The ungoverned agent surface
Shadow AI is employees using unsanctioned AI tools: a documented enterprise data-exfiltration path and the reason the governance control plane (see Security · Governance) exists. Adoption outruns policy: the concept now has a measured breach premium.
Nearly half of workers admit to using AI tools without employer approval: shadow AI is now the majority-adjacent norm, not an edge case.
78% of AI users bring their own AI tools to work (BYOAI): employees adopt faster than IT can sanction, so governance is always chasing.
A third of employees admit pasting enterprise research or datasets into AI systems outside company oversight: the primary data-exfiltration path of shadow AI.
27% have entered employee data (salary, performance records) into unsanctioned AI: a direct HR-privacy and regulatory exposure.
23% have input company financial information into unsanctioned AI tools: material non-public data leaving the perimeter with no audit trail.
Organisations with high levels of shadow AI paid $670,000 more per breach on average. The concept has a measured price.
98% of organisations have employees using unsanctioned apps including shadow AI, yet a small minority have enforceable AI-use policies: the gap governance tooling (see Security · Governance) exists to close.
| metric | stat | finding | category | src |
|---|---|---|---|---|
| Unsanctioned adoption | ~49% | Nearly half of workers admit to using AI tools without employer approval: shadow AI is now the majority-adjacent norm, not an edge case. | Adoption | ↗ T2 |
| Bring-your-own-AI | 78% | 78% of AI users bring their own AI tools to work (BYOAI): employees adopt faster than IT can sanction, so governance is always chasing. | Adoption | ↗ T1 |
| Enterprise data shared | 33% | A third of employees admit pasting enterprise research or datasets into AI systems outside company oversight: the primary data-exfiltration path of shadow AI. | Data leakage | ↗ T2 |
| Employee data shared | 27% | 27% have entered employee data (salary, performance records) into unsanctioned AI: a direct HR-privacy and regulatory exposure. | Data leakage | ↗ T2 |
| Financials shared | 23% | 23% have input company financial information into unsanctioned AI tools: material non-public data leaving the perimeter with no audit trail. | Data leakage | ↗ T2 |
| Added breach cost | +$670K | Organisations with high levels of shadow AI paid $670,000 more per breach on average. The concept has a measured price. | Cost | ↗ T1 |
| Governance gap | 98% vs few | 98% of organisations have employees using unsanctioned apps including shadow AI, yet a small minority have enforceable AI-use policies: the gap governance tooling (see Security · Governance) exists to close. | Governance | ↗ T2 |
Staff using AI the business has not approved, and cannot see
Shadow AI is staff using AI tools the business has not approved and cannot see. The behaviour is not new. Pasting a contract into a free grammar checker to tidy it up is the same act, handing company information to a third party nobody registered, and a third of employees say they have put enterprise research or datasets into AI systems outside company oversight.
Show more
What has changed is surface area. Agents widen it further, and visibility is the hard part: where the data went, how it was used, what scopes an API key carried, what was exchanged outside sanctioned systems. Those are the questions IT cannot answer. The tension underneath is genuine, because a business that wants to move fast on agentic capability also has to keep its information out of third-party systems, and the two pull against each other.
Enterprises with locked-down devices can route people to a sanctioned copilot and close most of the gap. The sharper exposure sits with mid-sized businesses, which have more flexibility, want the AI-native upside, and are often willing to carry the risk to get it.
What is shadow AI?
Employees using AI tools the organisation has not approved. It is shadow IT with a new surface: pasting company data into a public chatbot, or pointing an unsanctioned agent at internal systems. It matters because the data and the actions sit outside every control security has put in place.
Why is shadow AI a security risk?
The data leaves your perimeter the moment it is pasted in, and after that you have no say in how it is stored, logged or reused. There is usually no data-processing agreement and no audit trail. Agents raise the stakes further, because an unsanctioned agent does not just read data, it acts on systems.
How common is shadow AI at work?
Common enough to be closer to the norm than the exception. CIO puts unsanctioned AI use at nearly half of workers, Microsoft and LinkedIn put employees bringing their own AI tools to work at 78%, and Reco reports 98% of organisations have staff using unsanctioned apps. The figures vary this widely because the studies count different things: workers in one, organisations in another. Each finding below carries its own source and basis rather than being blended into one number.
Should companies ban AI tools?
Bans rarely hold, because the demand behind the behaviour is real and people route around policy. What works better is making the approved path the easier one: sanctioned tools that actually do the job, routed through a gateway that logs use and enforces what data can leave. Visibility beats prohibition.
How do you find out which AI tools employees are using?
Network and SaaS discovery tools will show traffic to known AI services, and an AI gateway makes sanctioned use visible by design. Neither catches everything, particularly use on personal devices. The practical move is to pair discovery with a good approved alternative, so that use surfaces rather than hides.