The most serious shadow AI risks at work don’t start with a hooded figure or a zero-day exploit. In 2026, a lot of them start with a helpful employee, a deadline, and a chat box that gives great answers. Nobody meant to leak anything. That’s exactly why these risks are the hardest to see and the easiest to underestimate.
If you’ve ever pasted a work email, a spreadsheet, or a chunk of code into a personal ChatGPT or Gemini tab to “just clean this up,” you have probably done a version of it. Whether it counts as shadow AI depends on what your organisation allows and what was in the text, which is exactly the judgement this post is about. This isn’t a scolding. The tools genuinely help. But if you’re also the person who has to wonder whether any of this is even allowed (a founder, a developer, or the de facto security owner on your team), then shadow AI is your problem twice over: you’re both a user and the one holding the risk. Here’s how to think about it clearly, for yourself and the people you lead.
Defining shadow AI: personal accounts, company data
Shadow AI is the use of AI tools for work without the knowledge, approval, or oversight of whoever is responsible for security. It’s the AI cousin of “shadow IT,” the old problem of employees using unsanctioned apps and cloud accounts.
The shape that shows up most is narrow: a person using their personal AI account to handle company data. Unapproved AI features inside tools you do sanction count too, and the common thread is AI use no one reviewed rather than the account type. A marketer summarizing an internal strategy doc in their own ChatGPT. A developer debugging proprietary code in a free Claude tab. A manager dropping the quarter’s numbers into Gemini to draft a summary. No ticket, no policy, no record.
The important part isn’t the tool. ChatGPT, Gemini, and Claude are all legitimate. The risk is the combination: sensitive work data flowing into an account your organization does not administer. Endpoint and network tooling may still see the traffic, but the conversation itself is somewhere you can’t audit, and can’t wipe.

How work data slips out: one paste into a personal AI account moves it past the company boundary, where it can be retained or used for training and can no longer be audited or wiped.
Shadow AI at work is normal behaviour, not fringe behaviour
The reason shadow AI is such a big deal is boring, and that’s the point: it’s happening at enormous scale, in the open, by well-meaning people. Microsoft’s 2024 Work Trend Index found that 78% of AI users already bring their own tools to work. The direction since then is worth reading carefully, because it has moved: Netskope’s 2026 figures show organisation-managed AI overtaking personal apps, with the personal share falling sharply in several regions. That is progress, not resolution. Personal use is still widespread, and it is now the smaller half of a much larger total.
A few numbers make the scale concrete:
- 47% of employees still use personal generative-AI apps, against 62% who use organisation-managed ones. The two overlap, so read this as how many people reach for a personal account, not as a share of total AI traffic (Netskope, 2026).
- Data uploaded to generative-AI apps rose from 7.7 GB to 8.2 GB per month, quarter over quarter. Netskope does not attach a per-organisation denominator to that figure, so neither does this sentence. What it does give per organisation is smaller than people assume: about 15 generative-AI apps in use, up from 13. The 1,550+ number quoted elsewhere is Netskope’s own catalogue of services it tracks, not anyone’s install list (Netskope, 2025).
- 34.8% of the data employees feed into AI tools is now sensitive, up from 10.7% two years earlier (Cyberhaven, 2025).
- 77% of employees paste data into generative-AI prompts, and 82% of that pasting activity comes from unmanaged accounts. Note the units: the first is a share of people, the second a share of events (LayerX, Enterprise AI and SaaS Data Security Report 2025).
Put those together and shadow AI stops looking like an edge case. It looks like the default behavior.
Four ordinary moments that leak company data
Shadow AI rarely feels like a security event in the moment. It feels like getting work done. A few everyday examples:
- The “just summarize this” moment. Someone pastes an unreleased contract into a personal AI account to get the gist before a meeting.
- The debugging shortcut. An engineer drops a stack trace and a block of proprietary code into a free chatbot to find a bug faster.
- The tidy-up. A staffer cleans up a customer list or a spreadsheet of names and emails by asking an AI to reformat it.
