What Is Shadow AI?
Shadow AI is the use of AI tools, models, plugins, or embedded AI features by employees without the knowledge, review, or approval of an organization's IT or security teams. It includes everything from pasting a client contract into a free chatbot to summarize it, to installing a browser extension that quietly runs AI over whatever page is open, to using an AI coding assistant that wasn't vetted or licensed by the company.
It is the AI-era evolution of shadow IT — the older problem of employees using unapproved software or cloud services. But shadow AI carries a distinct risk profile: the tools involved don't just store or transmit data, they actively process it, generate new outputs from it, and in many cases retain it to improve a third party's model. That difference is why security and compliance teams increasingly treat shadow AI as a separate risk category rather than a subset of shadow IT.
How Big a Problem Is Shadow AI in Large Enterprises?
Direct answer: Shadow AI affects the large majority of large enterprises today, not a minority. Multiple 2026 industry surveys put unsanctioned AI usage among employees in the 60–90% range depending on how usage is defined, while only a small fraction of organizations report having formal AI usage policies or full visibility into what's actually running. The gap between adoption and governance — not the existence of AI use itself — is what defines the scale of the problem.
The pattern behind that gap is consistent across research: employee AI adoption moved far faster than enterprise governance could follow. According to Salesforce's 2026 Workforce AI Survey, 67% of employees now use AI tools at work, while only 18% of organizations report having formal AI security policies in place. PagerDuty's 2026 international Shadow AI Survey, conducted among 1,250 office professionals at companies with $500 million or more in annual revenue across Australia, Japan, the UK, and the US, found that two-thirds of office professionals had used unauthorized AI tools at work.
Three structural factors explain why the gap keeps widening rather than closing:
Consumer AI products are not built for enterprise governance. Most of the tools employees reach for were designed to ingest data and improve on it — not to support enterprise retention controls, audit trails, or data lineage documentation.
Shadow AI hides inside tools that are already approved. Many organizations have reasonably tight control at the application layer and almost no visibility into the AI functionality quietly running inside the background of SaaS products their teams already use — an embedded summarization feature, an AI-powered search bar, a "smart" autocomplete calling an external model.
Employees are solving a real problem, not creating a reckless one. When a task that used to take two hours can be done in two minutes with an unapproved tool, most employees will use it — not out of disregard for policy, but because the sanctioned alternative doesn't exist or doesn't work as well.
Shadow AI Statistics: What the Data Shows in 2026
The numbers below are drawn from named, dated studies. Where a figure comes from a survey rather than measured incident data, that distinction is noted, since the two aren't interchangeable.
Breach and incident data (IBM, 2026 Cost of a Data Breach Report): Shadow AI-linked security incidents rose from 20% to 43% of AI-related breaches year over year, based on Ponemon Institute research across 602 breached organizations in 17 industries and 16 countries between March 2025 and February 2026. The average cost of a breach involving shadow AI reached $5.39 million. Sixty-eight percent of breached organizations had no policy in place to govern AI use or manage shadow AI, and 92% of organizations that experienced an AI-related breach lacked adequate AI access controls. Separately, one in four malicious breaches in the same study were AI-enabled — deepfake impersonation, AI-generated malware, and AI-crafted phishing — a 56% increase year over year, with those attacks averaging $6 million per breach.
What this means for enterprises: these are not projections. They're measured outcomes from organizations that had already been breached, which makes the governance gap IBM documents — most breached organizations had no AI oversight policy at all — the more urgent number in the data set.
Employee adoption data (Salesforce, 2026 Workforce AI Survey): 67% of employees report using AI tools at work; only 18% of organizations report having a formal AI security policy.
Employee adoption data (PagerDuty, 2026 Shadow AI Survey): 66% of office professionals at large enterprises (revenue $500M+) report having used unauthorized AI tools at work, based on a survey of 1,250 professionals across four countries.
Healthcare-specific data (Wolters Kluwer, 2026): 40% of healthcare professionals report encountering unauthorized AI tools in the workplace, nearly 20% admit to using them, and roughly one in ten report using an unauthorized AI tool in a direct patient-care context.
