Skip to content

Shadow AI Is a Workaround. Your Software Is the Reason.

Abstract diagram: a gold staircase of three steps climbs inside a bounded rectangle, then a red dashed path breaks through a gap in the wall to a node outside it

The first thing most leaders do when they find shadow AI is go looking for who did it.

I understand the instinct. Somebody put company data somewhere it shouldn't have gone. That feels like a discipline problem, and discipline problems have a familiar shape. You write a policy, you send the email, you block the domain, you move on.

Then you look at who's actually doing it and the story falls apart. In a 2025 Cybernews survey of more than 1,000 US employees, 93% of executives and senior managers said they use AI tools their company hasn't approved. Among employees who admitted feeding sensitive information into those tools, 57% said their manager knew and was supportive.

That's not a rogue-employee problem. That's an organization telling you something.

What Is Shadow AI, Exactly?

Shadow AI is the use of AI tools, models, or AI features buried inside other software, without the approval or the visibility of the people responsible for your company's data. Verizon's 2026 Data Breach Investigations Report found 45% of employees were regular AI users on corporate devices, up from 15% a year earlier, and 67% of them worked through non-corporate accounts.

Worth clearing up one thing, because it comes up in nearly every conversation we have about this. ChatGPT is not shadow AI. ChatGPT running on a company account under a commercial agreement is a sanctioned tool. The same product on somebody's personal login, pointed at your customer list, is shadow AI. What makes it shadow isn't the brand on the tool. It's the account and the data path.

The category is also wider than most people picture. It isn't only the chatbot tab. It's the AI features quietly switched on inside software you already pay for. It's browser extensions nobody vetted. It's the automation somebody wired up between two systems over a weekend because it finally became possible to do that without an engineer.

Your Team Isn't Being Reckless

People don't reach for unapproved AI to break the rules. They reach for it because the approved path doesn't reach the work. In that same Cybernews survey, 52% of employees said their employer provides approved AI tools, but only 33% said those tools fully meet their needs.

Sit with that gap for a second. It isn't a gap between having tools and not having them. It's a gap between having tools and having tools that work. Fifty-nine percent of employees use unapproved AI anyway, which is more than the number who say they were given anything in the first place.

The gap between provided and adequate, 2025 Provided is not the same as adequate Share of employees, 2025 52% Employer provides approved AI tools 33% Those tools fully meet their needs 59% Use unapproved AI tools anyway Source: Cybernews survey of 1,000+ US employees, via Journal of Accountancy, November 2025

The support numbers point the same direction. Lenovo's Work Reborn research, which surveyed 6,000 full-time employees, found 31% of AI users get no training from their employer at all and 22% say their employer provides no AI tools.

The most recent numbers say the same thing at a larger scale. Deloitte's GenAI Workforce Survey, published in September 2026, asked 25,000 UK workers about this and found 31% of GenAI users are working without their employer knowing, and roughly half have had no formal training on using it safely. The detail worth sitting with is what came next: 17% are paying for at least one AI tool with their own money, which Deloitte puts at £958 million a year across the UK workforce.

Read that number again. People are spending their own salaries on software that does the job their company's software won't. That is not recklessness. That is someone deciding the work matters more than the expense report.

So the average person in your company has been handed a tool that doesn't quite do the job, no instruction on how to use it, and a deadline. What did we expect to happen?

The Workaround Ladder

Shadow AI is the fourth rung on a ladder your company has been climbing for twenty years. Every rung is the same instinct: the system won't do the thing, so the person does the thing anyway.

We've watched all four get built. The first is the sticky note on the monitor with the eleven steps nobody could remember. The second is the spreadsheet that reconciles the ERP against the field app, because the two were never going to talk and somebody had to close the month. The third is the Access database, or the Airtable base, that one person built without asking and now three departments depend on. Nobody documented it. Everyone uses it.

The fourth is a personal AI account pointed at a system export.

The workaround ladder The workaround ladder Same instinct at every rung. Only one of them leaves the building. The sticky note with the eleven steps The spreadsheet that reconciles two systems The database nobody documented DATA LEAVES THE BUILDING Shadow AI A personal account, pointed at a system export

Here's the line I'd underline for anyone who runs one of these companies. Every rung before this one kept the data inside the building.

