Skip to content

Top 50 Shadow AI Statistics 2026: Who Uses It and What It Costs

Elton Chan By Elton Chan Co-Founder 11 min read
TL;DR: Most employees who use AI at work have used a tool their employer did not provide or approve. Microsoft's Work Trend Index found 78% of AI users bring their own AI tools to work. In a 2025 Gartner survey, 69% of organizations suspected or had evidence that staff were using banned public GenAI.

The people paid to enforce AI rules break them more often than most. In UpGuard’s 2025 State of Shadow AI report, 88% of security leaders said they used unapproved AI tools, against 81% of the wider workforce. Employees who said they understood AI security rules were also more likely to use those tools regularly.

Key takeaways
  1. 1In the UK, 71% of employees have used unapproved consumer AI tools at work, and 51% still do every week.
  2. 2Among AI users, 48% of Gen Z and Millennials have shared sensitive work information with AI tools behind their employer’s back, against 20% of Baby Boomers.
  3. 3Paying for and bringing your own AI ranges from 23% of employees in government to 58% in wealth and asset management.
  4. 4Only 38% of organizations have a formal, comprehensive AI policy, up from 28% a year earlier.

How Many Employees Use Unapproved AI Tools?

Between half and four in five, depending on the survey and its question. Microsoft and LinkedIn’s 2024 Work Trend Index surveyed 31,000 knowledge workers in 31 markets. Three in four used generative AI at work, and 78% of those users brought their own AI tools. At small and medium-sized companies, the figure was 80%.

Later surveys land on either side of that. Microsoft’s own UK study, run by Censuswide in October 2025, found 71% of UK employees had used unapproved consumer AI tools at work. BlackFog’s November 2025 poll of 2,000 US and UK employees at firms with 500 or more staff put the share at 49%.

Dot plot of the share of respondents using AI tools their employer did not provide or approve, by survey: UpGuard 2025 81 percent, Microsoft 2024 78 percent of AI users, Microsoft UK 2025 71 percent, Salesforce 2023 55 percent of generative AI users, Software AG 2024 50 percent, BlackFog 2025 49 percent and EY 2025 38 percent.
Why the surveys disagree. Microsoft and Salesforce report a share of AI users, which runs higher than a share of all employees because non-users drop out. BlackFog, Microsoft UK and EY count every employee they surveyed. EY also asks a narrower question: whether employees pay for and bring their own AI.

Banned tools, not only unapproved ones

Salesforce asked more than 14,000 workers in 14 countries in October 2023. Among those using generative AI on the job, 55% had used unapproved tools and 40% had used tools their employer explicitly banned. Training was rare: 69% said their employer had not provided any.

Many say a ban would not stop them. In Software AG’s 2024 study of 6,000 knowledge workers, half used AI tools their company had not issued, and 46% would refuse to give them up even under a full ban. BlackFog found 60% of employees think unsanctioned AI is worth the security risk if it helps them hit a deadline.

Budgets have not caught up with the habit. MIT’s Project NANDA, in its July 2025 report The GenAI Divide, found only 40% of companies had bought an official LLM subscription, while workers at more than 90% of the companies it surveyed used personal AI tools for work. Our AI in the workplace statistics cover the approved side of that adoption.

Do Employers Know Their Staff Use Banned AI?

Most suspect it. A Gartner survey of 302 cybersecurity leaders, run from March to May 2025, found 69% of organizations suspect or have evidence that employees use prohibited public GenAI. ISACA’s poll of digital trust professionals points the same way: in 2026, 90% believed employees in their organization were using AI.

Suspecting it and seeing it are different jobs. Cisco’s 2025 Cybersecurity Readiness Index polled 8,000 business leaders in 30 markets. Sixty percent lacked confidence that they could identify unapproved AI tools in their environment.

Three donut rings showing what organizations say about staff AI use: 69 percent suspect or have evidence of banned GenAI use in a Gartner survey of 302 cybersecurity leaders, 60 percent are not confident they can spot unapproved AI tools in Cisco's 2025 index, and 90 percent believe employees use AI in ISACA's 2026 poll.

Some employers tried blocking instead. In Cisco’s 2024 Data Privacy Benchmark Study of 2,600 privacy and security professionals, 27% said their organization had banned GenAI applications for the time being. A larger group, 61%, limited which GenAI tools employees could use, and 63% limited what data could go in.

Those same professionals were not clean either. Forty-eight percent admitted entering non-public company information into GenAI tools themselves.

Who Uses Shadow AI the Most?

Senior leaders. UpGuard’s survey found executives had by far the highest rate of regular shadow AI use of any seniority level. BlackFog asked a sharper question, whether speed matters more than privacy or security, and the answers split by rank.

Junior and administrative staff
  • 38% of junior executives say speed trumps privacy or security
  • 37% of administrative staff say the same
Senior leaders
  • 69% of presidents and C-level respondents
  • 66% of directors and senior VPs
Source: BlackFog, survey of 2,000 US and UK employees by Sapio Research, November 2025.

