- A 2026 PagerDuty survey found 66% of office workers have used AI tools they believed their employer had not approved, and 71% of those admitted feeding in sensitive data such as customer records and internal documents. Verizon's 2026 breach report found shadow-AI detections quadrupled in a year. The tools are already inside your business, whether you sanctioned them or not.
- Banning it does not remove it. A ban pushes the use underground, onto personal devices where you cannot see the risk at all.
- People reach for unofficial AI because the official option is missing or worse. The shadow use is telling you what to fix.
- The fastest response is to make the sanctioned path better than the shadow one, and to govern the data, not the curiosity.
- Leaders set the tone. In the same research, 81% of workers believe leadership plays by different AI rules than everyone else.
You signed the AI policy, and you feel like you have a handle on this. Then you learn what is actually happening on the floor. Most of your team is already using AI tools you never approved, pasting real customer data and draft contracts into them, quietly, because it helps them get the work done. The policy on the shared drive governs a world that no longer exists. The real one is already running on tools you have never seen.
This is not a discipline problem, and treating it as one makes it worse. Your people are not being reckless for the sake of it. They are reaching for the fastest way to do their job, and right now that is often a tool you did not give them. The question is not how to stamp it out. It is what the shadow is telling you, and how to bring it into the light.
How widespread is shadow AI, really?
Widespread enough that it is now the normal case, not the exception. A 2026 survey by PagerDuty, an operations software company, found that 66% of office workers had used AI tools they believed were not permitted by their employer. Of those, 71% admitted feeding in sensitive information: customer details, employee records, internal documents. This is not a fringe of rule-breakers. It is two in three of your people.
The security data confirms it is rising fast. Verizon's 2026 Data Breach Investigations Report, a widely cited annual study, found that detections of shadow AI on corporate systems quadrupled in a year, making it one of the most common insider actions they track. So the picture is not a few curious staff. It is a large, growing share of your workforce moving real data through tools you cannot see. It is a close cousin of the reason so many AI efforts stall on the human reality rather than the technology.
Two in three of your people already use AI you never approved. A ban does not remove it. It just moves it somewhere you can no longer see.
| The shadow AI picture (2026) | Figure |
|---|---|
| Office workers who used AI tools they believed were not permitted (PagerDuty) | 66% |
| Of those, the share who fed in sensitive data | 71% |
| Rise in shadow-AI detections on corporate systems in a year (Verizon DBIR) | quadrupled |
| Workers who believe leaders play by different AI rules | 81% |
Why does banning it make things worse?
Because a ban removes your visibility, not the behaviour. The demand is real: people have work to do and a tool that helps them do it. Tell them no, and the ones who need it most do not stop. They move to a personal phone or a home laptop, where your security team has no view at all. You have not closed the risk. You have blinded yourself to it, and handed the sensitive data an even less controlled route out of the building.
The lower-altitude question here is which tool to block, and how to catch people using it. That is a losing game, and it misreads the situation. The higher question is why your people needed the shadow tool in the first place. Almost always, the answer is that the official option is missing, slow, or worse than what they found themselves. The shadow is free product feedback about where your sanctioned AI falls short, and it is the same instinct behind treating your people's real ways of working as the advantage to build on.
So how should a leader handle shadow AI?
You bring it into the open by making the sanctioned path the better one, and by governing the data rather than policing the curiosity. The aim is visible, supported AI use that you can actually see and steer. Work it in this order:
- Give people approved tools that work. The single best way to shrink shadow use is to make the official option faster and better than the unofficial one.
- Govern the data, not the appetite. Be clear and specific about what information may go into which tools. People follow rules they understand and that do not block the work.
- Read the shadow as feedback. Where people go around you tells you exactly what your sanctioned AI is missing. Fix that, and the shadow shrinks on its own.
- Make the safe path the easy path. If doing it properly is slower than doing it quietly, people will do it quietly. Remove the friction from the sanctioned route.
- Lead by example. When leaders visibly follow the same AI rules they set, the rest of the organisation does too. When they do not, everyone notices.
Bringing your team's real AI use into the open?
The Strategy Session works on the governance side of AI: turning ungoverned shadow use into visible, supported adoption you can see and steer, by making the sanctioned path the one people actually want. We build the approach around how your people really work.
Book your Strategy SessionWhat does this make possible?
A business where AI use is out in the open, not hidden from you. Your people use tools you provided, tools good enough that they have no reason to go elsewhere. The sensitive data stays on paths you can see and control. And the constant signal of where people improvise becomes a map of what to build next, rather than a threat to chase. That is a far stronger position than a policy that looks tidy on paper while the real work happens somewhere you cannot see.
Picture it six months on. The shadow has shrunk, not because you policed it, but because the official tools got good enough to win. You can see how AI is used across the business, govern the data with confidence, and answer a regulator or a customer plainly. You met your people where they already were, and led them somewhere safer. That composure, in a fast-moving field, is exactly what builds the trust others are busy losing.
Frequently asked questions
What is shadow AI?
Should companies ban unauthorised AI tools?
How should leaders manage shadow AI?

About the author
British technology futurist, AI keynote speaker and advisor. Thirty years across enterprise technology and AI strategy, helping leaders navigate the future of work. The futurist who died.