3 Sources
[1]
Think Twice Before Using That Unsanctioned AI App at Work
Barbara is a tech writer specializing in AI and emerging technologies. With a background as a systems librarian in software development, she brings a unique perspective to her reporting. Having lived in the USA and Ireland, Barbara now resides in Croatia. She covers the latest in artificial intelligence and tech innovations. Her work draws on years of experience in tech and other fields, blending technical know-how with a passion for how technology shapes our world. You know that moment when you ask ChatGPT to polish a work email or summarize meeting notes? It may seem harmless at first, but using the wrong tool or giving it the wrong information can create a much bigger problem. Shadow AI is what happens when people use artificial intelligence tools at work without company approval, oversight or security review. That could be ChatGPT, Gemini, an AI note-taker during a meeting, an image generator or some other tool you opened because it helped you finish something faster. Most people aren't trying to leak company secrets or do anything nefarious. They're doing it because work is full of long documents, messy spreadsheets, meeting notes and wordy emails. But the road to hell is paved with good intentions. Once you put work information into an unapproved AI tool, your company may lose control over where that information goes, how it's stored and whether anyone can protect it. "Once the proprietary sensitive and confidential data is out, it's out," Edward Wu, founder and CEO of Dropzone AI, told CNET. That's why shadow AI is becoming one of the trickiest workplace AI problems. It can save time, but it can also move company information to somewhere your employer can't control it. Let's break down what this means for you and how to use AI at work without creating a mess for yourself or your company. What is shadow AI? "Ultimately, shadow AI is the usage of AI tools that have not been preapproved, reviewed and sanctioned by the IT and security team," Wu said. It's similar to shadow IT, which is when employees use unapproved apps or software at work. That's usually where the trouble starts. Not because you used AI to clean up a sentence, but because you gave it something your company would rather keep private. A quick shortcut can turn into an accidental data leak. That could be customer names, internal documents, source code or financial information. That doesn't mean every use of AI at work is dangerous. Asking AI to rewrite a generic email is different from pasting in a customer complaint or a legal memo. Approved AI tools usually come with privacy controls, security settings and rules about what happens to your data. A random free tool may not. Even if the tool says it doesn't train on your data, you may not know how long it stores your prompt or who can access it. "When you have your entire codebase and copy and paste it into a free-tier AI tool, you bet that code is going into training data immediately, and there's no way to undo that," Wu told CNET. Why people use shadow AI Let's be honest, AI tools are useful. That's the uncomfortable truth. Generative AI can help you draft emails, summarize reports, record meeting notes, clean up messy text, analyze data and brainstorm ideas. Those tasks eat up huge parts of the workday, and AI tools often feel faster than waiting for your company to approve something official. Microsoft's 2026 Work Trend Index shows why workers keep reaching for AI. The report found that 58% of respondents said it helps them take on tasks they couldn't have handled a year ago. Wu tells CNET that's the point companies shouldn't ignore. "The existence of shadow AI means there is productivity to be gained by certain functions. I don't think people are using AI tools for fun at work," Wu said. Employees are moving faster than company policies. Some workplaces still don't have clear AI rules. Others have rules buried in security documents no one reads unless they're already in trouble. Some companies ban public AI tools but don't offer a useful alternative. Shadow AI also doesn't always look like a separate app. It can live inside a browser extension, email plug-in, search engine, spreadsheet assistant or meeting recorder. You may think you're just clicking the helpful button, not using AI. When you're under pressure to do more with less, the free chatbot sitting in the next AI browser tab starts to look tempting. The risks companies see in shadow AI One small shortcut can expose more than you meant to share. "I think the biggest risk, obviously, is kind of uncontrolled data exposure," Wu said. AI tools need context to work well. That context might include internal tickets, documentation, customer details, contracts and code. Once that information is entered into an unapproved tool, the company may be unable to track it or retrieve it. IBM's 2025 Cost of a Data Breach Report found