The question is wrong before anyone answers it
Most organisations arrive at shadow AI in the accusatory mood. Somebody in finance has been feeding a draft forecast into a consumer chatbot; somebody in legal has been summarising contracts through a free browser extension; and the instinctive framing is one of transgression. Who did this, how do we stop it, what disciplinary lever applies.
That framing produces bad strategy, because it mistakes a symptom for a cause. Unapproved AI use is not principally an integrity failure among your workforce. It is a procurement failure, a latency failure and a design failure, expressed through the only channel available to employees who are being asked to do more with less. The correct opening question is not “how do we stop this” but “what does this behaviour reveal about the gap between the work we ask people to do and the tooling we have licensed them to do it with”.
Answer that question honestly and the strategy follows almost mechanically. Refuse to answer it, and you will spend eighteen months writing policies that your own executive committee quietly ignores.
The situation: this is now the default, not the deviation
The scale is no longer contestable. The CIPD’s Autumn 2025 Labour Market Outlook found that employees in roughly three quarters of UK organisations (76 per cent) are using AI tools at work, rising to 87 per cent in the public sector, whilst 61 per cent of organisations formally permit generative AI and a quarter still prohibit it with no plans to change.
The gap between permission and practice is where shadow AI lives, and it is enormous. MIT’s Project NANDA study, The GenAI Divide: State of AI in Business 2025, reported that only around 40 per cent of companies had purchased an official large language model subscription, yet employees at more than 90 per cent of companies were regularly using personal AI tools for work. The same report is better known for its headline that roughly 95 per cent of enterprise generative AI pilots delivered no measurable profit and loss impact, and the juxtaposition is the whole story: the sanctioned programme stalled whilst the unsanctioned one scaled.
Telemetry corroborates the surveys. Cyberhaven Labs, drawing on billions of observed data movements across 222 companies for its 2026 AI Adoption and Risk Report, found that 32.3 per cent of ChatGPT usage and 24.9 per cent of Gemini usage occurred through personal accounts, that 39.7 per cent of all interactions with AI tools involved sensitive data, and that the average employee inputs sensitive material into an AI tool roughly once every three days. Eighty-two per cent of the hundred most-used generative AI applications were classified as medium, high or critical risk.
And the behaviour is concealed. The University of Melbourne and KPMG global study, covering more than 48,000 respondents across 47 countries, found that 48 per cent of employees admitted using AI in ways that contravene company policy, including uploading sensitive company information into free public tools, and that 57 per cent hide their AI use and present AI-generated output as their own. Only 47 per cent had received any AI training.
You are not deciding whether to permit AI use. You are deciding whether the AI use already occurring will happen inside or outside your control environment.
The complication: the shadow falls upwards
Here the conventional narrative collapses, and with it most of the enforcement-led responses built upon it.
Shadow AI is habitually characterised as a frontline problem: digital natives circumventing a slow IT function. Original research conducted by TrustedTech with Censuswide in March 2026, surveying 2,001 employees split evenly between the UK and the United States, found precisely the opposite distribution. Forty-eight per cent of employees overall used unapproved AI tools, but senior decision-makers did so at more than twice the rate of the people they manage: 65 per cent against 31 per cent, rising to 73 per cent at C-suite level and falling to 36 per cent among entry-level staff. Usage of unsanctioned tools rose almost monotonically with seniority.
The stated reasons are strategically significant, because they are not the reasons a policy document can address. Decision-makers cited limitations in access to approved tools (29 per cent) and greater efficiency of unapproved alternatives (28 per cent), which one might anticipate. But they also cited worry that the organisation would see how often they use AI in ways that could affect their career (24 per cent), concern that visible AI use would raise doubts about their competence (23 per cent), and unease about managerial monitoring (23 per cent).
This is reputational risk aversion, not convenience seeking, and it inverts the usual governance logic. The population holding the most sensitive material, board papers, transaction analysis, strategy drafts, restructuring options, is routing that material through the least governed channel precisely because the sanctioned channel is legible to the organisation. Meanwhile, 37 per cent of decision-makers said they would continue using AI tools even if their workplace banned them and disciplinary action followed, against 19 per cent of those below decision-maker level.
The operational conclusion is uncomfortable but clear. A prohibition will hold at the bottom of the organisation, where the exposure is lowest, and fail at the top, where it is highest. You will have purchased the appearance of control at the cost of visibility over the material that matters most.
Why prohibition is the least defensible option available
Banning is superficially attractive because it is cheap, fast and legible to a board. It is also, on the evidence, the strategy with the worst risk-adjusted return.
