Shadow AI governance is the practice of finding, assessing, and managing the AI tools employees use without approval. Most organizations do the first half, writing a policy, and skip the second, auditing whether anyone follows it. IBM’s 2025 research found 63% of breached organizations had no AI governance policy, and only 34% of those with one audit for unsanctioned use.
Table of Contents
ToggleWhat Shadow AI Is, and How It Differs From Shadow IT
Shadow AI is the use of AI tools, assistants, and agents inside an organization without security approval or visibility. The category covers a free chatbot open in a browser tab, a personal account signed into a corporate laptop, a browser extension that summarizes documents, and an agent wired into a mailbox through an integration nobody catalogued.
The comparison to shadow IT is useful up to a point and then misleading. Shadow IT was largely a data location problem: a file sat in an unsanctioned place, and someone had to act on it for harm to follow. Shadow AI moves data and delegates judgment at the same time. A summarization tool receives the contract, retains the prompt, and returns an answer an employee may act on without verifying, which means the exposure is both a copy of the data and a decision made on the organization’s behalf.
That second half is what makes shadow AI a workforce risk rather than an asset inventory problem. Employees adopting unapproved tools are not usually trying to cause harm, which places most shadow AI in the category of insider risk that is misguided rather than malicious and changes what an effective response looks like.
How Widespread Shadow AI Is Inside Organizations
Adoption moved faster than almost any workplace technology on record. Verizon’s 2026 Data Breach Investigations Report found 45% of employees are now regular AI users on corporate devices, up from 15% the previous year, and that 67% of those users sign in with non-corporate accounts.
The second figure matters more than the first for governance purposes. A corporate account leaves logs, enforces retention settings, and can be revoked when someone leaves. A personal account does none of that. Two thirds of AI use on company hardware is therefore happening in a place the organization cannot audit, cannot configure, and cannot switch off, which is a materially different problem from employees using a tool the company bought.
Scale alone does not make this urgent. What makes it urgent is that the usage is invisible by construction, so the organizations most exposed are the ones least able to say so. Visibility gaps of this kind are a recurring theme in CISO visibility across security platforms.
What Shadow AI Costs When It Becomes a Breach
IBM’s Cost of a Data Breach Report 2025, conducted with the Ponemon Institute across 600 organizations, put numbers on the exposure.
| Finding | Figure |
|---|---|
| Organizations reporting a breach involving shadow AI | 20% |
| Additional cost where shadow AI levels were high | $670,000 above the average breach |
| Average cost of a shadow AI breach | $4,630,000, against $3,960,000 for standard incidents |
| Organizations with an AI-related incident that lacked proper AI access controls | 97% |
| Breached organizations with no AI governance policy | 63% |
| Policy holders that regularly audit for unsanctioned AI use | 34% |
| Shadow AI breaches involving customer PII | 65%, against a 53% global average |
| Shadow AI breaches involving intellectual property | 40%, against a 33% global average |
One in five breaches now involves shadow AI, and those breaches compromise more sensitive categories of data than the average incident. The data-type skew is the part worth sitting with: shadow AI breaches hit customer records and intellectual property harder than breaches generally, because the data employees paste into an assistant is the data they are working on, and people work on the things that matter.
IBM also reported that 32% of breaches resulted in regulatory fines, with 48% of those fines exceeding $100,000. Broader cost patterns for unmanaged human risk are set out in the cost of ignoring the human layer.
Book a Free
Demo Call
with Our Expert
Discover how Threatcop protects your workforce from modern cyber threats.
Why Is a Written AI Policy Not Governance?
A policy states an intention. Governance is the loop that checks whether the intention survived contact with the workforce, and the IBM figures show where organizations stop. Of breached organizations, 63% had no AI governance policy at all. Among those that did have one, only 34% regularly audited for unsanctioned AI use.
Put those two numbers together and the picture is stark: the large majority of organizations either never wrote the rule or never checked it. A policy nobody audits produces documentation without control, and it can be worse than nothing in a regulatory context, because it establishes that the organization knew the risk and can be asked what it did about it.
