky paste events come from personal accounts in unmanaged browser sessions, browser-level visibility is decisive. Enterprise browser extensions and secure enterprise browsers can distinguish corporate from personal logins on the same site and intercept sensitive pastes before submission. Complement this with OAuth consent audits — reviewing which AI apps employees have authorized against corporate identities — and endpoint scans for AI plugins inside IDEs and office suites.

A pragmatic discovery sequence looks like this:

  1. Mine DNS, proxy, and firewall logs for connections to known AI domains and APIs.
  2. Deploy CASB or SSE dashboards to classify and risk-score every discovered AI application.
  3. Audit OAuth grants and app consents in your identity provider for AI-related permissions.
  4. Scan endpoints and browsers for installed AI assistants, extensions, and IDE plugins.
  5. Run an anonymous, amnesty-backed employee survey to surface tools technology missed.
  6. Consolidate findings into a living AI asset inventory, refreshed at least monthly.

Gartner's analysts argue that discovery is the foundation everything else stands on. Speaking at the Gartner Security and Risk Management Summit in London in September 2025, covered by ITPro's report on the Gartner summit, Gartner VP of Research Christine Lee urged security leaders to move beyond prohibition.

Once you've discovered this shadow AI your job is to offer guidance better than 'nope not approved' because shadow AI is very quickly becoming ambient AI, embedded in everything.

— Christine Lee, VP of Research, Gartner, at the Gartner Security and Risk Management Summit, London, September 2025

Building a Shadow AI Governance Framework That Actually Works

Detection without governance just produces a longer list of problems. IBM's July 2025 findings underline the gap: 63% of breached organizations either had no AI governance policy or were still developing one, and 97% of organizations that suffered AI-related breaches lacked proper AI access controls. A workable shadow AI governance framework starts with ownership, because accountability is the scarcest resource. A Mindgard survey presented at RSA and Infosecurity Europe 2025, reported by Computing's coverage of shadow AI concerns, found that 39% of security professionals say no one in their organization owns AI risk.

The core artifact of the framework is an AI acceptable-use policy that employees can actually follow. Its essential components are:

  • A named catalog of sanctioned AI tools, mapped to permitted use cases and data classes.
  • An explicit list of prohibited data types for public AI tools: PII, PHI, financial records, credentials, source code, and trade secrets.
  • Redaction and anonymization requirements for any business data used in prompts.
  • Mandatory human verification of AI outputs before they enter decisions, code, or client deliverables.
  • Intellectual property rules for AI-generated content and disclosure standards.
  • A no-blame incident reporting channel for accidental exposure.
  • Quarterly policy reviews, because the AI tool landscape shifts too fast for annual cycles.

Governance should sit inside a cross-functional body spanning security, legal, compliance, data, and the business — the same coalition that steers any serious AI-driven digital transformation strategy. Crucially, the committee must move at the speed of experimentation. Quarterly approval meetings cannot govern tools that employees adopt in an afternoon.

The Approved AI Tool Catalog and Fast-Track Approval Process

The single most effective antidote to shadow AI is a visible, well-stocked catalog of approved alternatives. Employees go rogue when the sanctioned path is empty or slow. Consequently, mature programs use a three-tier model rather than binary allow-or-block decisions:

  1. Block: tools that train on user inputs by default, lack enterprise agreements, hold no compliance certifications, or claim rights over submitted content.
  2. Monitor: moderate-risk tools with an enterprise upgrade path; usage is logged, prompt-aware DLP is active, and users are steered toward approved equivalents.
  3. Approve: tools that pass security review with SSO integration, no-training-on-data contract clauses, audit logging, and clear data residency terms.

Pair the catalog with a fast-track approval process: any employee can request a new AI tool, triage happens against a standard risk rubric, and a decision lands within ten business days. Speed is the point. As EPC Group's research on BYOAI notes, the average enterprise already harbors 67 unsanctioned AI tools, and 23% of them have received sensitive corporate data — every week of approval delay recruits more of them.

Governed platforms make the sanctioned path genuinely attractive. Informat, the AI-powered low-code development platform at ai.informat.com, illustrates the pattern: employees get AI-assisted application building and automation inside an environment where administrators control permissions, data access, and audit logs. Teams evaluating such platforms should apply the same scrutiny they apply to any AI vendor, following established low-code security best practices for enterprise platforms — role-based access, environment isolation, and centralized logging chief among them.

AI Literacy Training: Turning Employees Into the First Line of Defense

Technology catches shadow AI; culture prevents it. The training gap is stark: Help Net Security's May 1, 2026 reporting found that 31% of shadow AI users have received no employer AI training whatsoever, while BlackFog found 60% of employees consider unsanctioned AI worth the risk to hit deadlines. People are not malicious — they are unequipped and under pressure.

Effective AI literacy programs are practical rather than legalistic. They should cover:

  • How generative AI services handle, retain, and potentially train on submitted data.
  • Concrete examples of prohibited prompts, including the Samsung source-code incidents of April 2023.
  • A simple heuristic for gray areas: if you would not share it with a direct competitor, do not paste it into a public chatbot.
  • How to find the approved catalog, request a new tool, and report accidental exposure without punishment.
  • How to verify AI outputs before they influence decisions, code, or customer communications.