By generation

Bringing your own AI is not a Gen Z habit. Microsoft found 85% of Gen Z AI users did it, but so did 73% of those aged 58 and over.

The age gap opens up on data. In the 2025 Oh, Behave! report from CybSafe and the National Cybersecurity Alliance, younger AI users were more than twice as likely as Boomers to share sensitive work information without telling their employer.

Split bars by generation among AI users. Bringing their own AI tools, from Microsoft's 2024 Work Trend Index: Gen Z 85 percent, Millennials 78, Gen X 76, Boomers 73. Sharing sensitive work information with AI without the employer knowing, from the 2025 Oh, Behave! report: Gen Z 48 percent, Millennials 48, Gen X 30, Boomers 20.

Across all ages, 43% of AI users in that survey of seven countries had shared sensitive work information without their employer knowing. In India it was 55%. Among those who shared, half passed on internal company documents and 44% passed on customer or client data.

Training has not kept pace. More than half of employed respondents, 52%, said they had received no training on the security or privacy risks of AI tools.

By industry and department

Finance and technology lead. EY’s 2025 Work Reimagined Survey of 15,000 employees in 29 countries found 38% pay for and bring their own AI on average. Wealth and asset management reached 58%, and government sat at the bottom with 23%.

Horizontal bars of employees who pay for and bring their own AI, by sector, from EY's 2025 Work Reimagined Survey: wealth and asset management 58 percent, technology 56, banking and capital markets 53, mining and metals 49, global average 38, retail 32, health 26, and government and public sector 23.

Inside companies, UpGuard found marketing and sales use unapproved AI the most, with HR close behind. Operations, finance and support use it less. Engineering stands out on total AI use: Cyberhaven’s 2026 report found more than 60% of engineering employees use AI tools, about 20 points more than marketing, counting approved and unapproved use together.

Which AI Tools Do Employees Use Without Approval?

ChatGPT, by a wide margin. Reco’s 2025 State of Shadow AI report, built from customer telemetry, put OpenAI at 53% of all the shadow AI usage it tracked. Some unsanctioned apps ran for more than 400 days on average before anyone acted. In the Oh, Behave! survey, 77% of AI users named ChatGPT as a tool they use.

The KPMG and University of Melbourne global study found many employees choose free, publicly available tools over the ones their employer provides. A free chatbot’s handling of what you type is a consumer privacy question, and privacy sites such as VPNoverview.com now publish AI guides next to their VPN coverage.

Personal accounts are falling, but not gone

Network data shows companies pulling employees onto managed accounts. Netskope’s Cloud and Threat Report 2026 tracked the shift from October 2024 to October 2025. The share of genAI users on personal AI apps fell from 78% to 47%, while users switching between personal and company accounts more than doubled.

Slope chart of how genAI users sign in, from Netskope's Cloud and Threat Report 2026 covering October 2024 to October 2025: personal app use fell from 78 to 47 percent, company accounts rose from 25 to 62 percent, and users of both rose from 4 to 9 percent.

The mix depends on the tool. Cyberhaven’s browser data from 222 companies shows how much of each app’s use still runs through personal logins.

60.9%
of Perplexity use runs through personal accounts
58.2%
of Claude use
32.3%
of ChatGPT use
24.9%
of Gemini use
Source: Cyberhaven 2026 AI Adoption and Risk Report, February 2026.

ChatGPT’s figure was far higher two years earlier, when Cyberhaven’s 2024 report found 73.8% of workplace ChatGPT use on non-corporate accounts. That report drew on a different customer base, so the two numbers are not a clean trend. See our ChatGPT statistics and Claude statistics for each tool’s overall reach.

Why Do Employees Hide Their AI Use?

Feeling like a cheat, or looking lazy, tops the list. Company rules come last. Slack’s Fall 2024 Workforce Index surveyed 17,372 desk workers in 15 countries. Forty-eight percent would be uncomfortable telling their manager they used AI for common tasks.

Columns showing why desk workers who are uncomfortable telling a manager about their AI use feel that way, from Slack's Fall 2024 Workforce Index: it feels like cheating 47 percent, fear of being seen as less competent 46, fear of being seen as lazy 46, and company policy only 21 percent.

Microsoft’s 2024 survey found the same unease: 52% of AI users were reluctant to admit using it for their most important tasks.

The KPMG study, which covered 32,352 employees in 47 countries, measured the hiding itself. Fifty-seven percent had used AI in non-transparent ways, such as presenting AI output as their own work or not saying they had used it.

Rule-breaking is common in the same study. Forty-four percent of employees had used AI in ways that contravene their organization’s policies, and 56% had used AI tools at work without knowing whether their employer allowed it.

A secret advantage, or no approved option

Some reasons are about getting ahead. Ivanti’s 2025 Technology at Work report found 32% of genAI users keep their use a secret from their employer.