The audit half is skipped because it is genuinely harder. Writing an acceptable-use policy takes an afternoon. Establishing which of 4,000 employees pasted client data into an unapproved assistant last quarter takes instrumentation, a definition of what counts, and a decision about what happens when the answer is uncomfortable. Governance disciplines that survive that test are discussed in strategic governance and a risk-aware culture.
The Friction Gap That Drives Employees to Unapproved Tools
Employees adopt shadow AI for a reason that is consistent enough to be treated as a design input: the approved path is slower than the unapproved one. When the sanctioned assistant requires a ticket, lacks the model the team needs, or blocks the file type they work in, the free tool in the browser wins on the only metric the employee is measured against, which is getting the work done.
That has a direct governance consequence. A shadow AI rate is not only a compliance number, it is a measurement of the gap between what the organization provides and what the work requires. A department with 70% unapproved usage is reporting a procurement failure as much as a discipline failure, and treating it purely as the second guarantees the behavior moves further underground.
Enforcement-first responses tend to produce exactly that. Blocking domains moves usage to personal phones, where no log exists at all, and disciplinary framing suppresses the self-reporting that would otherwise give security teams their cheapest source of visibility. Building the opposite instinct is the subject of incident reporting culture.
How to Build a Shadow AI Inventory Without Blocking Everything
Discovery does not require perfect visibility on day one, and waiting for a complete picture is how organizations stay at zero. The sequence below produces a usable inventory in weeks rather than quarters.
| Step | Action | Output |
|---|---|---|
| 1 | Pull authentication and egress logs for known AI domains, then widen the list monthly as new tools appear | A first-pass list of tools in use and rough volumes |
| 2 | Survey the highest-exposure functions directly, with amnesty stated in writing | Named tools, and the task each one is solving |
| 3 | Inventory browser extensions and OAuth grants against corporate accounts | Agents and integrations holding standing access |
| 4 | Classify each tool by data sensitivity it touches and whether it can act, not just read | A risk-ranked list rather than an alphabetical one |
| 5 | Approve or provide an equivalent for the highest-volume legitimate use cases | A sanctioned path that competes on speed |
| 6 | Train the roles the inventory surfaced, on the specific tools they actually use | Role-level coverage, evidenced |
Step 2 is where most of the value sits and where most programs flinch. An amnesty window produces more accurate data in a fortnight than log analysis produces in a quarter, because employees know what they use and logs only know what they can see. Amnesty has to be real, though: one disciplinary action taken on survey data ends the honest reporting permanently.
Threatcop’s TLMS carries step 6, delivering role-based content on the specific tools a function uses and reporting coverage by role, so the people who showed up in the inventory are the people who get trained rather than the whole workforce receiving one generic AI module. Approaches to scoping that kind of program are covered in human risk management.
Step 3 catches the category that carries the most authority. An OAuth grant to a mailbox persists after the employee stops thinking about it, which places it closer to third-party data breaches than to casual tool use, and it survives password changes that people assume revoke access.
Metrics That Show Whether Shadow AI Governance Is Working
Six measures tell a board or an auditor whether the loop is closed, and none of them is a policy acknowledgement rate.
| Metric | What it reveals |
|---|---|
| Known AI tools in use, by function | Whether discovery is running or stalled |
| Ratio of sanctioned to unsanctioned usage volume | Whether the approved path is winning on merit |
| Share of AI sessions on corporate rather than personal accounts | Whether usage is auditable at all |
| Standing OAuth grants and agent integrations, reviewed quarterly | Delegated authority nobody is tracking |
| Time from a new tool appearing to a classification decision | Whether governance keeps pace with adoption |
| Voluntary disclosure rate after an amnesty | Whether the culture supports visibility |
Two of these deserve a note on how to read them. A rising count of known AI tools is a good sign early in a program and a bad sign later, because it means discovery is working before it means adoption is sprawling. A falling voluntary disclosure rate almost never means shadow AI stopped; it usually means something happened to make disclosure feel unsafe. The second and third measures are the ones to watch over time, because they move when the underlying behavior changes rather than when documentation is refreshed. Selecting measures that behave this way is covered in metrics for a human risk program and in why an employee risk score matters.