Prohibition does not eliminate usage; it displaces it. Research from PagerDuty found that 66 per cent of office professionals had used AI for work despite believing it was not permitted, a figure that rose to 72 per cent at organisations with 1,500 or more staff. Software AG’s earlier survey of 6,000 knowledge workers found that 46 per cent would refuse to relinquish personal AI tools even if their organisation banned them outright. Displacement is worse than permission, because it destroys the telemetry you would otherwise use to manage the risk, and it moves activity from managed devices onto personal ones.
Prohibition also forfeits the evidentiary position. Under the UK GDPR and the Data Protection Act 2018, and increasingly under sector-specific expectations, the question a regulator asks after an incident is not whether you had a rule but whether you had a demonstrable control. A ban that everybody breaches is, in accountability terms, worse than a permissive regime that is instrumented and logged, because it establishes that you knew the risk, asserted a control, and failed to verify it.
Finally, prohibition surrenders the productivity. In the TrustedTech data, 54 per cent of AI users reported saving three or more hours per week. The MIT findings suggest much of the realised value in enterprises today is being created in the shadow economy rather than the sanctioned one. A ban does not recover that value for the organisation; it merely ensures the organisation cannot see, audit, compound or defend it.
The three ledgers of exposure
Boards tend to reduce shadow AI to a single line item, data leakage. That understates the position on two of three ledgers.
The first ledger is data and security exposure, and it is now quantified. IBM’s Cost of a Data Breach Report 2025, produced with the Ponemon Institute across 600 breached organisations, found that one in five had suffered a breach linked to shadow AI, and that a high level of shadow AI added approximately USD 670,000 to the average breach cost, against a global average of USD 4.44 million. Ninety-seven per cent of organisations reporting an AI-related security incident said they lacked proper AI access controls, and 63 per cent had no AI governance policy at all, with only 37 per cent operating any approval or oversight mechanism. Shadow AI breaches disproportionately compromised customer personal data, at 65 per cent against a 53 per cent global average, and took longer to identify.
The second ledger is decision quality and accountability. The Melbourne and KPMG study found that around two thirds of employees rely on AI output without evaluating its accuracy, and that a majority acknowledged making mistakes in their work as a result. When 57 per cent conceal usage, the organisation loses the ability to trace a defective output back to its origin. This is the ledger that produces the professional negligence claim, the misfiled regulatory return and the discriminatory recruitment shortlist, and it does not require any data to leave the building.
The third ledger is capability asymmetry, and it is the one most consistently under-weighted. Cyberhaven’s data shows frontier organisations deploying more than 300 generative AI tools with employee adoption above 70 per cent, whilst cautious enterprises sit below 15 tools and near-negligible adoption. That is not a security gap; it is a compounding operating-model gap. The cost of a restrictive posture is not primarily a breach avoided. It is a workforce that becomes structurally slower than its competitors, and that learns to treat the organisation’s controls as obstacles to be routed around.
The answer: governed enablement, sequenced
The defensible strategic posture is neither prohibition nor laissez-faire. It is governed enablement: making the sanctioned path the path of least resistance, and instrumenting it sufficiently that you can evidence what happened. Six moves, in order.
One. Discovery before doctrine. You cannot govern an estate you have not enumerated, and any enforcement action taken without a baseline will punish the compliant and miss the material exposure. Establish actual usage through network egress analysis, browser and endpoint telemetry, identity and single sign-on logs, and, critically, expense and corporate card data, which is where personal-tier subscriptions surface. Pair this with a time-boxed amnesty: a stated period during which disclosure of unapproved tools carries no sanction. The amnesty is not softness; it is the cheapest available discovery mechanism, and it is the only one that surfaces tools used from personal devices.
Two. Classify by data, not by tool. Tool-level allow-lists decay within weeks, because the market produces new entrants faster than any review board can process them. Govern instead by data class. A short, memorable “do not paste” list, covering client personal data, special category data, credentials, unpublished financials, source code, and anything under a confidentiality obligation, will do more practical work than a forty-page policy. Then tier permitted use: unrestricted for public and synthetic material, controlled for internal material within enterprise-tier instances, prohibited for the named classes above absent a documented exception.
Three. Close the latency gap, because latency is the root cause. An employee can adopt a new AI service in ninety seconds; a conventional procurement and security review takes weeks. That differential is the entire mechanism by which shadow AI is generated. Commit publicly to a triage lane with a stated service level, for example an initial risk decision within five working days, and staff it. Simultaneously, buy the enterprise tiers of the tools people are demonstrably already using, with contractual guarantees on training-data exclusion and retention. The single most effective control against a personal ChatGPT account is a corporate one that is at least as good.
Four. Decouple usage telemetry from performance management, explicitly and in writing. This addresses the executive driver identified above, and nothing else will. If leaders believe that AI usage logs may be read as evidence of diminished competence or inflated headcount, sanctioned tools will carry a trust penalty that free consumer alternatives do not. The commitment must be written, specific, and issued by the executive committee rather than by IT, because it is the executive committee’s own behaviour it is intended to change.