Amnesty matters as much as instruction. Organizations that offer no-penalty self-reporting windows consistently surface more shadow usage and migrate it to safe channels faster than those that threaten discipline. Peter Garraghan, CEO of AI security firm Mindgard and a professor at Lancaster University, frames the organizational requirement bluntly.

Shadow AI isn't a future risk. It's happening now, often without leadership awareness, policy controls or accountability. Gaining visibility is a critical first step, but it's not enough. Organisations need clear ownership, enforced policies and coordinated governance across security, legal, compliance and executive teams.

— Peter Garraghan, CEO, Mindgard; Professor, Lancaster University

Balancing AI Governance and Productivity: Redirect, Don't Repress

The hardest part of shadow AI governance is restraint. Employees adopted these tools because they work, and heavy-handed prohibition punishes initiative while pushing usage further underground. Samsung's May 2023 ban is instructive: it stopped usage on corporate devices, but employees could still turn to personal phones, where corporate visibility is exactly zero. Blanket bans do not stop shadow AI; they relocate it beyond your instrumentation. Reco's analysis, Blocking ChatGPT Didn't Stop Them, found that 71% of workers kept using AI even where tools were blocked.

The better posture treats shadow AI as a demand signal. Every unsanctioned tool marks a workflow where employees lack a sanctioned way to automate drudgery. The governance principles that preserve productivity are:

  • Match every blocked tool with an approved alternative that is at least as capable, available within weeks rather than quarters.
  • Measure adoption of sanctioned tools as a program KPI, not just the count of blocked sessions.
  • Channel builder energy into governed environments — citizen developers who might script rogue automations can instead use platforms like Informat to assemble hyperautomation and AI workflow automation under IT-defined guardrails.
  • Publish approval decisions and reasoning openly, so employees trust the process instead of routing around it.

The organizations that govern shadow AI best treat employee demand as a product roadmap, not a disciplinary problem. When the safe path is also the fast path, the shadow shrinks on its own.

Shadow AI Governance FAQs

Security and IT leaders rolling out shadow AI governance programs raise the same questions repeatedly. The answers below distill the 2025–2026 evidence base into practical guidance.

Is banning ChatGPT an effective way to stop shadow AI?

No. Bans reliably fail because free AI tools are accessible from personal devices and unmanaged browsers that corporate controls never see. Reco's 2025 data shows 71% of knowledge workers use AI without approval even in environments with blocking in place. Bans also destroy the visibility you need: usage continues, but your telemetry goes dark. Detection, tiered controls, and strong approved alternatives outperform prohibition on every measured outcome.

What should an AI acceptable-use policy include?

A complete policy names the sanctioned tools and their permitted use cases, lists prohibited data types, and sets verification duties for AI outputs. It should also define the fast-track request process, the incident reporting channel, and the review cadence. Four elements are non-negotiable:

  • Explicit prohibited-data classes: PII, PHI, credentials, source code, financials, trade secrets.
  • A named, regularly updated approved tool catalog.
  • Human review requirements before AI output enters business decisions.
  • Quarterly updates, because annual reviews cannot track the AI market.

How is shadow AI different from BYOAI?

BYOAI — bring your own AI — describes employees deliberately using personal AI accounts and subscriptions for work, and EPC Group's research shows 78% of AI users bring their own applications to the job. Shadow AI is the broader category: it includes BYOAI plus tools a local manager "approved" without enterprise review, embedded AI features switched on inside sanctioned SaaS, and autonomous agents granted OAuth access. All BYOAI is shadow AI, but not all shadow AI is BYOAI.

Conclusion: Shadow AI Governance Is Now a Board-Level Priority

Shadow AI governance has moved from an IT hygiene task to a board-level obligation, because the numbers no longer permit complacency. One in five organizations has already been breached through shadow AI, at a premium of $670,000 per incident. Half or more of the workforce uses unsanctioned tools, executives lead the rule-breaking, and the average unauthorized tool operates undetected for more than 400 days. The invisible enterprise is already here — the only question is whether you can see it before regulators, attackers, or customers do.

The playbook that works is consistent across the 2025–2026 evidence:

  • Discover continuously with CASB/SSE dashboards, DNS and traffic analysis, browser telemetry, OAuth audits, and amnesty-backed surveys.
  • Govern with a living AI acceptable-use policy, clear risk ownership, and a three-tier block-monitor-approve model.
  • Redirect demand into an approved AI tool catalog and governed platforms such as Informat, backed by a ten-day fast-track approval lane.
  • Educate relentlessly, since a third of shadow AI users have never received any training.

Above all, remember what the shadow represents. Employees are not sabotaging the enterprise; they are showing it, workflow by workflow, exactly where AI creates value. Shadow AI governance done well converts that hidden experimentation into sanctioned capability — and turns the enterprise's biggest blind spot into its clearest map of what to build next.

Start building

Ready to build your enterprise system?

Use AI to design, generate, and operate the system your team actually needs.