Legal-specific data (Thomson Reuters, 2024): 45% of legal professionals reported using consumer AI tools for work tasks — a figure worth tracking forward given how quickly adoption has moved since, but the most recent verifiable figure available for the sector.
Data-loss pattern data (Verizon, 2026 Data Breach Investigations Report): Analysis of 858,440 DLP events involving uploads to generative AI tools found source code was the single most common data type uploaded to unauthorized AI systems, ahead of images and structured data.
What this means for enterprises: the risk isn't evenly distributed. Source code exposure concentrates in technology and engineering functions; patient-context exposure concentrates in healthcare; privileged-information exposure concentrates in legal. A generic, one-size-fits-all shadow AI policy misses where the actual exposure sits inside a given organization.
Treat any shadow AI statistic — including the ones above — as a snapshot, not a constant. Given how quickly adoption is moving, figures from even a year prior likely understate current exposure.
What Are the Biggest Shadow AI Security Risks?
Direct answer: The most significant shadow AI risks are sensitive-data leakage into third-party systems with no enterprise retention controls, loss of audit trail and accountability for AI-influenced decisions, unauthorized AI agents taking real actions rather than just generating text, and a widening gap between what regulators expect organizations to document and what shadow AI usage actually allows them to prove.
Sensitive-data leakage. When an employee pastes customer records, financial data, or unreleased product information into an unauthorized AI tool, that data typically leaves the organization's control entirely — often to a vendor with no contractual data-handling agreement with the enterprise at all.
PII and confidential business information exposure. Personal information, pricing models, M&A discussions, and internal strategy documents are all common categories that end up inside shadow AI prompts, frequently without the employee registering it as a data-handling decision at all.
Intellectual property and source-code exposure. As Verizon's 2026 DBIR data shows, source code is the single most common category of data uploaded to unauthorized AI tools — a direct threat to competitive position when that code represents proprietary logic, algorithms, or product architecture.
Credential exposure. API keys, service account credentials, and access tokens are sometimes pasted into AI tools alongside code or configuration files being debugged — turning a productivity shortcut into a potential system-access vulnerability.
Insecure or malicious AI applications. Not every AI tool employees find is a legitimate product with reasonable security practices. Some browser extensions and AI-branded apps are built specifically to harvest the data passed through them.
Prompt injection. Attackers can embed hidden instructions in content an AI tool processes — a webpage, a document, an email — that hijack the tool's behavior. Shadow AI tools, deployed without security review, typically have no defenses against this at all.
Third-party data retention. Many consumer AI products retain submitted data to improve their models by default, meaning information an employee considered a one-time query may persist indefinitely in a system the enterprise has no visibility into or control over.
Unauthorized AI agents. An agent that can take actions — not just generate text — introduces risk that scales with what it's connected to: the files it can access, the systems it can call, the workflows it can trigger.
AI supply-chain risk. Shadow AI tools often rely on their own third-party model providers and subprocessors, meaning the enterprise inherits risk from vendors it never assessed and may not even know exist.
Insecure APIs. Background AI features embedded in approved SaaS tools frequently call external APIs the security team never reviewed, creating exposure that looks, from the outside, like normal application traffic.
Compliance violations. Regulations like the EU AI Act and GDPR increasingly expect documented data lineage and AI usage governance; shadow AI usage makes that documentation impossible to produce accurately, regardless of what internal policy says on paper.
Inaccurate outputs feeding real decisions. When shadow AI tools generate wrong or fabricated information that quietly informs a business decision, the resulting risk is often invisible until the decision's consequences surface.
Lack of monitoring. Every risk above is compounded by the same root problem: without visibility into which tools are in use, security and compliance teams cannot assess exposure, let alone respond to an incident in progress.
What Does Shadow AI Cost Enterprises?
Shadow AI's cost shows up in more places than a single breach line item. It's useful to separate direct financial costs from indirect business costs, since they call for different responses.
Direct financial costs:
- Breach and incident costs. IBM's 2026 research puts the average cost of a breach involving shadow AI at $5.39 million — measurably above the overall average breach cost of $4.99 million reported in the same study.