- The catch-up email. A manager feeds meeting notes (including a few things that weren’t meant to leave the room) into a chatbot to write a recap.
None of these people are careless. They’re productive. But in each case, real company data has just entered an account the company can’t see into. The foundational example is still instructive: back in 2023, Samsung engineers reportedly pasted proprietary source code and internal meeting notes into ChatGPT, which pushed the company to restrict the tool. Three years on, the assistants are far more capable and far more woven into daily work, yet the same pattern keeps repeating. The behavior was ordinary then, and it’s even more ordinary now. The exposure was not.
Counting the real cost of shadow AI risks at work
Here’s where “harmless shortcut” collides with real numbers, the kind that land on your desk if you’re the one accountable for them. IBM’s 2025 Cost of a Data Breach report found that 20% of the organizations it studied had a breach linked to shadow AI. Separately, and this is a different measure rather than the same one restated, it found that having a high level of shadow AI added an extra USD 670,000 to the global average breach cost of 4.44 million.
Why so expensive? Because these incidents are hard to see. In IBM’s 2025 figures, breaches involving shadow AI disproportionately exposed customer personal data (65% of the time, versus 53% on average) and intellectual property. The oversight gap is the real villain: 63% of breached organizations had no governance policy for managing AI or detecting unauthorized use at all.
That’s the quiet math of shadow AI. Each individual paste feels like nothing. In aggregate, and on IBM’s numbers above, a high level of it sits alongside a measurably higher breach cost, precisely because no one is watching.
Ask three questions before you paste
Most people approach AI safety by asking, “Which AI tool is the safe one?” That’s the wrong question, and it’s why the problem persists. There is no single safe tool; there’s only appropriate use.
The shift that actually reduces risk is to stop thinking about tools and start thinking about three things at once:
- What data is this? Public and throwaway, internal, or genuinely confidential? The sensitivity of the input decides everything downstream.
- What account am I using? A personal consumer account, or an approved company plan with a contract behind it? Consumer plans, free or paid, put your conversations within reach of model training, whether that is a default you have to switch off or a choice you were asked to make, and they offer personal-plan protections only.
- Whose rules apply? Does your organization have a policy for this, and does this action fit it?
Those three questions will not fix the causes of shadow AI, which are usually a missing approved tool and a deadline. What they do change is the individual moment: people stop feeding confidential data into accounts that were never meant to hold it. The goal isn’t to ban AI. It’s to make the safe path the obvious one.
Make the safe path the obvious one
You don’t fix shadow AI with a single tool or a stern email. You fix it by making good choices easy, for yourself and your team. This pillar is the hub for a series that walks through the practical pieces:
- Start with the tool most people already use for work: ChatGPT vs Gemini vs Claude: Which Keeps Your Work Data Private? breaks down what each free plan does with your data and how to opt out.
- From there, the series covers opting out of AI training across all three, a one-page acceptable-use policy your team can adopt, a pre-upload checklist for company data, and how everyday data leakage happens.
If you only take one thing from this page, make it the three-question habit above. It’s the difference between AI as a productivity tool and AI as an invisible leak.
FAQ
QCan my employer see what I type into ChatGPT?
Can my employer see what I type into ChatGPT?
QCan I get fired for using AI at work?
Can I get fired for using AI at work?
QShould companies ban AI tools to stop shadow AI?
Should companies ban AI tools to stop shadow AI?
QHow can you tell if employees are using shadow AI?
How can you tell if employees are using shadow AI?
QWhat’s the difference between shadow AI and shadow IT?
What’s the difference between shadow AI and shadow IT?
Sources
- Netskope: Cloud and Threat Report (generative AI)
- Cyberhaven: 2025 AI Adoption and Risk Report
- IBM: Cost of a Data Breach Report 2025
- Microsoft: Work Trend Index
- LayerX: Enterprise AI and SaaS Data Security Report 2025
- Infosecurity Magazine: Personal LLM Accounts Drive Shadow AI Data Leak Risks
Each figure is labeled with the year of the report it comes from, which is not always the current year. Figures are cited as reported; check the linked primary sources for methodology and updates.