In one sentence
Shadow AI is the use of ChatGPT, Claude, Gemini and other AIs outside the official corporate framework. Your salespeople pasting client contracts into ChatGPT, your developers copying proprietary code into personal Cursor, your HR team summarising CVs via NotebookLM. 78% of companies are affected. And most don't know it.
🛡️ Want the complete AI security guide for your company?
SAIF frameworks, OWASP, AI Act, 90-day action plan.
The scale of the phenomenon
The figures are staggering:
Shadow AI: the 2026 figures
The gap: employees massively use unauthorised AIs (78%), but CISOs underestimate the phenomenon (65%). You have 3-4× more Shadow AI than you think.
Mapping: where Shadow AI hides
The 6 reasons why it happens
📚Why your employees bypass IT
1. Official AI is too limited
You deployed Microsoft Copilot? Cool, but it's worse than ChatGPT Plus for many tasks. Employees perceive a degradation in productivity and switch to personal.
Solution: deploy ChatGPT Enterprise or Claude for Work. It costs £30-60/user/month but it's cost-effective.
2. The IT process is too slow
Requesting a new AI takes 3-6 months (validation, contracts, security). In 6 months, 5 new AIs have come out.
Solution: create a fast-track process for AI tools (validation in 2 weeks).
3. Nobody explained the rules
"We have a charter", which doesn't clearly say what's forbidden or not. Many employees DON'T KNOW that pasting client data into ChatGPT is a problem.
Solution: clear, short AI policy + flash training.
4. The productivity gain is real
A salesperson who writes a proposal in 2 hours instead of 8 thanks to ChatGPT, they'll continue. Even if it's forbidden. Productivity pressure will win.
Solution: officially recognise the need + provide an approved tool.
5. Nobody's monitoring
IT has no visibility on the web SaaS tools used by employees. Without a CASB (Cloud Access Security Broker), it's the blind leading the blind.
Solution: deploy a CASB or Zscaler AI Security to see what's happening.
6. AI arrives without us knowing
Notion, Slack, Microsoft 365 add AI features to their existing tools. Your employees use AI without even realising it.
Solution: audit the AI features of all SaaS used. Disable those that pose problems.
Real Shadow AI incidents in 2024-2026
How to detect Shadow AI in your company
The 30-day remediation plan
📚From Shadow AI to controlled AI
Week 1: Diagnosis
Action 1: Anonymous survey (15 min/employee)
- 5-7 short questions:
- Which AI tools do you use for work? - How many times per week? - For what (summaries, code, emails, ...)? - Have you pasted company data into an AI? - Do you know what's allowed?
Action 2: Network logs (1 SOC day)
- List AI domains visited in the last 30 days
- Traffic volume to each
- Identify anonymised "power users"
Result: Shadow AI dashboard to present to the executive committee.
Week 2: Emergency policy
Action 1: Simplified AI charter (1 page)
- ALLOWED list: deployed tools + what you can put in them
- FORBIDDEN list: "NEVER paste into a consumer AI..."
- Identifiable client data (GDPR) - Proprietary code - Contracts, NDAs, patents - Detailed financial data - HR data
Action 2: Communication (executive email + intranet)
- Not guilt-inducing ("we understand you use it")
- Constructive ("here are alternatives, here are the rules")
- Clear objective: amnesty + improvement
Week 3: Tooling
Action 1: Official AI deployment
- ChatGPT Enterprise (£30/user) OR Claude for Work (£60/user) OR Microsoft Copilot (£30/user)
- Configure Data Residency EU (GDPR)
- Configure No training data (API clause)
Action 2: DLP (optional but recommended)
- Block paste of sensitive content to public ChatGPT
- Tools: Calypso AI, Glean, Microsoft Purview
Week 4: Training and follow-up
Action 1: Flash training (1h all, 4h for techs)
- Concrete cases ("Here's what my colleague did, here are the consequences")
- Demo of the official tool
- Validation quiz
Action 2: AI hotline
- "Not sure if you can put X in Y?" → Slack channel #ai-doubts
- Response in <2h during office hours
Action 3: Measurement
- Re-survey at 3 months to measure impact
- KPI: % Shadow AI usage (target <20%)
The trap: don't fall for total prohibition
The metaphor that sums it all up
Absolutely remember
- ✅ 78% of employees use an unauthorised AI at work
- ✅ Risks: data leakage, GDPR, IP loss, AI Act sanctions up to €35M
- ✅ Why: limited official AI, IT too slow, unclear rules
- ✅ Detection: anonymous survey + network logs + CASB
- ✅ 30-day remediation: diagnosis → charter → tooling → training
- ✅ DO NOT ban: govern, that's what works
- ✅ Enterprise tools: ChatGPT Team/Enterprise, Claude for Work, Microsoft Copilot
Shadow AI is not a failure of your employees, it's a failure of your organisation to provide the right tools. Reverse the perspective and you'll find the solution.
What is the approximate percentage of employees using an unauthorised AI at work in 2026?
Go further
- 🛡️ Securing your company against AI, complete CISO guide
- 🎣 AI phishing: the new wave
- 🔒 AI and confidentiality