Where Shadow AI Collides With Regulatory Obligations
Shadow AI creates exposure under regimes that were not written with AI in mind. Data protection law is the immediate one: pasting customer records into a consumer assistant is a disclosure to a third-party processor with no contract, no documented transfer basis, and no retention control, which is a problem under GDPR and under India’s Digital Personal Data Protection Act alike.
Sectoral rules compound it. An organization that must evidence where regulated data resides cannot do so when an unknown share of it has been sent to model providers outside its control, and IBM’s finding that shadow AI breaches disproportionately involve customer PII means the collision is not theoretical. Breaches spanning multiple environments also took the longest to identify and contain, at 276 days.
There is also a training obligation now attached. Where the EU AI Act applies, deployers must take measures supporting AI literacy among the people operating AI systems on their behalf, and an organization that cannot name which systems those are cannot evidence that its measures matched them. Governance and behavioral evidence are increasingly the same artifact, a point developed in longitudinal behavior profiling and AI governance.
Start With Discovery, Not With the Policy
Most organizations write the AI policy first because it is the artifact that can be produced in a week. Run discovery first instead. The inventory will tell you which rules are worth writing, which functions need them most, and where the approved path is losing to the free one, and a policy built on that evidence stands up to questions the generic version cannot answer.
Once the inventory names the roles, the training has somewhere to land. Deliver role-specific AI use content to the functions the discovery surfaced, in the languages your teams work in, and report coverage by role so governance has behavioral evidence behind it rather than an acknowledgement log.
Frequently Asked Questions
What is shadow AI?
Shadow AI is the use of AI tools, assistants, or agents within an organization without security approval, procurement review, or visibility. It includes consumer chatbots accessed through personal accounts, browser extensions, and agents connected to corporate systems through integrations that were never catalogued. The defining characteristic is that the security team cannot see the tool, the data going into it, or the access it holds.
How common is shadow AI in the workplace?
Verizon’s 2026 Data Breach Investigations Report found 45% of employees are regular AI users on corporate devices, up from 15% a year earlier, and that 67% of them sign in using non-corporate accounts. IBM’s Cost of a Data Breach Report 2025 found 20% of organizations suffered a breach involving shadow AI, making it one of the fastest-growing breach factors on record.
Why is shadow AI more dangerous than shadow IT?
Shadow IT was primarily a data location problem, where files sat somewhere unsanctioned until someone acted on them. Shadow AI both moves data and delegates judgment, because employees act on outputs they have not verified and agents can take actions under an employee’s identity. An unapproved agent connected to a mailbox holds standing access that persists long after anyone remembers granting it.
Can blocking AI tools solve shadow AI?
Blocking rarely solves it and often makes visibility worse. Domain blocks move usage to personal phones and home devices where no corporate log exists, and disciplinary framing discourages the voluntary disclosure that gives security teams their cheapest source of discovery. Providing a sanctioned tool that competes on speed with the unapproved one addresses the reason people route around the policy.
What should an AI acceptable use policy contain?
At minimum: which tools are approved and for what tasks, which data categories may never be entered into any AI system, the rule on personal versus corporate accounts, the requirement to verify outputs before acting on them, the approval path for new tools, and the process for disclosing tools already in use. A policy without an audit mechanism attached documents intent rather than establishing control.
Adhish Chakma is a Senior Product Manager at Kratikal, where he leads product initiatives focused on cybersecurity and AI-powered solutions. With experience in product management and cybersecurity, he works on developing practical technologies that address evolving security challenges. His areas of interest include People Security Management, cybersecurity awareness, AI-driven security, email security, and human-layer risk. He is passionate about building security products that make organizations more resilient against emerging cyber threats.
Adhish Chakma is a Senior Product Manager at Kratikal, where he leads product initiatives focused on cybersecurity and AI-powered solutions. With experience in product management and cybersecurity, he works on developing practical technologies that address evolving security challenges. His areas of interest include People Security Management, cybersecurity awareness, AI-driven security, email security, and human-layer risk. He is passionate about building security products that make organizations more resilient against emerging cyber threats.
