What Is Shadow IT: Examples, Statistics and Risks
Shadow IT used to mean an employee signing up for a free Trello board or syncing work files to a personal Dropbox account. That risk never went away, but it has been overtaken by a bigger one: employees pasting company data into ChatGPT, Claude, or Gemini without anyone in IT knowing. If you are still thinking about shadow IT as unsanctioned SaaS apps and BYOD phones, you are only seeing half the picture in 2026.
What is shadow IT, really?
Shadow IT is any hardware, software, or service employees use for work without going through an official approval or procurement process. That still includes the classics: personal devices, unlicensed software, unauthorized cloud storage, and messaging apps nobody vetted. But the fastest-growing category by far is what security researchers now call shadow AI, employees quietly using AI tools their employer never approved, or explicitly banned.
The numbers on this are not subtle. A 2025 State of Shadow AI report from UpGuard found that more than 80% of workers, including nearly 90% of security professionals, use unapproved AI tools in their jobs. Half of workers said they use unapproved AI tools regularly, and fewer than one in five said they stick to company-approved tools only. Read that again: the people whose job is to stop this behavior are among the worst offenders.
"Employees who view AI tools as their most trusted source of information are far more likely to use shadow AI tools as part of their regular workflow," UpGuard noted in its report. That is the uncomfortable insight buried in the data. People are not sneaking around because they distrust the rules; they are sneaking around because they trust the AI tool more than the process they are supposed to follow.
How common is this in practice
PagerDuty ran its own survey in June 2026 across 1,250 office professionals at companies with $500 million or more in annual revenue, spanning the US, UK, Australia, and Japan. Two-thirds (66%) of respondents said they had used AI tools at work that they believed were not permitted under company policy. This is not a fringe behavior at small, under-resourced companies. It is happening at the exact kind of large enterprise that supposedly has mature governance in place.
What makes this genuinely dangerous, not just a policy violation on paper, is what people are putting into these tools. In the same survey, 88% of office professionals said they had shared work-related information with public AI tools. Broken down: 43% shared emails or correspondence, 40% shared meeting notes or summaries, 34% entered customer data, and 31% shared financial information or confidential strategy documents. None of that data is recoverable once it is inside a third-party model's training pipeline or logs, and most employees have no idea what happens to it after they hit enter.
"When over 30% of employees are putting confidential company data into public models, 'Shadow AI' becomes a massive enterprise liability," said Tim Armandpour, CTO at PagerDuty, commenting on the survey results. "The goal for any executive today should not be to slow down AI adoption, but to redirect that energy into proven platforms that offer governance and automation at scale."
That last point is worth sitting with, because it cuts against the instinct most IT leaders have when they see numbers like these. The reflex is to ban things. But 72% of workers in the PagerDuty survey believe they understand AI better than their own tech teams do, a figure that climbs to 80% at billion-dollar companies. Telling that population "just don't use it" rarely works. It usually just pushes the behavior further underground, where you have even less visibility into it.
Why shadow IT keeps winning
This is where teams usually trip up: they assume shadow IT is a discipline problem, something you fix with a stricter acceptable-use policy and a stern all-hands email. In practice it is almost always a gap problem. Employees reach for unauthorized tools because the sanctioned alternative is slower, clunkier, or does not exist yet.
Microsoft and LinkedIn's Work Trend Index found that 78% of employees who use generative AI at work bring their own tools rather than using something IT provided. At small and midsize companies, that number rises to 80%. These are not rogue actors trying to cause a breach. They are people trying to get their jobs done faster, with whatever is available, because the official option either does not exist or is too slow to request.
There is also a generational split worth noting. Among AI users, 48% of Gen Z and Millennial employees say they have shared sensitive work information with an AI tool without telling their employer, compared with 20% of Baby Boomers, according to research compiled by Second Talent's review of 2025 and 2026 shadow AI data. Younger employees grew up treating AI assistants as a default utility, not a special-case tool that requires sign-off. That habit does not disappear when they start a corporate job; if anything, it gets exported into the workplace.
