Ask most leaders how their team uses AI and you'll get a tidy answer: a tool or two, a few sensible use cases. The fuller truth is better news than it sounds. Your people have already found AI tools that genuinely help them do their jobs, and they did it without a budget, a rollout plan, or anyone asking them to. The problem isn't the initiative. It's that all of it is running on personal laptops and free tiers, outside anything the company can stand behind.
The name for that gap is shadow AI: every AI tool your people use for work that no one approved, licensed, or even knows about. It isn't rare, and it isn't rebellion. In one 2025 survey, 78% of employees said they use AI tools their employer never gave them. Unapproved use isn't the exception. It's the default.
Why you can't see it
Shadow AI is invisible by design, not by deceit. It runs on free tiers and personal logins. There's no license to show up in a software audit, no log routing through IT, no line item anywhere. An employee opens a browser tab, pastes in their work, and gets an answer. Nothing about that touches a system you control.
This is also why the obvious fix fails. You can't survey your way to the truth, because people won't volunteer that they've been using a tool they suspect isn't allowed. The most common method companies reach for is the one guaranteed to undercount. LayerX's 2025 research found that 82% of what employees paste into AI tools goes in through unmanaged personal accounts, the kind no dashboard ever sees.
Invisible use is the risky kind
Every protection a company can put in place, a clear line on what data goes where, training built on real workflows, an approved-tool list, assumes the use has a legitimate home you can point to. Shadow AI has none, so none of those protections reach it.
It also compounds. The longer unapproved use runs in the dark, the more quietly your real work starts to depend on it, until a tool no one sanctioned is load-bearing. That invisibility carries a price. In IBM's 2025 breach research, unsanctioned AI was a factor in about one in five breaches and pushed costs roughly $670,000 higher where the shadow use ran deep.
What the hidden usage is actually telling you
The instinct is to treat shadow AI as a discipline problem: find the offenders, lock down the tools, send a stern email. That reading misses what the behaviour is telling you. People reached for these tools because the tools help them do their jobs, and no one offered a sanctioned way to get the same result. They aren't going around the system. There is no system.
A ban doesn't fix that. It just pushes the same usage further out of view, onto phones and home accounts where you have even less visibility than before. What closes the gap is giving AI use a legitimate place to live: approved tools, a clear line on what data is fine to use, and someone who owns the answer. The usage is going to happen. The only real choice is whether it happens where you can see it.
The decision shadow AI is waiting on
The decision underneath shadow AI is one most companies have never made on purpose: what do we actually want our people using, for what work, with what data? You can't answer that while the real usage is hidden from you.
The AI Readiness Assessment is built to surface exactly this, where AI is already running in your organization and what kind of data is flowing into it, across the five dimensions that turn scattered use into a system. Five questions, about two minutes. Surfacing it is also where we start with clients: we build the governance system that gives the use a legitimate home, and your team runs it from there.
Shadow AI is still yours to answer for. The choice is whether you give the use a home on your own terms, or find out about it on someone else's.
Keep reading
Part of a series on AI governance, the structure underneath the tools.
- The Moment the Data Leaves. What actually happens in the pastes you can't see.
- The 4 Stages of AI Governance Maturity. Where unmanaged use puts you on the ladder.