Special Offer

Get 3 months free of PEO*

articleIcon-icon

Article

9 min read

Shadow AI is the new shadow IT, and it's already inside your company

Kaila Caldwell

Author

Kaila Caldwell

Published

September 09, 2026

shadow ai workplace

66% of office professionals have used an AI tool at work despite believing it wasn't permitted, and 88% have shared work data with a public AI tool, according to PagerDuty's 2026 Shadow AI Survey of 1,250 professionals at companies with more than $500 million in revenue.

Employer-managed AI account use climbed to 62% of all AI users over the past year, as more companies rolled out sanctioned tools of their own, according to Netskope's 2026 Cloud and Threat Report.

Even so, 88% of employees with an employer-provided AI tool are also using a personal one for work, according to Gartner's Q1 2026 Global Labor Market Survey of 12,004 employees and managers across 40 countries. This is shadow AI, the newest version of shadow IT: unsanctioned tools employees adopt on their own, even when an approved one already exists.

Verizon's 2026 Data Breach Investigations Report measured personal-account AI access directly from network traffic, rather than self-reported survey data: 67% of AI users access it through personal, unsanctioned accounts on their corporate devices.

Shadow AI has a price. Breaches at organizations with heavy shadow AI use cost $670,000 more, on average, than breaches at organizations with little or none, according to IBM's 2025 Cost of a Data Breach Report. In 97% of the incidents where shadow AI was involved, the company had no AI access controls in place beforehand.

Employees are choosing personal AI tools because they're faster, less restricted, or simply better than what's officially provided. Banning those tools outright doesn't remove that choice, it just hides it from the people meant to manage it.

Why employees are still using personal accounts

Ryan Michaels, an independent biotech researcher at Pepthrive, had no enterprise AI tool at all. "I don't have an AI-powered enterprise tool behind me when I boot up my laptop," he says. So he subscribed to Claude personally, and it stuck. "What used to take the better part of a morning is now a matter of moments," he says. His manager noticed the change in his output within two months but never asked how. When the AI use came up organically in a later conversation, Michaels didn't shy away from it.

Loc Dang, digital marketing specialist at Cricket One, had a company tool, just not a reliable one. "I started using a personal account because our company did not have an AI tool that was consistently available, and when options were discussed internally, they were usually more limited than what I was already using on my own," he says. "The biggest gap was not intelligence, it was friction. If a tool is slower, heavily filtered, or not good with longer prompts, I stop using it."

Using his personal AI accounts, Dang estimates he has cut 30 to 40% off his research and drafting time, and his manager has noticed the output quality improve and turnaround get faster. He's mentioned using AI "in general," but not every workflow detail. "For most employees, this is not about trying to break policy," he says. "It is about removing delays. When the official tool creates more friction than the work itself, people route around it."

Aditya Gaur uses AI for work on client websites, but he stopped relying on his company's tool after repeated problems. "It started to hallucinate a lot more with each model upgrade," he says. "It even broke the whole site code for one of our key clients once." He switched to personal Gemini and Claude subscriptions instead. His employer built a formal approval process for this within weeks of an earlier incident. It's run for the past 18 months, requiring sign-off from his manager, an HR-approved form, and routine IT checks.

Given an official tool with real parity, Gaur says the decision would be easy. "I'd switch immediately, no hesitation, that'd be a very quick and clear decision for me," he says. "[Company AI tools] need to be less hallucination-prone LLMs, this is the most important part. It can produce results a bit slowly but should not hallucinate very much."

Ariana Rodriguez's company tool isn't the problem at all. "My employer provides Copilot, and it's perfectly capable," she says. "The difference is that I've spent years building context with my personal AI. Because my AI account and I had thousands of conversations over the years, I no longer have to build the perfect prompt." Rebuilding that history inside Copilot isn't a quality question. "Could I eventually teach Copilot enough about my work style to be effective? Probably," she says. "But rebuilding five years of collaborative history? That's incredibly daunting."

What monitoring doesn't catch

The same Verizon report examined 858,440 data-loss-prevention events targeting generative AI tools. Shadow AI is now the third most common way employees accidentally expose company data, a fourfold increase from the previous year. Source code was the most common category of data submitted to unauthorized AI tools.

Monitoring can lose visibility when employees move onto personal devices, cellular data, personal hotspots or unmanaged accounts, says Rafay Baloch, a white-hat penetration tester and founder of REDSECLABS. He says monitoring can lose visibility when employees move onto personal devices, cellular data, personal hotspots or unmanaged accounts. “When a person leaves the company network and uses [their] phone or a personal hot spot, most CASB and DLP are not effective anymore because most of them are monitoring the managed devices or the network traffic crossing the company boundaries,” Baloch says.

At one mid-sized company, Baloch found another blind spot. The company’s monitoring system caught files uploaded into AI tools but missed information pasted directly into the browser. “Nothing exotic was needed to get past but a different input method,” he says. “It is one of the most common oversights I encounter and is never discovered until somebody goes looking for it.”

At The Critter Depot, a 20-employee online pet retailer, chief engagement officer Jeff Neal moved employees onto a monitored enterprise ChatGPT account after initially allowing company documents to be uploaded into personal accounts. The company can restrict uploads on company computers, but its visibility ends beyond them. “We do not monitor their AI accounts on their personal devices,” Neal says. “So we have no way of knowing if they are uploading sensitive data into their personal accounts on their personal devices.”

Banning AI isn’t the solution

Christian Espinosa, founder and CEO of Blue Goat Cyber, worked with a client that banned ChatGPT across its engineering organization and backed the ban with monitoring. About six weeks later, his team traced AI-generated design documentation to 3 engineers copying and pasting ChatGPT output from a personal Gmail tab. “The ban did not appear to have been effective,” Espinosa says. “It had made it invisible.”

