A colleague in accounts has a list of two hundred clients in front of her and needs to pull out the ones more than three months overdue. Doing it by hand would eat her afternoon. So she pastes it into ChatGPT and twenty seconds later it's done. She did good work, quickly, and told nobody — it didn't occur to her that she should.
That moment now happens in companies every single day. And it has a name: shadow AI — the use of AI tools a company doesn't know about and doesn't govern. According to data published this summer, it's also the most expensive security problem most companies refuse to admit they have.
What this year's data shows
The hardest numbers come from the IBM Cost of a Data Breach Report 2026, conducted by the Ponemon Institute across 602 organisations that suffered a real data breach between March 2025 and February 2026. The findings are uncomfortably specific:
Shadow AI was present in 43% of breaches — more than double the previous year's 20%. And in companies with high levels of ungoverned AI use, the average breach cost $670,000 more than where it was under control.
Other surveys fill in the scale: employees use unsanctioned AI tools in virtually every organisation, and roughly two thirds of office professionals admit reaching for a tool they believed company policy didn't allow. Not out of defiance. Because it saved them time.
And now the paradox
This is where the study turns into something I didn't expect. Companies responded to the growing risk by putting less control in place, not more.
The share of breached companies with no AI governance at all rose from 63% to 68%. And the share that require IT approval before an AI tool is deployed fell from 45% to 38%. Only 19% of organisations say their security and AI teams coordinate at all.
I could turn that into a "bans don't work" headline, but it would be imprecise — the study doesn't prove one causes the other. What does follow reliably, and what I see constantly in practice, is something else: companies have rules but no visibility. There's a policy someone circulated by e-mail once, and beside it a reality nobody measures.
Why a ban alone doesn't hold
When a company bans AI and offers no alternative, it puts employees in front of a choice: work slower, or work around the rule. Most people choose the work — especially with a deadline and nobody watching.
I understand the other side of it too. A ban is the fastest option for management because it requires no decision about tools, budget or training. You write "don't use this" and the responsibility shifts to the employee. But the risk doesn't go anywhere — it just stops being visible.
The second problem is that a blanket ban throws away the benefit as well. That colleague has a genuine need AI handles well. A ban doesn't remove it — it just guarantees the solution happens outside company oversight.
What it means legally
This is where it shifts from "security risk" to "legal liability", in two layers.
GDPR. When an employee pastes client personal data into a public AI tool, the company is liable as the data controller — regardless of not knowing. In fact, the absence of any governance or records is an aggravating factor in an audit, not a mitigating one. The argument "we banned it" carries little weight without evidence the company actually checked.
The AI Act. Oversight of the AI literacy obligation started this August — meaning companies must ensure people working with AI understand what it does and where its limits are. If employees use AI management knows nothing about, the company cannot meet that obligation even in theory. I covered the wider framework in my piece on the AI Act in 2026.
In one sentence: the company deploying AI is always answerable for its output — and with shadow AI it turns out it was "deployed" by someone with no authority to make that call.
What to do — in order of sequence, not importance
1. First find out what's actually happening. Not through a policy, through a conversation. Ask people what slows them down and whether they're already helping themselves somehow. The crucial part is that admitting it carries no consequences — if people are afraid, you'll learn precisely nothing. In the companies where I've done this, it nearly always turned out two or three people were already using AI and nobody knew.
2. Draw the line around data, not tools. Banning "ChatGPT" makes no sense — stating what must never go into any external tool does. Typically: client personal data, contract contents, payroll and health records, credentials, non-public financials. That's a sentence an employee will remember. Nobody remembers a list of approved tools.
3. Give people a legitimate path. This is the whole heart of it. Until they have something to replace what saves them time, they'll keep doing it off the books. That path might be a paid business tier where inputs aren't used for training, or an internal knowledge system over your own documents, where data never leaves the company at all. In sensitive sectors, a model running on your own server is worth the cost.
4. Keep a record of who uses AI and for what. This needn't mean monitoring — it's enough that every new tool is known about and signed off by someone. That record doubles as the documentation you'll need when somebody asks.
5. Train the staff, not just the managers. Not on "how AI works", but on what specifically must not leave the company, and why. Half an hour of plain explanation achieves more than a ten-page policy nobody finishes.
What not to do
Don't turn it into an investigation. The moment you start hunting for "who broke the rule", people close up and you lose visibility permanently. The goal isn't to find a culprit — the colleague in the opening had no offence in mind. The goal is to move that activity out of the grey zone and into the light.
Don't buy a "shadow AI detection" tool as step one. A market is already forming around this topic that will sell you software before you've even worked out what data you're protecting. A conversation with five people costs you an afternoon and tells you more.
Don't pretend it isn't happening. If anyone in your company works with text, spreadsheets or e-mail and you haven't given them a working alternative, the odds are high. The data is unambiguous: this isn't just a large-corporate phenomenon.
An honest conclusion
Shadow AI is an unusual kind of problem because it doesn't stem from negligence or bad intent. It stems from employees adopting new tools faster than companies can govern them. That isn't a failure of people — it's normal, and it was predictable.
The only unpleasant part is how expensive that gap can get. The good news is that it closes surprisingly cheaply: a conversation, one clear sentence about data, and one working alternative. None of those three requires a software budget.
If you take one idea from this article, let it be this: people will always find a route to faster work. The only thing you decide is whether it runs through your company or around it.
Frequently asked questions about shadow AI
As part of an AI audit I'll go through your processes and tell you where data moves, where the risk is and what to replace it with — concretely and without scare tactics.
Book a free 30-minute callI build AI solutions for businesses — from chatbots to knowledge systems. I write about what actually works, no buzzwords. More about me →