Does that distinction sound academic? It isn't. A shadow spreadsheet is a mess, but it's your mess. It sits on a shared drive where an auditor eventually trips over it. The Access database is fragile and undocumented, but it never left. You can find it, read it, and replace it on a Tuesday.

Rung four is different in kind, not just in degree, and for three reasons.

The data actually goes somewhere else. Cyberhaven Labs tracked 39.7% of data movements into AI tools carrying sensitive information in 2026, with source code the single most common category. The average employee puts sensitive data into an AI tool roughly once every three days.

There's also no artifact left behind. Shadow AI is now the third most common non-malicious insider action in Verizon's data loss prevention dataset, up fourfold in a year across 858,440 events. A prompt typed into a personal account leaves nothing on your side of the wall to find later.

And the terms aren't the ones your legal team assumes. Consumer AI tiers handle retention and model training differently from commercial agreements. The account somebody signed up for on their own doesn't carry the protections in your vendor contracts. That's the same argument I made about extending the systems you already own, and it holds here.

This is the newest line item on the workaround tax. It's also the most expensive one, and the first one you can't see.

What Does Shadow AI Actually Cost?

IBM's Cost of a Data Breach report found shadow AI in 43% of breached organizations in 2026, more than double the 20% recorded a year earlier, and those breaches averaged $5.39 million against a global average of $4.99 million. Compared specifically against breaches involving sanctioned AI, shadow AI incidents ran about $670,000 higher.

Average breach cost by type, 2026 What a breach costs, by what was involved Global average cost per incident, 2026 Global average $4.99M Shadow AI involved $5.39M AI-enabled attack $6.00M Source: IBM, Cost of a Data Breach Report 2026

For anyone operating in insurance, healthcare services, or financial services, there's a number in that report that matters more than the averages. About one in five shadow AI incidents resulted in a regulatory fine.

The governance picture is moving the wrong way, which is the part I find genuinely surprising. Sixty-eight percent of organizations had no AI governance policy in place in 2026. Thirty-five percent had nothing at all, and another 33% had something in development. Among organizations that suffered an AI-related security incident, 92% lacked proper access controls on their AI systems.

I want to be precise about what this means for a company your size, because a $5 million average is easy to dismiss when you're a $150 million distributor. The number that should land isn't the headline. It's the direction. This cost is already being incurred at your company right now. It just isn't showing up on a budget line, because it's sitting on the risk register instead. Nobody has approved anything to fix it, because nobody has priced it.

Why Buying a Sanctioned Chatbot Doesn't Fix It

Every guide on the first page of Google ends at the same recommendation: give people an approved, enterprise-grade AI tool and the shadow usage goes away. That advice is necessary and it isn't sufficient, and the reason matters.

An enterprise subscription changes where the conversation happens. It doesn't change what your underlying systems can do.

Say your controller went to a personal ChatGPT account because the ERP won't produce a margin report broken out by branch. Now you buy the governed version and roll it out. That governed chatbot has exactly the same lack of access to the ERP that the personal one had. It produces the same nothing. So the controller does what she did before. She exports to Excel, and now she's pasting into a tool you're paying for, which feels better and solves nothing.

The sanctioned tool just becomes rung five.

It's the same failure we keep seeing across AI programs generally. MIT's NANDA initiative found roughly 95% of generative AI pilots produced no measurable P&L impact after $30 to $40 billion in enterprise spend, and the pattern behind the handful that worked was integration into a specific workflow rather than better technology. Buying access to a model isn't the same as connecting it to your business.

The fix isn't a tool. It's access. Your systems need to be reachable by something other than a person with a login.

Read the Prompt Log as a Requirements Document

Here's the reframe that changes what you do on Monday. The inventory of shadow AI use inside your company is the most honest requirements document you will ever get, and it cost you nothing to produce.

Every security vendor treats that inventory as an incident report. It's a list of violations, ranked by risk, to be remediated. Read it the other way. It's a backlog your people wrote for free, and it comes with evidence no product manager ever gets.

Each entry tells you four things at once:

  • Who wanted it. A named person in a real role, not a persona in a workshop.
  • How badly. They took a personal risk to get it. That's a stronger demand signal than any survey.
  • How often. The cadence shows up in the pattern. Weekly beats hypothetical.
  • What the system failed to do. The prompt itself is the specification.

That last one does most of the work. Read the prompts as feature requests and the translation is usually direct.