that 20% of organizations had unauthorized AI tools in their environments, while 63% had no AI governance policy or were still developing one. That's another sign that companies are still catching up to how fast AI is being used. AI output can also sound right even when it isn't. That's called an AI hallucination. A chatbot can summarize the wrong point, invent a detail, miss context or produce a confident answer that falls apart once someone checks it. If you use that output in a financial analysis or technical document, the shortcut may create more work than it saves. If AI-generated work goes out with false details, private information or sloppy mistakes, your company may not only have to fix the error but also deal with reputational damage. Being put on the internet wall of shame nowadays can come with a hefty price. For example, Deloitte faced public backlash and a mandatory review after submitting a million-dollar government report that contained fabricated, AI-generated research citations. The net consequence is clear: A tool that saves you 10 minutes can create a problem your company spends weeks cleaning up. Lawyers have already learned this the hard way after filing court documents with fake AI-generated case citations. Why banning AI usually doesn't work "Banning AI tools generally pushes more people to go kind of underground," Wu said. "Very similar to when parents tell teenage kids to stop using Instagram. That kind of never works." If you know AI can save time and your company doesn't provide a useful approved option, you may look for another way. You might use a personal account, your phone, a browser plug-in or a tool that looks harmless enough to slip by. A better policy focuses on what you're using AI for and what data you're putting into it. Your company might allow AI for brainstorming or summarizing public information, while banning customer data, confidential documents, unreleased product plans, financial records or source code in public tools. "[The] marketing team may feel free to use AI tools to generate images, right?" Wu said. "But you know, customer success team, please don't copy-paste customer interactions directly into unsanctioned tools." That kind of rule works better because it tells you where the line is. Wu says it's hard for individual workers to self-police what's appropriate, especially when AI tools have different privacy settings that aren't always obvious. "If things are not clearly spelled out, then it's left for interpretation," Wu said. Companies need clear guidelines that explain which tools are approved, which data is off-limits and which tasks require human review. What to do if you use AI at work If you use AI at work, assume anything you paste into a tool is out there forever. Check whether your company has an approved AI tool or policy. Don't upload sensitive, internal information in public tools or anything marked confidential, unless your company has explicitly allowed it. If you're not sure, don't paste it. Treat AI like Santa's little helper, but don't outsource your intelligence. Check facts, verify summaries, rewrite awkward lines and make sure the final version still sounds like a person who knows what they're talking about. While AI may have done the writing or summarizing, remember that it's your reputation -- or your company's -- at stake if there are mistakes. Shadow AI exists because people have found tools that help them work faster. That's not going away. The real challenge is making sure the shortcut doesn't turn into a security problem or one very awkward meeting with IT and HR.
[2]
'You fix it by making the secure option just as fast and frictionless as the risky one': Practical advice on addressing shadow AI
'AI is a basic utility': Enterprise-grade AI should be frictionless AI's timeline is very much still being written, but one thing is clear - companies are now in the midst of shifting from experimentation to widespread implementation after having determined strong use cases, with security and trust now becoming higher priorities. The question is no longer about whether employees are willing to embrace AI, because that much is clear. It's now about whether their employers know how AI tools are actually being used, whether they're providing the right type of solutions, and whether their governance supports real-world use cases. Off the back of that, companies are now struggling to tame shadow AI as workers go off to explore their preferred tools, rather than being confined to workplace-provided alternatives. But while organizations have years of experience handling shadow IT, shadow AI is presenting new challenges. Shadow AI is harder to tame than Shadow IT - gaining visibility is the first step Rather than being blocked from downloading certain software, workers can almost painlessly head to their chosen AI tool directly from the browser or via a personal account without approval or restrictions. As