Security · Governance

Shadow AI Is Already
in Your Building

m2m2-consultingAugust 20267 min read
employeepersonal AIunsanctionedno policyrisk

The scale, measured

Shadow AI is the use of AI tools that the organisation has not sanctioned, cannot see, and does not govern. It is the direct descendant of shadow IT, and it has spread faster than any technology category before it — because the barrier to entry is a browser tab.

Microsoft and LinkedIn's 2024 Work Trend Index, drawn from 31,000 knowledge workers across 31 markets, found that 78% of AI users bring their own AI tools to work — and that 52% of people using AI for their most important tasks are reluctant to admit it [1]. A separate study of 6,000 knowledge workers put the share using unapproved "shadow AI" at 50%, with 46% saying they would keep using it even if their employer banned it outright [2].

The evidence

78% of AI users bring their own AI tools to work; 52% won't admit using AI for their most important work (Microsoft / LinkedIn, 31,000 workers) [1].

Leaders estimate 4% of employees use gen-AI for a meaningful share of daily work; employees report the true figure is roughly three times higher (McKinsey) [3].

Only 31% of organisations have a formal, comprehensive AI policy (ISACA, 3,200+ professionals) [4].

The perception gap is the real risk

The most instructive finding is not the raw adoption number — it is the distance between perception and reality. McKinsey's 2025 research found that leaders estimate around 4% of employees use generative AI for at least a third of their daily work, while employees themselves report the real figure is about three times that [3]. Leadership is not looking at a future risk to plan for. It is mis-measuring a present one.

This blind spot has an operational cost. Nearly half of security professionals — 47% in one 2026 survey — say they lack full visibility into which AI tools their employees use [5]. You cannot write a data-protection impact assessment, negotiate a vendor agreement, or answer an auditor's question about a tool you don't know is running.

Shadow AI is not primarily a story about malicious employees. It is a story about a productivity need that outran the organisation's ability to meet it safely — so people met it themselves.

Why banning fails

The instinct to prohibit is understandable and, the evidence suggests, counterproductive. When 46% of shadow-AI users say they would continue regardless of a ban [2], a prohibition does not end the behaviour — it drives it further from view, onto personal devices and personal accounts where the organisation has no telemetry, no data-processing agreement, and no recourse.

The gap that produces shadow AI is a supply gap: employees reach for unapproved tools because the sanctioned toolset does not meet their needs, or does not exist. In the same study, a third of employees said IT simply does not provide the AI tools they need [2]. The durable fix addresses the cause, not the symptom.

From shadow to sanctioned

Forrester and Gartner both now track shadow AI as a distinct risk category; Gartner forecasts that by 2030, more than 40% of organisations will experience a security or compliance incident driven by unauthorised AI use [6]. The organisations that avoid becoming that statistic tend to do four things:

Shadow AI is not a sign that your people are reckless. It is a sign that they are ahead of your governance — which, handled well, is a position of strength. The task is not to catch up by force. It is to give grassroots adoption a safe channel before it becomes the incident nobody saw coming.