Where this creates real risk
The mechanics of the risk have not changed much from the earlier shadow IT era, but the blast radius has. A few places this bites organizations in practice:
1. Data exposure with no audit trail
When someone pastes a contract, customer list, or source code snippet into a public chatbot, that data leaves your controlled environment permanently. Unlike an unauthorized SaaS app, which at least generates some kind of log somewhere, a copy-paste into a browser tab often leaves nothing for your security team to find after the fact.
2. Compliance violations that surface later
If your company handles regulated data under HIPAA or PCI DSS, an employee feeding protected health information or card data into an unapproved AI tool can put you in violation of those regulations well before anyone notices. The gap between the violation and its discovery is often the most expensive part.
3. Incident response blind spots
Security monitoring and SIEM tooling is built to watch sanctioned infrastructure. Unsanctioned AI tools and shadow SaaS applications typically fall outside that visibility entirely, which means an incident involving them can run for weeks before it is even flagged.
4. Erosion of the policies you do have
GTIA's State of the Channel 2026 research found that only 38% of organizations have a formal, comprehensive AI policy in place, up from 28% a year earlier. Progress, but still a minority. And having a policy is not the same as enforcing one: Gartner's 2025 survey found 69% of organizations suspected or had direct evidence that staff were using banned public generative AI tools anyway.
What actually reduces the risk
None of this means shadow IT and shadow AI can be eliminated. They cannot, not fully, and pretending otherwise just wastes budget on controls that get routed around. What works better is narrowing the gap between what people want to do and what they are allowed to do.
- Give people an approved AI option fast. If your organization does not have a sanctioned AI tool with acceptable data handling terms within reach of employees, you have already lost the argument. Most people will use the approved tool if it exists and is not painfully worse than the free alternative.
- Write the policy in plain language, then actually distribute it. A policy that lives in a wiki nobody visits is not a policy. Make clear what data categories are off-limits for any public AI tool, and repeat it more than once.
- Monitor at the network and endpoint level, not just the app layer. DNS-based and browser-extension monitoring can flag traffic to consumer AI domains even when there is no formal SaaS contract to track. Pair this with our guide to shadow IT prevention tools for specific product options.
- Train on consequences, not just definitions. Generic awareness training about "what is shadow IT" underperforms training that walks through a real, recent example of data exposure and what it cost. Security awareness training works better when it is specific and recurring rather than a once-a-year checkbox.
- Require MFA everywhere sensitive data lives. If a shadow tool does end up connected to something important, multi-factor authentication limits how far a compromised credential can travel.
- Accept that some shadow IT is a signal, not just a threat. If half your sales team is using the same unauthorized tool, that is useful market research about what your official tooling is missing. Treat recurring shadow IT patterns as product feedback for your internal IT stack, not only as a violation to shut down.
One honest caveat: none of this fully closes the gap, and it should not be sold to leadership as a silver bullet. Even organizations with strong policies, monitoring, and approved tools still see meaningful shadow AI usage, because the underlying driver, people wanting faster answers than the sanctioned process provides, is not something a policy alone resolves. The goal is reducing exposure and improving visibility, not reaching zero.
The BYOD connection hasn't gone away
Bring-your-own-device policies remain a common on-ramp into shadow IT, and that has not changed just because AI tools are the newer headline risk. Employees still sync work email to personal phones, still install unapproved apps on devices that touch company networks, and still connect from public Wi-Fi without a second thought. If your BYOD policy has not been revisited in a couple of years, it is worth pairing your AI governance update with a fresh look at device management policy generally, since the two risks compound each other. An employee using a personal, unmanaged laptop to access a personal, unapproved AI tool is effectively shadow IT squared.
The bottom line
Shadow IT was never really about rogue employees trying to cause harm. It has always been a symptom of a mismatch between what people need to do their jobs and what official channels make available to them fast enough. That dynamic has intensified with generative AI because the unofficial option is not just convenient, it can feel genuinely smarter and faster than anything IT has rolled out. Organizations that respond by tightening bans alone tend to just lose visibility. The ones making progress are pairing sanctioned, fast alternatives with real monitoring and policies people can actually find and understand. This is one of the few areas of cybersecurity where the fix is less about locking things down and more about keeping up.