much as two-thirds (67%) of enterprise AI use now takes place through unmanaged personal accounts, even when an organization already provides enterprise-grade licenses. But those sanctioned AI tools are clearly working for employees, who are seeing higher productivity. At the end of the day, this is a major win for companies who are under pressure to prove ROI, but shadow AI presents security risks that enterprise-grade software generally negates. Teramind has revealed that 86% of organizations lack visibility into how data moves to and from AI tools, and it's not just knowledge workers who are to blame. Nearly seven in 10 C-suite execs also admitted to prioritizing speed over security. I spoke with Teramind VP of Strategy Leeron Walter to understand why shadow AI has become more of an issue than we might've thought, and what organizations can realistically do to regain visibility and control while continuing to meet workers where they feel most comfortable and productive. * How do you define shadow AI, and why does it happen inside approved tools? Shadow AI is any AI usage that operates outside organizational visibility and governance - whether through banned apps, personal accounts, or AI features embedded in tools you already pay for. The reason it's hiding inside approved platforms is simple: vendors are racing to embed AI into everything. Your licensed Microsoft 365, your PDF reader, your CRM - they all have AI features now. Our research shows 67% of enterprise AI usage runs through unmanaged personal accounts on corporate-licensed platforms. The perimeter didn't move. It dissolved. * Do executives actually follow the AI policies they sign off on? Not always. Our data is unambiguous: 69% of C-suite leaders prioritize speed over security when using AI tools, versus just 37% of frontline employees. Executives feel competitive pressure more acutely, so they rationalize bypassing policies. * What goes through an employee's head when they choose productivity over compliance - and can companies change that? They're doing a fast cost-benefit calculation: "Missing this deadline hurts me now. A data breach is someone else's problem later." 60% of employees in our research said productivity benefits outweigh security risks when deadlines are involved. You don't fix that with more restrictions - 48% said they'd use AI even if it were explicitly banned. You fix it by making the secure option just as fast and frictionless as the risky one. Remove the tradeoff entirely. * Is Gen Z really more likely to work around AI rules? Yes, but not because they're reckless - because they're impatient with policies that feel arbitrary. For them, AI is a basic utility, like a search engine. Blocking it doesn't register as a security measure; it registers as the company being behind. Meet them with speed and enablement, not bureaucracy. * Why do traditional DLP tools miss AI traffic? Because they were built to catch files moving, not ideas being processed. Shadow IT was about unauthorized storage - a file uploaded to Dropbox. Shadow AI is about unauthorized processing - sensitive data pasted into a chat prompt. There's no file transfer to intercept. The data moves through an encrypted browser session, and legacy DLP tools are pattern-matching against file types and network transfers, not semantic content in a chat box. The threat model changed; the tools didn't. * What does the first 90 days of gaining AI visibility actually look like? Days 1-30: Observe, don't block. Deploy behavioral telemetry to build a full Shadow AI inventory - browser extensions, clipboard activity, personal account usage inside approved platforms. Understand what's actually happening before you touch anything. Days 31-60: Categorize risk. Which tools train on user data? Which departments depend on them? This is when you find out Engineering lives in an unvetted coding assistant. Days 61-90: Enable and enforce. Roll out approved alternatives for high-risk tools. Implement real-time coaching - block the risky action, surface the safe alternative immediately. Goal: not zero AI usage, but 100% visible AI usage. * What does an enablement-first AI approach actually look like - and how do you stop it becoming shadow AI with extra paperwork? You build paved roads. Give employees a fast, secure, approved AI path so they don't need to go off-road. That means enterprise AI tools with zero-retention data policies, integrated into existing workflows - not buried in a separate portal. To avoid it becoming theater, your AI tool approval process needs to be agile. If the review takes six months, employees use the consumer version today and say nothing. Govern the data, not the application - allow the tool, but monitor and control what data flows through it in real time. Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
[3]
Shadow AI - over-confidence and complacency are a toxic enterprise mix with disaster just around the corner...
