What Is Shadow AI? The Biggest AI Risk in Your Company

What Is Shadow AI? The Biggest AI Risk in Your Company

Empowerment AI··Updated

Shadow AI is the use of AI tools, like ChatGPT, Claude, Gemini, or the AI features built into other apps, by employees without the knowledge or approval of their company's IT or security team. It's the AI version of shadow IT, and its main risk is company and customer data leaving the business through a chat window nobody is watching.

TL;DR: The biggest AI security threat to most companies is their own well-meaning employees pasting sensitive data into AI tools nobody approved. In IBM's 2026 Cost of a Data Breach Report, security incidents involving shadow AI more than doubled, to 43% from 20% the year before, and those breaches averaged $5.39 million. Below: real examples, the ways shadow AI turns into a breach, how to detect it, and how to prevent it without banning AI outright.

What are examples of shadow AI?

If an AI tool touches company data and whoever approves tools doesn't know about it, it counts. In a business without an IT department, that approval is the owner's. The common cases:

  • A personal ChatGPT, Claude, or Gemini account used to shorten a client contract or clean up a spreadsheet of customer names.
  • A browser extension that "improves your writing" by reading everything typed into every web page.
  • An AI note-taker that joins every meeting on someone's calendar, including the ones with clients.
  • AI features quietly switched on inside a tool the company already pays for, like a CRM or help desk.
  • A developer pasting proprietary code into a coding assistant on a personal plan.
  • A personal AI agent installed on a work laptop. Token Security reported that 22% of its enterprise customers had employees running the open-source agent now called OpenClaw, which can read email and files. We covered what that agent can do in AI agents vs chatbots.

Is ChatGPT shadow AI?

It depends on the account, not the tool. ChatGPT on a company-managed Business or Enterprise plan (Business was formerly called Team) that IT approved is sanctioned AI. OpenAI doesn't train on data from those plans by default. The same ChatGPT on an employee's personal Free or Plus account, fed company data, is shadow AI. Consumer conversations can be used for training unless the user turns off the "Improve the model for everyone" setting.

Shadow AI vs shadow IT

When someone uses an unapproved app for file sharing, the data usually stays inside that app. When someone pastes customer records into a consumer AI tool, the data can end up in conversation logs, in training data, and in the account history of whoever controls that login. Shadow AI creates copies of your data in places you can't list, let alone secure.

How big is the shadow AI problem?

Bigger every year, and faster than most leadership teams think.

In IBM's 2026 Cost of a Data Breach Report, security incidents involving shadow AI more than doubled, to 43% from 20% the year before. Those breaches averaged $5.39 million, up from $4.63 million. For comparison, the global average breach cost a record $4.99 million in 2026.

IBM's 2025 research measured the extra damage. That year:

Three ways shadow AI turns into a breach

1. Company data pasted into personal accounts

This is the everyday version. Someone in marketing drops customer research into a free chatbot to get a summary. Someone in finance uploads a vendor list to build a spreadsheet. Nobody means harm, and nobody tracks where the data went.

For regulated businesses (healthcare, finance, anything touching government contracts) this can be a compliance problem the moment protected data lands in an unapproved tool.

What to do: Give people approved AI tools that route through your accounts and settings. Then block what you can. Kiteworks found in 2025 that only 17% of organizations have technical controls that block access to public AI tools combined with data loss prevention scanning. Policies and training alone don't stop a tired person at 5 p.m.

2. Stolen AI accounts hand over the history

IBM's 2026 X-Force Threat Intelligence Index found that in 2025, over 300,000 ChatGPT credential sets were advertised on the dark web, driven largely by infostealer malware.

A stolen AI login matters for two reasons. People reuse passwords, and IBM spells out the risk: "Password reuse across personal and enterprise accounts continues to create indirect attack paths." And the account itself holds a searchable archive of every prompt and upload. An attacker who gets in can read your company's internal thinking, one conversation at a time.

What to do: Require multi-factor authentication on every AI account used for work, ideally phishing-resistant options like passkeys or FIDO2 keys. Put business AI tools behind your single sign-on so access ends when employment does. Check Have I Been Pwned for your company's email domain.

