What Is Shadow AI? The Risks, Why Bans Fail and What to Do Instead
Shadow AI is any use of AI at work that the company has not approved and cannot see. A client email pasted into a personal ChatGPT account. Management accounts uploaded to a free tool for a quick summary. A sales rep’s own Claude wired into the company inbox with his own password. None of it is malicious. It happens because the approved route is slower, or does not exist.
The fix is rarely a ban. It is a sanctioned route that is easier than the workaround. This guide covers what shadow AI is, why it happens, what it actually risks, and five steps to bring it into the open.
What shadow AI is
Shadow AI is the use of AI tools, accounts or connections for work that the company has not approved and does not know about. The tool itself is usually fine. Companies use Claude, ChatGPT and Copilot safely every day. What makes it shadow is the setup: a personal account instead of a business one, a connection into company systems that nobody signed off, and data going to a provider the company has no agreement with.
It is also bigger than most leaders assume. In Microsoft and LinkedIn’s 2024 Work Trend Index, 75% of knowledge workers used AI at work, and 78% of those users brought their own tools rather than ones their employer provided. At small and medium-sized companies the figure was 80%. In the UK, a Microsoft survey of 2,003 employees in October 2025 found that 71% had used unapproved consumer AI tools at work, and 51% still did so every week.
Shadow AI examples
Most of it looks ordinary, which is why nobody flags it. Four typical patterns, written as examples rather than real cases:
The client email. Say an account manager has a tricky reply to write. She pastes the whole thread, names and contract terms included, into a chatbot on her personal account.
The personal connector. A sales rep connects his own assistant to the CRM and his inbox so it can prepare his meetings. It works brilliantly. Nobody else knows it exists, and when he leaves, nobody knows to switch it off.
The meeting bot. Someone signs up for an AI note-taker with their work email. It joins every meeting in their calendar, client calls included, and stores the recordings with a provider nobody has assessed.
The private prompt library. The best proposal writer in the company has a set of prompts that turn rough notes into a strong first draft. They live in her personal account. Everyone else writes proposals the slow way.
Shadow AI vs shadow IT
Shadow IT is the older idea: software used for work without IT’s approval, like a personal Dropbox for work files. Shadow AI is a kind of shadow IT, but it behaves differently in ways that change how you deal with it.
| Shadow IT | Shadow AI | |
|---|---|---|
| What goes in | Files people choose to store | Whatever people paste or connect: emails, contracts, customer records, HR notes |
| How fast it spreads | A team adopts a tool over months | One person starts in a minute, on a phone, with nothing to install |
| What it can do | Store and share | Read, summarise, draft and, once connected, act in your systems |
| How you spot it | Licences, expense claims, network traffic | Much of it runs in a browser or on a personal phone, so the usual signals miss it |
The last row is the one that matters. Shadow IT could often be found and switched off. Shadow AI mostly cannot, which is why the answer is a better route rather than a better search.
Why shadow AI happens
People are not being reckless. They have found something that saves them an hour a day, and the company has not given them an approved way to do it. In Microsoft’s UK survey, 41% said they used consumer AI tools because that is what they use in their personal life, and 28% said their employer did not provide an approved option.
So everyone builds their own setup. Their own accounts. Their own connections into email, the CRM and the shared drive, one at a time. Their own prompts. Multiply that by fifty people and you get the picture on our home page: every tool wired to every system, one person at a time, and nobody can see any of it.
The most careful people, meanwhile, often do nothing at all. They are not sure what is allowed, so they stay away.
The real risks of shadow AI
Shadow AI risks are less dramatic than the headlines and more practical. For a company of 20 to 200 people, four matter most.
Customer and personal data in tools you have no agreement with. A client’s details pasted into a personal account now sit with a provider your company has no contract with, on terms written for consumers. Under GDPR, and UK GDPR, your company stays responsible for the personal data it handles. In the University of Melbourne and KPMG’s 2025 global study of more than 48,000 people, 48% of employees said they had uploaded sensitive company or customer information into public AI tools.
No log of who asked what. If a client asks what happened to their data, there is no record to answer from. In IBM’s 2026 Cost of a Data Breach study, shadow AI played a part at 43% of the breached organisations studied, up from 20% the year before.
Knowledge that leaves with the person. The prompts, connections and clever workflows live in personal accounts. When that person leaves, all of it goes with them.
Uneven quality. Ten people with ten tools and ten private prompts produce ten standards of work. Clients notice when one proposal is sharp and the next reads like a first draft.
This is a practical overview, not legal advice. If personal data may already have gone into unapproved tools, or you are unsure what your obligations are, check with your data protection officer or legal adviser.
Why banning AI does not work
The reflex is to ban it, and it has been tried. In 2023 Samsung banned generative AI tools on company computers, phones and networks after engineers uploaded internal source code to ChatGPT. More than one in four organisations in Cisco’s 2024 Data Privacy Benchmark had banned generative AI, at least for a while.