A US financial services firm has provided a useful reminder of the dangers of the encroachment of Shadow AI within the enterprise, but will anyone listen? Pennsylvania-based CB Financial Services revealed in a recently-filed material cybersecurity Form 8-K with US regulators that employees were able to use un-authorized AI to bypass IT firewalls, resulting in the accidental disclosure of customer names, social security numbers and dates of birth. It wasn't even, it appears, an intentional act - an employee put such sensitive data into an unauthorized chatbot to save time. According to the filing, on this occasion the incident did not involve a disruption to the bank's operations, customer access to accounts or services, payment systems, or core information technology infrastructure. But the volume and sensitive nature of the non-public information concerned raised warning flags internally. It's clear this could have been a lot worse and CB Financial Services have now launched internal reviews to ensure it can't happen again, but similar incidents are likely to become increasingly common as users within organizations become more and more exposed to AI as part of their working lives. Impatient/unsatisfied with the sort of corporate AI they're offered compared to the stuff they use in their consumer lives, the temptation will grow to 'bring their own' into the workplace. This places a burden on the IT and governance teams to ensure that operational guardrails and processes are in place to rein this in. Cross-sector issue It's happening across all business sectors, including some that are highly-regulated and handle enormously sensitive personal data. According to the 2026 Nutanix Healthcare ECI study, an international poll of 1,600 cloud, IT, and engineering execs, Shadow AI is rife and largely unmanaged. Seventy-nine percent of healthcare organizations report AI applications or agents being implemented by employees in non-IT functions. The dangers associated here are appreciated - some 83% believe that AI tools and agents operating outside official oversight create business risk. So why is it happening? It's down to organizational barriers, as the most common reason cited. Silos between business units and IT make it difficult to effectively execute technology initiatives, according to 83% of respondents. A second study, Writer's 2026 AI Adoption In The Enterprise survey, backs up the threat Shadow AI exposes organizations to. Sixty-seven percent of respondents here say their company has already suffered a data leak or breach due to un-approved AI tools. Seventy-nine percent say AI applications are being created in silos with individual departments deploying AI tools independently. Meanwhile 35% of employees admit to entering proprietary information into public AI tools. Some 40% say they'll just use whatever it takes to get job done, while 32% think IT-approved tools are terrible. And nothing is being done about it, it seems. Fifty-five percent describe AI use as a "chaotic free-for-all" at their company, 36% don't have any formal plan for supervising AI agents, and 35% wouldn't be able to shut down a rogue agent if it was detected. And over a fifth of respondents (21%) claim that their manager knows what's happening, but turns a blind eye to it! So what are organizational leaders playing at here? Is this really wilful blindness or 'rabbit in the headlights' panic at an oncoming storm? Identity management firm Okta's AI Agents at Work 2026: Securing the agentic enterprise report may provide some insight here. Surveying 292 executives and 492 knowledge workers across seven countries, the findings suggest that leaders vastly under-estimate the prevalence of Shadow AI, and thus the risk levels to which they are exposed. It seems to be a potent combination of over-confidence and complacency at play here. An overwhelming 90% of those polled said they have confidence in their organization's visibility into AI tools, while even more (95%) assume their employees are using AI responsibly. This despite the data also finding that over half (52%) of knowledge workers admit to using unsanctioned AI tools at work, nearly a quarter (24%) admitting to doing so regularly. Of those using unapproved AI tools, the top three most-shared types of information included internal messages and emails (54%), HR-related information (45%), and confidential company documents, including financials and contracts (39%), just the sort of thing to land you on the receiving end of a lawsuit or unwanted regulatory attentions. Meanwhile over 20% of those using un-approved tools are also sharing login credentials and passwords, and 28% are sharing banking and payment information, throwing open the corporate window to external cyber-attack from bad actors. What to do? So is there a need for the immediate introduction of draconian governance regimes to clamp down on all this? Bill Patterson, EVP of Corporate Strategy at Salesforce, suggests: 'Bring your own AI' is not something I think many IT organizations want to think about, because it creates a security risk for companies. And then also, ubiquitous access of AI means that a lot of people are just using the tool for the wrong purpose and job. I don't know if I think of it necessarily in the world of governance and control. I definitely think of it as maybe appropriate use and economic value, and so I do think this means that, you know, we probably need to help companies navigate this moment. Fo his part, Mark Williams, COO, Sharp UK, argues: Trust and clarity