3. Nobody owns AI governance

In IBM's 2025 research, 63% of breached organizations either had no AI governance policy or were still developing one. That gap gets more expensive every year. U.S. federal agencies introduced 59 AI-related regulations in 2024, more than double the year before, and legislative mentions of AI rose 21.3% across 75 countries, according to Stanford's 2025 AI Index. And in IBM's 2026 report, about one in five shadow AI incidents ended with the organization paying a regulatory fine.

What to do: Write a short AI policy that names the approved tools, what data can and can't go into them, and how someone requests a new tool. Then check real usage every quarter, not just the policy.

Two related AI risks

These aren't shadow AI in the strict sense, but they land on the same people, and the fixes overlap.

Attackers use AI on the same employees

The people using shadow AI are also the people receiving AI-written phishing. SlashNext's 2023 State of Phishing report counted a 1,265% increase in malicious phishing emails from the fourth quarter of 2022 through the third quarter of 2023, and a 967% jump in credential phishing. In a 2023 experiment, IBM's X-Force team found that a phishing email that typically took them about 16 hours to write could be generated with AI in five minutes.

It's showing up in breach data now. In IBM's 2026 report, one in four malicious breaches were AI-enabled, mostly deepfake impersonation and AI-enabled malware, and those breaches cost an average of $6 million. A Gartner survey found that 62% of organizations experienced a deepfake attack involving social engineering or exploiting automated processes in the prior 12 months. Deloitte projects that generative AI could push U.S. fraud losses to $40 billion by 2027, up from $12.3 billion in 2023.

What to do: Retire the "look for typos" training. Require a callback on a known number for any payment change, wire request, or password reset, even when the request arrives on video.

AI apps you built and never tested

If you've added a chatbot to your website or an AI step that reads documents, it can be manipulated. Prompt injection, data extraction, and jailbreaks all work on tools that were never tested for them. We walk through the attacks in Prompt Injection: What Developers Need to Know.

What to do: Before launch, try to break it. Ask it to reveal its instructions, to ignore its rules, and to show another customer's data. If it does any of those, it isn't ready.

How to detect shadow AI

Start by asking, then check. People will tell you more than you expect if the question comes with amnesty.

  1. Run an anonymous survey. Which AI tools do you use for work, and for what? Promise no penalties for past use.
  2. Check connected apps. Your Google Workspace or Microsoft 365 admin console lists the third-party apps people have connected to their work accounts. AI note-takers and writing tools show up here.
  3. Look at network traffic. DNS or firewall logs show visits to AI services like chatgpt.com, claude.ai, and gemini.google.com.
  4. Read the expense reports. AI subscriptions on company cards are a map of who's using what.
  5. Inventory browser extensions on company devices, and look at meeting invites for note-taker bots you didn't approve.

How to avoid shadow AI without banning AI

Bans push usage onto personal phones, where you can see even less. The approach that works is to make the approved path easier than the unapproved one.

  • Offer a sanctioned tool. A business AI plan that doesn't train on your data, behind single sign-on, with MFA.
  • Draw the data line. Keep a short "never list" for any AI tool: customer names tied to personal details, payment data, ID numbers, health information, passwords, and confidential client work.
  • Make it one page. A policy people actually read beats a thorough one nobody opens.
  • Add controls that don't rely on memory. Block unapproved AI services on company devices and add data loss prevention where you can.
  • Train for the specific risks. Show people what goes wrong, not just the rules.
  • Use AI on defense. In IBM's 2026 report, security teams that used AI and automation extensively saved $1.93 million per breach on average and shortened their breach times by 65 days. We looked at how that's playing out in code review in application security in 2026.

If you want help with the training piece, our Safe AI at Work session covers where your team is already using AI, the never list, the privacy settings pass on your actual accounts, and a one-page policy written before the session ends. For a broader program, see our AI training for employees.

The bottom line

Most shadow AI comes from good employees trying to go faster: a customer list pasted into a free chatbot, a contract shortened on a personal account, a note-taker nobody approved sitting in on a client call. None of them think they're doing anything wrong, and until someone sets the rules, they aren't breaking any.

Start with an inventory this month. Give people a sanctioned tool. Write the one-page policy.

Enjoyed this article? Share it.

Share

Newsletter

Want the next one in your inbox?

One useful AI idea a month for small businesses, in plain English. No drip campaign.

Practical AI for small businesses, about once a month. Every issue has an unsubscribe link.

Prefer video? Subscribe on YouTube →