36% like the secret advantage30% worry their job may be cut27% feel AI-fuelled imposter syndrome

Others point at IT. In Software AG’s study, 53% of employees using their own AI said they prefer the independence, and 33% said their IT team does not offer the tools they need. In Microsoft UK’s survey, 41% said shadow AI is what they know from their personal life.

The tools employees pick carry their own flaws, from prompt injection to insecure code, which our AI tool security vulnerability statistics track.

How Many Companies Have an AI Policy?

Fewer than half on most counts, though the share is climbing fast. ISACA’s AI Pulse Poll found 38% of organizations had a formal, comprehensive AI policy in 2026, up from 28% in 2025 and 15% in 2024. Another 30% had a limited policy, and 25% had none at all.

Arrow plot of AI policy prevalence between surveys: Littler employers with a formal AI policy rose from 38 to 68 percent between 2025 and 2026, ISACA organizations with a formal, comprehensive policy from 28 to 38 percent, and US employees reporting guidelines or policies in Gallup's panel from 20 to 30 percent between 2024 and 2025.

Employees see fewer rules than employers report. Gallup’s 2025 panel found 30% of US employees said their organization had general guidelines or formal policies for AI. Only 22% said it had shared a clear plan for bringing AI in. In the KPMG study, only 34% of employees reported any policy or guidance on generative AI.

Employment law firm Littler found faster movement. Its 2026 employer survey found 68% of respondents had a formal policy on workplace AI use, against 38% a year earlier. Fifty-five percent had a review or approval process for AI tools, and 54% limited what data employees could enter.

How Much Does a Shadow AI Breach Cost?

About $400,000 more than the average breach, on IBM’s 2026 numbers. The Cost of a Data Breach Report 2026, researched by the Ponemon Institute, studied 602 organizations breached between March 2025 and February 2026. The global average was $4.99 million, and incidents involving shadow AI averaged $5.39 million, up from $4.63 million a year earlier.

The $400,000 gap is our subtraction of IBM’s two averages. IBM’s 2025 edition measured the premium directly, by comparing organizations with high and low levels of shadow AI.

Waterfall of average data breach cost by level of shadow AI from IBM's Cost of a Data Breach Report 2025: 4.07 million dollars with low or no shadow AI, a premium of 0.67 million dollars, and 4.74 million dollars with a high level of shadow AI.

Organizations with a high level of shadow AI paid $4.74 million per breach, IBM reported in July 2025, against $4.07 million for those with little or none. Customer personal data was compromised in 65% of shadow AI incidents, against 53% of all breaches.

In the 2026 study, 49% of shadow AI incidents led to data loss or compromise and 42% disrupted operations. In about one in five, the organization reported paying a fine.

Which controls companies use

IBM found 68% of the organizations it studied lacked AI governance policies to manage AI or detect shadow AI, up from 63% a year earlier.

Among controls in use, IT approval before an AI deployment was the most common at 38%, down from 45%. For employees, that approval usually starts as an access request, the kind of internal ticket an ITSM platform routes to IT. AI governance frameworks and governance technology each reached 33%, and only 19% coordinated governance with security teams.

Building AI Tools Your Team Will Use

A third of employees who bring their own AI say IT does not offer the tools they need. Second Talent matches companies with pre-vetted AI developers and machine learning engineers who can build internal assistants on licensed models and connect them to your systems.

Tell us what you are building and we will send matching profiles.

Frequently Asked Questions

What counts as shadow AI?

Any AI tool used for work outside the organization’s visibility, policy and control. A personal ChatGPT login on a work laptop counts. The same tool on a company-managed enterprise account does not.

Is shadow AI the same as shadow IT?

It is a subset. Shadow IT covers any software or service used without approval. Shadow AI is the AI part of it, and it gets separate attention because each prompt can carry company data to an outside provider.

Can a company see which AI tools employees use?

Partly. Tools that inspect web traffic or browser activity can show which AI apps employees open and whether they sign in with a personal or company account. That is how Netskope, Cyberhaven and Reco produce their figures. Use on a personal phone off the company network stays outside that view.

Hire AI engineers.

Pre-vetted senior engineers from Asia at 50 to 70% below US hiring costs, with first profiles in 24 hours.

Hire AI engineers Apply as talent →
Elton Chan

Written by

Elton Chan is the Co-Founder of Second Talent, a solution that connects global tech leaders with top-tier tech talent across Asia. He specializes in talent solutions and has led Second Talent’s rapid growth since 2024, helping scale its network to over 100,000 pre-vetted developers and earning industry recognition as the #1 in the Global Hiring category on G2. A long-time entrepreneur with deep roots in digital transformation, Elton previously co-founded Branch8, a Y Combinator–backed e-commerce technology firm, and served as the Founding Chairman of HKEBA, a leading Asia-focused business association driving innovation, digital education, and cross-border collaboration. His work bridges technology, talent, and business strategy to shape how companies scale in an increasingly remote and digital world.

More posts by Elton Chan →

Loading available times…