What the prompt saysWhat it means your system can't do
"Summarize these 40 service tickets by root cause"Your ticketing system has no categorization your team trusts
"Compare this quote to our last three for the same customer"Quote history isn't reachable at the moment of quoting
"Rewrite this into a customer-facing update"Your system produces internal records, not communications
"Which of these invoices look wrong?"Nobody built the exception report

None of those are AI problems. They're reporting gaps, access gaps, and process gaps wearing an AI costume.

So run the diagnostic. Four questions, and you can get through them in a week without hiring anyone:

  1. What are people actually asking AI to do with our data?
  2. Which system should have done that, and why couldn't it?
  3. Is this a reporting gap, an access gap, or a process gap?
  4. What would it take to make the sanctioned path faster than the workaround?

That fourth question is the whole game. If the compliant path is slower than the workaround, the workaround wins. Every time. Policy doesn't change that arithmetic and neither does training. The only thing that changes it is making the right way the fast way.

This is the same method we run at the start of an engagement, just seeded with observed behavior instead of a whiteboard. It's cheaper, and honestly it's better, because nobody is performing for the room.

What to Do in the Next 90 Days

Three moves, and the order matters more than the speed.

Weeks 1 to 2. See it. Not with a procurement cycle. Just ask. The survey data says managers already know in most cases, so a direct, non-punitive question surfaces more in an afternoon than a tool will in a quarter. Make it explicit that nobody is in trouble, and mean it, because the moment this feels like an investigation people stop telling you the truth. Pair it with whatever visibility your existing stack already gives you.

Weeks 3 to 8. Make the top three legitimate. Not all of it. The three highest-frequency workarounds. Give those a sanctioned path that is genuinely faster than the shadow one. In practice that usually means extending a system so it can answer the question directly, not buying a subscription and hoping.

Weeks 9 to 12. Decide what to build. The workarounds that remain are your roadmap input. Some are process fixes you can make next month. Some are integration work. A few are the business case for something real, and now you have evidence instead of an opinion. If the diagnostic keeps pointing at the same aging system, that's worth reading as a modernization question rather than an AI question, and the technical debt underneath it is probably the real bill.

One thing I'd avoid. Don't ban it without providing something faster. A ban with no alternative doesn't remove the behavior. It moves it to personal phones, where you have no visibility at all, and then you've made the problem invisible and called it solved.

If you want a structured version of this, our modernization assessment walks the same diagnostic across your core systems. But you don't need us to run the four questions. Run them yourself first.

Frequently Asked Questions

Is ChatGPT shadow AI?

Not on its own. ChatGPT accessed through a company account under a commercial agreement is a sanctioned tool. The same product on a personal login, pointed at company data, is shadow AI. The account tier and the data path decide it, not the brand of the tool.

What are the risks of shadow AI?

IBM puts shadow AI in 43% of breached organizations in 2026 at an average cost of $5.39 million, with roughly one in five of those incidents drawing a regulatory fine. The underrated risks are the quiet ones: no audit trail, and consumer terms that differ from your commercial contracts.

How do you prevent shadow AI?

You reduce it by making the sanctioned path faster than the workaround. Policy and domain blocking without that step relocate the behavior rather than removing it, usually onto personal devices. As of 2026, IBM found 68% of organizations still had no AI governance policy at all.

How is shadow AI different from shadow IT?

Same instinct, different blast radius. Shadow IT left an artifact inside the company, like a spreadsheet or a database you could eventually find and replace. Shadow AI moves data out through a personal account and leaves nothing behind on your side to discover.

The Bottom Line

  • Shadow AI is a workaround, and workarounds are information. People route around software that can't do what the job requires.
  • It's the fourth rung on a familiar ladder, and the first one where your data leaves the building.
  • A sanctioned chatbot changes where the conversation happens. Extending the systems people are working around changes whether they need to.
  • The shadow AI inventory in your company is a requirements document your people already wrote. Read it that way.

The uncomfortable version of all this is that your team has already told you what your software can't do. They told you by going around it, at some personal risk, repeatedly, for months.

The only question left is whether you treat that as a violation or as information. One of those gets you a policy nobody reads. The other gets you a roadmap.

If you're staring at a list of workarounds and trying to work out which ones are worth building, that's a conversation worth having before you commit a budget to it.