Espinosa estimates roughly 60% of the medical-device companies his firm works with experience some version of unauthorized AI use. “The engineers are not doing it to save money,” he says. “They're doing it because the approved platforms for documentation are just slow as can be, and the submission deadlines are not.”

A 2025 paper in Strategic Change, the first peer-reviewed academic study focused specifically on shadow AI, found restriction alone does not function as a governance strategy and recommended controlled enablement and monitored flexibility instead of prohibition. A separate study of 433 office workers, published in Computers & Security, found clearer security policies reduced employees’ intent to work around them, while policy overload increased employees’ intent to circumvent the rules.

Chris Kirksey, founder and CEO of Direction.com, runs a healthcare SEO agency where every content workflow uses AI while every client also operates under HIPAA. Through a network of healthcare compliance professionals, Kirksey reviewed a regional healthcare organization that banned external AI writing tools across its marketing and communications teams. “They banned the tools on a Tuesday. The following Monday, every member of that team had found a workaround, not because they were careless people, but because the approved internal platform they were handed as a replacement required three additional approval steps for every content piece and ran on a system that crashed regularly under normal load.”

Six months later, a compliance spot check found AI-generated content fingerprints across 34 pieces of published material. “Every single one of them traced back to tools that had been explicitly banned,” Kirksey says.

The approved-tool test

At Parallel Learning, Meryll Dindin manages AI enablement for more than 300 employees as head of technology. Parallel’s security software found more than 40 outside AI services connected to company accounts, including transcription and note-taking tools requesting access to calendars and meetings. “A note-taker on a call is requesting access to exactly the conversations we most need to protect,” Dindin says.

Dindin blocked a few tools with specific security concerns, but he did not try to eliminate outside AI use. “The real exposure was never people using AI,” he says. “It was an ungoverned AI connection reaching company data with permissions nobody scoped.” His goal was to make the approved route more useful rather than more restrictive. “The question was never how to stop people,” he says. “It was how to make the sanctioned path the obvious one.”

Parallel gave employees access to Claude, Gemini, Perplexity, Gamma, Wispr Flow and Granola, and built an internal tool able to work with company data employees could not safely put into a consumer account. “Shadow use does not persist because people are reckless,” Dindin says. “It persists because the approved tool is worse than the twenty-dollar personal subscription. Hand employees a locked-down, cheaper model and call it the sanctioned option, and they keep the personal account.”

Employee behavior changed as Parallel’s approved tools improved. “How do I know it worked? Monitoring plus behavior, not a survey,” Dindin says. “The early Gemini sprawl consolidated onto supported tools as they got better, and the real work moved into the governed ones.”

Kirksey built his agency’s AI setup around a similar requirement. “It had to be faster and easier than whatever my team was already using on their own,” he says. The agency configured tools for its own workflows, put data-handling agreements in place and trained employees on live work before allowing AI use with client accounts. “The honest reason this works is not the policy itself,” Kirksey says. “It is that my team does not need to go around the system because the system is not slower than the alternative.”

The room HR isn't in, but should be

Kirksey reviewed one case involving a project coordinator at a roughly 200-person professional services firm who had been using a personal ChatGPT account to draft client-facing work for nearly four months. “No malicious intent behind it either,” he says. “She had a backlog, her company platform was slow and she found a faster way to get the work done.”

Once the company discovered the use, the response moved quickly. “IT locked her account within 24 hours. Legal drafted client disclosure language by day three. HR was notified on day six, the same day affected clients received the formal notice,” Kirksey says. “At that point the narrative was already written, the legal posture was already locked and HR was handed a finished decision and told to process the paperwork.” Whether the employment decision was right or wrong, he says, “Nobody in that process ever had a real conversation about intent before the legal framing closed the door on it permanently.”

Kirksey says HR should have been investigating the employee’s behavior while IT contained the data exposure and legal handled disclosure. “HR gets called into the room on day one, not day six,” he says. “Was this an employee working around a broken tool or was this deliberate data misuse? Those are two entirely different problems and they need two entirely different responses.”

At Dollar Bureau, founder Firdaus Syazwani oversees hiring and team operations himself. By the time he started setting rules around AI, employees and contractors were already using ChatGPT for research, drafting, document summaries and other everyday work.

“Some team members become noticeably faster at outlining, researching, and repetitive content tasks because they have developed stronger AI workflows,” Syazwani says. Others “may produce comparable work more slowly because they lack access, training, or confidence.”

For HR, unequal AI access and training change what a performance difference can mean. An employee producing work more slowly may need training rather than a lower performance rating. “What looks like a performance difference may partly be a tools-and-training difference,” Syazwani says.

“The more useful question for HR is not simply, ‘Who is using AI?’” Syazwani says. “It is, ‘Which workflows now depend on AI, and what risks or inequalities has that created?’”

“IT can determine whether a tool is technically secure,” Syazwani says, “but HR must help determine how its use changes the employee’s role and how policies will be communicated and enforced consistently.”

Kaila Caldwell

Kaila Caldwell is a freelance journalist contributing to Deel Works, where she reports on workforce trends, management, and the future of talent. Her work combines original reporting, expert interviews, and primary data to produce long-form features for business leaders and decision-makers worldwide.

Before Deel Works, Kaila spent several years as an editor and journalist covering the future of work, AI, workforce transformation, economics, and sustainable finance. She has lived and worked in the US, France, and Tunisia, and is currently based in Washington, D.C.

Connect with her on LinkedIn.