are key to implementing AI in the most effective way, right from the C-Suite down to every layer of business operations. Businesses must create the frameworks and shared understanding of what good AI use looks like to enable them to lead by example. These aren't the concerns of people resisting AI. They're the concerns of people trying to navigate it without enough support and enablement to get the most from these tools. Williams notes that a sizeable chunk of business leaders do already recognise the risk., but adds: The gap between recognising it and doing something about it is where the real work is. This about culture and mindset, and leaders are in the best position to set the tone on this. Not by having all the answers, but by being open about how they're using AI themselves. This changes habits faster than any policy. My take One of the ironies here is that it was Shadow IT that took many of today's SaaS leaders into the enterprise landscape on 'land and expand' missions that lead to their market dominance over the legacy contenders, when employees swiped a credit card to access a Salesforce or a Workday rather than use the aging installed alternative. But that's a history lesson that is too risky to repeat with powerful AI technologies. Every organization needs to wake up to the reality of the dangers of Shadow AI to their organizational, reputational, and operational integrity. Is it going to take a massive public failure by some hapless enterprise to scare them into action? In the meantime, we could do worse than try to follow some steps suggested by management consultancy KPMG on this topic: * Create a dedicated AI transformation organization or authority to govern strategy, architecture, tools, trust, and standards across the business. * Develop clear AI governance policies - and stick to them! * Use discovery tools and platforms to maintain a tight inventory of AI tech across the enterprise. * Create a cross-functional AI technology review steering committee to ensure cross-enterprise alignment. * Stand up an AI labs function as a sandboxed realm in which teams can dabble with new AI tech safely, reducing the scope for unsanctioned experimentation. * Allow 'bring your own AI' only within strictly-approved boundaries, such as enabling staff to choose from a curated list of vetted generative AI tools, for example. * Promote education and awareness of AI risk, security principles, and the importance of data governance. * Encourage a culture of transparency whereby employees can safely share ideas and experiences of AI tech use.
Share
Copy Link
Shadow AI is spreading across organizations as employees turn to unauthorized AI tools for productivity gains, often without IT approval. Recent incidents show the risks: CB Financial Services accidentally leaked customer social security numbers through an unapproved chatbot. With 67% of enterprise AI use happening through unmanaged personal accounts, companies face a critical challenge balancing worker productivity with data security.
Shadow AI has become one of the most pressing workplace AI risks facing organizations today. The term describes what happens when employees use AI tools without company approval, oversight, or security review
1
. This could mean using ChatGPT to polish emails, Gemini for document summaries, or any number of unsanctioned AI apps at work that promise to speed up daily tasks. While most employees aren't attempting anything malicious, the consequences can be severe. "Once the proprietary sensitive and confidential data is out, it's out," Edward Wu, founder and CEO of Dropzone AI, told CNET1
.
Source: diginomica
The scale of the problem is staggering. Research from Teramind reveals that 67% of enterprise AI use now takes place through unmanaged personal accounts, even when organizations already provide enterprise-grade licenses
2
. More troubling still, 86% of organizations lack visibility into how data moves to and from unauthorized AI tools2
. This blind spot creates significant exposure for companies that believe they have control over their AI landscape.The dangers of shadow AI moved from theoretical to tangible when CB Financial Services filed a material cybersecurity Form 8-K with US regulators. The Pennsylvania-based financial firm revealed that employees used unauthorized AI tools to bypass IT firewalls, resulting in accidental data leaks of customer names, social security numbers, and dates of birth
3
. The incident wasn't intentional—an employee simply put sensitive information into an AI chatbot to save time3
.This case illustrates how the road to data exposure is paved with good intentions. According to Writer's 2026 AI Adoption In The Enterprise survey, 67% of respondents say their company has already suffered a data leak or breach due to unapproved AI tools
3
. The types of information being shared are particularly concerning. Among those using unauthorized AI tools, 54% share internal messages and emails, 45% share HR-related information, and 39% share confidential company documents including financials and contracts3
.The uncomfortable truth is that AI tools deliver genuine productivity and security benefits that employees can't ignore. Microsoft's 2026 Work Trend Index found that 58% of respondents said AI helps them take on tasks they couldn't have handled a year ago
1
. When faced with mounting workloads and tight deadlines, workers make a fast cost-benefit calculation: missing a deadline hurts them now, while a potential data breach feels like someone else's problem later2
.