Five. Instrument the boundary, not the individual. Deploy controls at the point where data leaves: browser-level and endpoint data loss prevention capable of inspecting prompt content and file uploads, an AI gateway or reverse proxy through which sanctioned traffic is routed and logged, and account-type detection that distinguishes corporate from personal instances of the same application. IBM’s finding that 97 per cent of AI-related incidents involved organisations lacking AI access controls is the empirical case for this line item. Note the distinction from surveillance: you are logging data flows and policy exceptions, not building a productivity dossier on named employees.
Six. Anchor the programme to an external framework, so the work is auditable and portable. ISO/IEC 42001:2023, the first certifiable AI management system standard, provides the plan-do-check-act structure and is increasingly appearing in enterprise procurement questionnaires; ISO/IEC 42006:2025 governs the accreditation of its auditors. The NIST AI Risk Management Framework supplies a complementary, non-certifiable risk methodology whose functions map onto the ISO requirements. In the UK, the DSIT AI Cyber Security Code of Practice, published in January 2025 and built on the NCSC’s Guidelines for Secure AI System Development, has been carried into ETSI TS 104 223 as an international baseline. If any part of your operation touches the EU, note that Article 4 of the EU AI Act, requiring providers and deployers to ensure a sufficient level of AI literacy among staff and contractors, has applied since 2 February 2025, with national market surveillance and penalty regimes due to be in place from 3 August 2026. Domestically, the ICO’s guidance is in motion following the Data (Use and Access) Act 2025, with a statutory code of practice on AI and automated decision-making in preparation.
The agentic turn: what breaks next
Everything above assumes shadow AI means a human pasting text into a chat window. That assumption has a short remaining life.
Gartner has projected that some 40 per cent of enterprise applications will feature task-specific AI agents by the end of 2026, up from under five per cent in 2025. Agents differ from chatbots in one governance-relevant respect: they act. To act, an agent requires credentials, API keys, OAuth tokens or service accounts, which is to say it requires a non-human identity with standing access to systems and data. Research reported by Delinea found that 53 per cent of organisations regularly encounter unauthorised AI tools and agents accessing company systems, whilst 90 per cent reported pressure on security teams to relax access controls in support of AI-driven automation.
An unsanctioned agent is therefore not a policy violation; it is an ungoverned identity with execution authority, provisioned outside every lifecycle control your organisation applies to human access. The practical implication is that the agent registry, mandatory registration of purpose, owner, permission scope and review date, should be built now, whilst the population is small enough to enumerate. Organisations that defer this will attempt it later against an estate of unknown size, during an incident.
What to place in front of the board
Strategic problems require measured positions, not assurances. Four metrics carry most of the signal:
- Coverage ratio: the proportion of detected AI interactions occurring through sanctioned, logged channels. This is the single number that tells you whether governed enablement is working. It should rise quarter on quarter; if it does not, your sanctioned tooling is uncompetitive.
- Approval latency: median elapsed time from tool request to risk decision. This is the leading indicator of future shadow AI, and it is the one metric wholly within your control.
- Sensitive data flow rate: the proportion of AI interactions carrying classified material, and the share of those flowing to personal or unvetted accounts.
- Agent inventory completeness: the proportion of detected non-human identities associated with AI tooling that have a named owner, a documented purpose and a scheduled review.
Report these alongside the conventional incident measures. They convert a diffuse cultural anxiety into a managed variance, which is what a board is equipped to govern.
Closing judgement
Shadow AI is best understood not as indiscipline but as an unpriced demand signal that your workforce has already acted upon. The evidence indicates that it is majority behaviour, that it is concentrated among senior staff handling the most sensitive material, that prohibition displaces rather than eliminates it, and that its costs are measurable on the security ledger, the decision-quality ledger and the competitive ledger simultaneously.
The organisations that will handle this well over the next eighteen months are not those with the strictest policies. They are those that treat the gap between sanctioned and actual usage as a performance metric, that make the governed path the fastest path, and that build the identity and logging substrate now, whilst the problem is still humans typing into a text box rather than autonomous agents holding credentials to production systems.
The choice is not between control and enablement. It is between governing AI use whilst that remains cheap, and reconstructing what happened afterwards, at USD 670,000 above the going rate.
