Part of our guide: AI governance and risk
In 2026, shadow AI affects over 75 percent of enterprises, and that statistic from industry research should concern every leadership team, especially those in regulated sectors where data handling and decision accountability are not optional.
Shadow AI is what happens when employees adopt AI tools (chatbots, content generators, data analysis platforms and coding assistants) without going through IT, procurement or compliance. It is the more dangerous successor to shadow IT, and the risks are not just financial: they are operational, regulatory and reputational.
Why shadow AI is different from shadow IT
Shadow IT was someone using Dropbox instead of SharePoint, and it was an annoyance, though the resulting access risk was usually contained. Shadow AI is someone pasting customer data into ChatGPT to draft a response, or feeding proprietary financial data into an unvetted AI platform to generate analysis. The data leaves your perimeter, the AI vendor may train on it and the output may be wrong, all while nobody in your governance structure knows it happened.
Research shows 77 percent of employees paste data into generative AI prompts, and 82 percent of those interactions come from unmanaged accounts sitting outside any enterprise oversight. The average enterprise experiences 223 data policy violations per month related to AI usage, and shadow AI added $670,000 to average breach costs last year. These are not theoretical risks, and they are happening now, in businesses like yours.
The three layers of shadow AI risk
Data exposure is the first layer, and every time an employee uses an unvetted AI tool with company data, that data potentially leaves your control. In sectors governed by GDPR, FCA regulations or client confidentiality obligations, this is a compliance event, whether you know about it or not.
Decision quality is the second layer, and it arises when employees use AI to generate analysis, draft communications or inform decisions without any quality assurance. The outputs can be wrong, biased or misleading, and if a client-facing decision is based on shadow AI output that nobody reviewed, the accountability trail is broken.
Governance erosion is the third layer, and shadow AI normalises the idea that AI adoption happens outside formal channels until that culture takes hold. Structured governance then becomes progressively harder to implement, and by the time the leadership team decides to formalise AI governance, the horse has bolted.
Why people use shadow AI
Understanding this matters because the response cannot simply be "ban it", and people use shadow AI because the official channels are too slow, too restrictive or non-existent. If your organisation does not provide sanctioned AI tools with clear usage guidelines, employees will find their own, and the demand for AI productivity is real and legitimate, making the failure organisational, not individual.
What to do about it
Acknowledge it exists, because most leadership teams underestimate the extent of shadow AI in their organisation, and run a discovery exercise. The exercise can be something as informal as a survey, aiming to understand what tools people are using and what data they are putting into them.
Provide sanctioned alternatives, because the fastest way to reduce shadow AI is to give people approved tools that meet their needs. If the marketing team needs content generation, provide a governed tool with clear data handling policies, and if analysts need AI-assisted data exploration, deploy one centrally with appropriate controls.
Set clear, simple policies, since your AI usage policy does not need to be 50 pages long and what it does need is to answer three questions. Those questions cover what data people can put into AI tools, the tools that are approved and who to ask when unsure, keeping the policy short, visible and unambiguous.
Build governance proportionate to risk, because not every use of AI requires the same oversight, and tier your governance accordingly. Someone using AI to summarise meeting notes carries different risk from someone using AI to generate compliance reports, and Responsible AI on a Mid-Market Budget offers a practical framework.
Monitor, do not just mandate, because policies without monitoring are suggestions, using network-level visibility to understand what AI services are being accessed from your corporate network and devices. This is about understanding and managing risk, not about surveillance.
For the governance framework that prevents shadow AI from becoming a structural problem, see AI Governance in Financial Services, and for the strategic architecture that gives AI a formal home in your organisation, see AI Operating Model Design.
If shadow AI is something you suspect but cannot quantify, Breathe surfaces what is already happening, sanctioned and otherwise, as it maps your capabilities and scores data readiness.