Source: CNET
This calculation is backed by data. Sixty percent of employees believe productivity benefits outweigh security risks when deadlines are involved
2
. Even more striking, 48% said they'd use AI even if it were explicitly banned2
. The existence of shadow AI signals that there are productivity gains to be captured. "I don't think people are using AI tools for fun at work," Wu explained1
.A toxic mix of overconfidence and complacency at the leadership level compounds the shadow AI problem. Okta's AI Agents at Work 2026 report found that 90% of executives have confidence in their organization's visibility into AI tools, while 95% assume employees are using AI responsibly
3
. This stands in stark contrast to reality, where 52% of knowledge workers admit to using unsanctioned AI tools at work, with 24% doing so regularly3
.The problem extends to the C-suite itself. Teramind's research reveals that 69% of C-suite leaders prioritize speed over security when using AI tools, compared to just 37% of frontline employees
2
. Executives feel competitive pressure more acutely and rationalize bypassing policies they themselves signed off on2
. Adding to the dysfunction, 21% of employees claim their manager knows about their use of unauthorized AI tools but turns a blind eye3
.Shadow AI presents fundamentally different challenges than shadow IT, rendering many traditional data loss prevention tools ineffective. Legacy DLP systems were built to catch files moving between locations—a document uploaded to Dropbox, for example. Shadow AI involves unauthorized processing of sensitive information pasted into chat prompts
2
. There's often no file transfer to intercept, just data moving through encrypted browser sessions that pattern-matching tools can't detect.The challenge intensifies because AI features are now embedded everywhere. Shadow AI operates not just through banned apps, but through personal accounts on corporate-licensed platforms and AI features built into tools companies already pay for
2
. Your licensed Microsoft 365, PDF reader, or CRM likely all have AI capabilities now. Workers can access these through personal accounts without triggering traditional security alerts.
Source: TechRadar
Related Stories
According to Teramind VP of Strategy Leeron Walter, the solution isn't more restrictions. "You don't fix that with more restrictions," Walter explains. "You fix it by making the secure option just as fast and frictionless as the risky one. Remove the tradeoff entirely"
2
. This approach recognizes that for many workers, especially younger generations, AI is a basic utility like a search engine. Blocking it doesn't register as a security measure but as the company being behind.Gaining visibility represents the critical first step. Walter recommends a 90-day approach: spend the first 30 days observing without blocking, deploying behavioral telemetry to build a complete shadow AI inventory including browser extensions, clipboard activity, and personal account usage inside approved platforms
2
. Days 31-60 should focus on categorizing risk levels before implementing controls2
.The healthcare sector provides a cautionary tale. According to the 2026 Nutanix Healthcare ECI study of 1,600 cloud and IT executives, 79% of healthcare organizations report AI applications being implemented by employees in non-IT functions
3
. While 83% believe unauthorized AI tools create business risk, organizational silos between business units and IT make it difficult to execute technology initiatives effectively3
. Similarly, 79% of companies report AI applications being created in silos with individual departments deploying tools independently3
.The shift from AI experimentation to widespread enterprise AI adoption means security and trust must become higher priorities. Organizations can no longer ask whether employees will embrace AI—that question is settled. The critical questions now center on whether employers know how AI tools are actually being used, whether they're providing the right solutions, and whether their corporate governance supports real-world use cases
2
.Companies face mounting pressure to prove ROI from AI investments while managing the security risks that come with rapid adoption. The challenge is particularly acute because 35% of employees admit to entering proprietary information into public AI tools, while 40% say they'll use whatever it takes to get the job done
3
. With 55% describing AI use as a "chaotic free-for-all" at their company and 35% unable to shut down a rogue agent if detected3
, the window for establishing effective governance is closing rapidly.Summarized by
Navi
18 Feb 2025•Technology

22 Aug 2025•Technology

27 May 2026•Technology

1
Technology

2
Science and Research

3
Policy and Regulation