Sources
- IBM and Ponemon Institute, Cost of a Data Breach Report 2025. https://www.ibm.com/reports/data-breach
- IBM Think, “2025 Cost of a Data Breach Report: Navigating the AI rush without sidelining security”. https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai
- IBM Think, “Cost of a Data Breach: what CDOs need to know”. https://www.ibm.com/think/insights/data-matters/cost-of-a-data-breach
- Cybersecurity Dive, “‘Shadow AI’ increases cost of data breaches, report finds”. https://www.cybersecuritydive.com/news/artificial-intelligence-security-shadow-ai-ibm-report/754009/
- Cyberhaven Labs, 2026 AI Adoption and Risk Report. https://www.cyberhaven.com/resources/report/ai-adoption-risk-report-2026
- Cyberhaven, “Sensitive Enterprise Data Is Flowing Into AI Tools at Scale”. https://www.cyberhaven.com/blog/sensitive-data-flowing-into-ai-tools
- MIT Project NANDA, The GenAI Divide: State of AI in Business 2025, as reported by Fortune and VentureBeat. https://venturebeat.com/ai/mit-report-misunderstood-shadow-ai-economy-booms-while-headlines-cry-failure
- Gillespie, N., Lockey, S., Ward, T., Macdade, A., and Hassed, G. (2025), Trust, Attitudes and Use of Artificial Intelligence: A Global Study 2025, University of Melbourne and KPMG. DOI 10.26188/28822919. https://kpmg.com/xx/en/our-insights/ai-and-technology/trust-attitudes-and-use-of-ai.html
- CIPD, Labour Market Outlook, Autumn 2025, and “Generative AI at work: can it deliver the productivity boost UK employers need?”. https://www.cipd.org/en/about/blogs/can-ai-deliver-productivity-boost-uk-needs/
- TrustedTech with Censuswide, Shadow AI in the Workplace research, fielded 19 to 24 March 2026, 2,001 UK and US employees. https://www.trustedtechteam.com/blogs/security/shadow-ai-executives-workplace-risk
- PagerDuty research on unauthorised AI use, reported by TechRadar Pro. https://www.techradar.com/pro/intentionally-hide-using-ai-66-of-office-workers-admit-to-secretly-using-banned-ai-tools
- Software AG, Chasing Shadows: Getting Ahead of Shadow AI. https://www.cybersecurityintelligence.com/blog/half-of-employees-use-shadow-ai-8338.html
- HR Dive, “Nearly half of workers say they’ve used banned AI tools at work, survey finds” (Anagram research). https://www.hrdive.com/news/workers-use-banned-ai-tools-at-work/757481/
- Gartner projection on task-specific AI agents in enterprise applications, as cited by Vectra AI, “Shadow AI explained: risks, costs, and enterprise governance”. https://www.vectra.ai/topics/shadow-ai
- Delinea research on non-human identities, reported by Help Net Security. https://www.helpnetsecurity.com/2026/05/13/hidden-risk-non-human-identities-ai-adoption/
- European Commission, “AI talent, skills and literacy” (Article 4, EU AI Act). https://digital-strategy.ec.europa.eu/en/policies/ai-talent-skills-and-literacy
- Crowell and Moring, “Employer AI Literacy Obligations under the EU AI Act”. https://www.crowell.com/en/insights/client-alerts/part-2-ai-literacy-employer-ai-literacy-obligations-under-the-eu-ai-act
- DSIT, AI Cyber Security Code of Practice and Implementation Guide. https://assets.publishing.service.gov.uk/media/679cae441d14e76535afb630/Implementation_Guide_for_the_AI_Cyber_Security_Code_of_Practice.pdf
- NCSC, Guidelines for Secure AI System Development. https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development
- NCSC, “New ETSI standard protects AI systems from evolving cyber threats” (ETSI TS 104 223). https://www.ncsc.gov.uk/blog-post/new-etsi-standard-protects-ai-systems-from-evolving-cyber-threats
- Osborne Clarke, “ICO updates its views on using personal data in generative AI in the UK”. https://www.osborneclarke.com/insights/ico-updates-its-views-using-personal-data-generative-ai-uk
- Covington Inside Privacy, “ICO Shares Early Views on Agentic AI and Data Protection”. https://www.insideprivacy.com/artificial-intelligence/ico-shares-early-views-on-agentic-ai-data-protection/
- Farrer and Co, “AI in the workplace 2026 UK: what employers need to know about the Business and Trade Committee inquiry”. https://www.farrer.co.uk/news-and-insights/ai-in-the-workplace-2026-uk-what-employers-need-to-know-about-the-business-and-trade-committee-inquiry/
- ISO/IEC 42001:2023 and ISO/IEC 42006:2025, discussed in EC-Council, “EU AI Act, NIST AI RMF and ISO/IEC 42001: A Plain English Comparison”. https://www.eccouncil.org/cybersecurity-exchange/responsible-ai-governance/eu-ai-act-nist-ai-rmf-and-iso-iec-42001-a-plain-english-comparison/