- Regulatory fines. IBM found regulatory fines occurred in roughly one in five AI-related breach incidents, adding direct financial exposure on top of remediation costs.
- Redundant and unauthorized subscriptions. Individual employees and teams frequently pay for AI tools out of expense accounts or personal cards, creating duplicate spend the organization has no visibility into and no negotiating leverage over.
- Uncontrolled API costs. Where shadow AI usage runs through pay-per-use APIs rather than flat subscriptions, costs can scale unpredictably with usage the organization isn't tracking.
- Incident response and remediation. Investigating and containing a shadow AI-related exposure typically costs more than a routine incident, precisely because there's no existing inventory of what tool was used, what data it touched, or who else may have used it.
Indirect business costs:
- Audit and compliance overhead. Reconstructing what data went where, after the fact, is dramatically more expensive than maintaining that documentation as a byproduct of a governed AI environment from the start.
- Productivity losses from fragmented tooling. Ironically, the same organizations exposed to shadow AI risk often aren't capturing shadow AI's productivity upside efficiently either — value is scattered across unmanaged, uncoordinated tools rather than consolidated into tools the whole organization can build on.
- Vendor sprawl. Every unauthorized tool is a vendor relationship the organization has implicitly entered into without due diligence, multiplying the number of parties with some claim on enterprise data.
- Reputational and trust costs. These are the hardest to price precisely and often the most consequential — a publicized shadow AI-linked exposure of customer or patient data affects trust in ways that outlast the direct financial remediation.
- Strategic risk. Decisions made on the back of unverified or ungoverned AI outputs carry a cost that may not surface until well after the decision itself, when the underlying error becomes apparent.
None of these figures should be treated as fixed. They vary meaningfully by industry, data sensitivity, and existing governance maturity — the ranges above are directional, not a forecast for any specific organization.
Which Industries Are Most at Risk From Shadow AI?
Direct answer: Healthcare, financial services, legal, and technology sectors face the highest shadow AI exposure, because each handles data categories — protected health information, regulated financial records, privileged client communications, and proprietary source code — where unauthorized AI exposure creates not just a security incident but a specific regulatory or professional liability.
Healthcare. Patient information, clinical notes, and treatment data are subject to strict regulatory protection, and unauthorized AI use in clinical or administrative workflows creates direct compliance exposure. Wolters Kluwer's 2026 research found roughly one in ten healthcare professionals had used an unauthorized AI tool in a direct patient-care context — a use case where an inaccurate or ungoverned AI output carries consequences well beyond a typical data-handling policy violation.
Financial services and insurance. Customer financial records, transaction data, and underwriting information sit under some of the most detailed regulatory requirements of any sector. Unauthorized AI processing of this data creates exposure not just to data breach rules but to sector-specific financial regulation governing how customer data can be processed and by whom.
Legal. Attorney-client privilege and confidentiality obligations mean that pasting case details or client communications into a consumer AI tool isn't just a data-handling risk — it can jeopardize privilege itself. Thomson Reuters' 2024 research found 45% of legal professionals had used consumer AI tools for work tasks, a figure that underscores how normalized the behavior had already become before most firms had formal AI policies in place.
Technology. Source code, product roadmaps, and technical architecture represent an organization's core competitive position. Verizon's 2026 DBIR analysis of AI DLP events found source code was the leading data category uploaded to unauthorized generative AI tools — a direct line from shadow AI usage to intellectual property exposure.
Government and public sector. Citizen data, security-classified information, and public trust obligations make unauthorized AI use in government workflows a governance issue with implications beyond any single agency.
Professional services. Consulting, accounting, and advisory firms routinely handle multiple clients' confidential strategic and financial information simultaneously, multiplying the exposure surface of any single unauthorized AI interaction.
Manufacturing. Proprietary designs, supply-chain data, and operational technology information create intellectual property and, increasingly, operational-security exposure when processed through ungoverned AI tools.
Education. Student records and research data — often protected under sector-specific privacy rules — face growing exposure as AI tools spread informally through both administrative and academic use.