But the work does not go away, and neither does the phone in everyone’s pocket. In Salesforce’s survey of more than 14,000 workers, 40% of people using generative AI at work had used tools their employer had banned. A ban does not remove the use. It removes your view of it.
| A ban | A sanctioned route | |
|---|---|---|
| What people do | Move to their phone or personal laptop | Use the approved tool, because it is easier |
| What you can see | Nothing | Who uses what, and every call into company systems |
| Customer data | Goes to providers you have no agreement with | Stays with providers you have an agreement with |
| When someone leaves | Their setup leaves with them | Access is removed in one place, and the shared prompts stay |
| The careful half of the team | Stays away from AI | Gets a clear yes |
How to find shadow AI without hunting for it
Shadow AI detection tools exist. They watch network traffic, browser extensions or expense claims for AI services. For a large enterprise with a security team they can be worth it. For a company of fifty they mostly find what happens on company laptops and miss the phone.
The faster way is to ask, and to make it safe to answer. Tell the team you are not looking for culprits: you want to know what helps, so you can make it official. Then send five questions, anonymously if that gets more honest answers:
People enjoy answering the fifth question. It is also where your first company skills will come from.
What to do instead: five steps
None of this needs a big project. The goal is one sanctioned route that is easier than the workaround.
- Find out what is used today. Ask, do not hunt. The five questions above take a week to collect.
- Pick the approved tools. One or two assistants on business plans whose data terms you have read. If people already love a tool, start there: the closer the approved route is to what they use now, the faster the shadow version disappears.
- Give people a sanctioned way into company systems. Each person signs in with their own login, access follows their role, and every call is logged. That is what an MCP gateway does, and our MCP connector pages show it system by system.
- Write a one-page AI policy. Approved tools, what data never goes in, and who to ask when unsure. The governance minimum is in our AI strategy guide.
- Share the good prompts as company skills. Turn the best answers to question five into skills everyone can use, so the private prompt library becomes the company’s. Work that repeats every week can then become an AI agent.
Order matters. A policy without an approved tool is a ban with extra steps. An approved tool that cannot reach your systems sends people back to copy and paste, and soon back to their own setup.
Where Deployed OS fits
Step three is the one we build. Deployed OS is the company’s own MCP layer between the assistants your people already use and the systems they work in. It works in Claude, ChatGPT and Copilot. Each person signs in with their own login. Admins decide which groups may read or write in which system. Every call is logged and can be exported. Company skills and guardrails are shared, so everyone works from the same instructions.
Deployed is an EU company, fully GDPR compliant, and you choose where your data is stored. The private connections become one route the company can see, and the shadow version stops being the easy option.
Frequently asked questions
What is shadow AI?
Shadow AI is the use of AI tools, accounts or connections at work that the company has not approved and cannot see. Typical examples are an employee pasting a client email into a personal ChatGPT account, uploading company figures to a free AI tool, or connecting their own assistant to the company inbox or CRM. The tools are often fine in themselves. What makes it shadow AI is that the company has no agreement with the provider, no record of what was shared and no say in how it is set up.
What is the difference between shadow AI and shadow IT?
Shadow IT is any software or service used for work without IT’s approval, such as a personal file-sharing account. Shadow AI is a kind of shadow IT with three differences: people put far more sensitive material into AI tools (emails, contracts, customer records), one person can start using a tool in a minute on a phone, and a connected AI tool can act in company systems rather than just store files. It is also harder to detect, because much of it runs in a browser or on personal devices.
What are the risks of shadow AI?
The main risks are customer or personal data ending up with AI providers the company has no agreement with, which can be a data protection problem under GDPR; no log of who asked what or what an AI tool accessed; knowledge, prompts and connections that leave when the person leaves; and uneven quality when everyone uses different tools and private prompts. If personal data may already have gone into unapproved tools, check with your data protection officer.
How do you detect shadow AI?
Monitoring tools can spot AI services in network traffic, browser extensions or expense claims, but they miss use on personal phones and laptops. For most companies of 20 to 200 people, the fastest way to find shadow AI is to ask: a short, anonymous survey on which tools people use, on which accounts, for what, whether they have connected anything to company systems, and which prompts save them the most time. Make it clear you are looking for what to make official, not for culprits.
Should companies ban ChatGPT and other AI tools?
A ban rarely stops the use. It moves it to personal phones and accounts where the company sees nothing. In a Salesforce survey of more than 14,000 workers, 40% of those using generative AI at work had used tools their employer had banned. A better approach is to approve one or two tools on business plans, give people a sanctioned way to connect them to company systems with their own login and a log, and write a one-page policy on what data never goes in.
How do you stop shadow AI?
Make the approved route easier than the workaround. Find out what people use today by asking, pick approved tools on business plans, give people a sanctioned way to connect AI to company systems with their own login and logging, write a one-page AI policy, and share the best prompts as company skills. When the official setup is better than the personal one, people have a reason to move over.
Found this useful? Send it to someone who needs it.