NetCov Resources

How to Combat Shadow AI

Written by Bill Goldin, SVP of Innovation and AI | Sep 30, 2026, 1:07:26 PM

Somewhere in your organization right now, someone is using AI. You might already know it, and if you don’t, we are here to shed light on it. An employee or teammate could be using ChatGPT or Copilot to write emails, summarize documents, or create images. And that’s just at a basic level.

The thing that you should care about is that none of this appears in your software inventory or flows through your data loss prevention tools. But all of it is happening anyway. In fact, UpGuard’s State of Shadow AI report puts unapproved AI use at over 80% of employees. 
This guide covers what shadow AI actually is, why it spreads despite good policies, what it costs, and the five moves that shrink it without grinding your business to a halt.

What Is Shadow AI?

Shadow AI is the use of artificial intelligence tools for work purposes without the knowledge, approval, or oversight of the organization. It includes personal accounts on public chatbots, free-tier AI features inside everyday apps, unvetted browser extensions, and AI functions quietly added to software you already have implemented.

It is the direct descendant of shadow IT, but with more risk. When an employee installs an unapproved project management app, the risk is that company data sits in an unmanaged place. When an employee pastes data into a public AI model, the data may leave your control entirely and, depending on the tool’s settings, become part of someone else’s training material.

Why Do Employees Use AI Tools Without Approval?

Employees turn to shadow AI because it’s everywhere, it’s immediate, and an approved path may be slower than the problem in front of them. Gallup found that only 22% of employees say their organization has communicated a clear plan for integrating AI into their work. Into that vacuum, people bring their own solutions.

There are three forces that drive the spread:

  • Speed: A free AI tool answers in seconds. A procurement and security review takes weeks. When the deadline is Friday, the review loses.

  • Gaps in the approved toolkit: As AI continues to be discussed, implemented, and advertised everywhere, more people are starting to use unauthorized AI tools at work. Between the pressure of external factors to use AI and the lack of a sanctioned alternative internally, the number of people using shadow AI continues to grow.

  • No perceived harm: Pasting a document into an AI tool feels like a private conversation, not a data transfer. The interface hides the risk that a file share or an email attachment makes obvious.

Almost none of this is done maliciously. Shadow AI is what productivity looks like when governance hasn’t shown up yet. That framing matters because it points to the only response that actually works, making the governed path the easy path.

What Does Shadow AI Actually Cost Organizations?

The costs fall into four buckets, and only one of them shows up on a standard security report.
Breach costs. IBM’s 2025 research found that breaches at organizations with extensive shadow AI cost an average of $670,000 more than comparable breaches without it, and that 65% of shadow-AI-linked incidents exposed Personally Identifiable Information (PII). More data scattered across more tools means more places for an attacker to find you.

Second is compliance exposure. When customer data enters an unapproved tool, you may lose the ability to honor a GDPR deletion request, satisfy NCUA or CMMC audit requirements, or demonstrate the data-handling controls your clients’ contracts promise. The violation happens when an employee pastes information into the AI tool, which means it can accumulate silently for years.

Then you have intellectual property leakage. This can happen from anyone in your organization using a tool to get work done quicker. For an AEC firm, that can include bid strategies and proprietary designs. For a credit union, that can include member information and lending models. Once these enter a third-party model, you cannot recall them.

Lastly, there is the decision-quality risk. AI outputs that no one validated now inform real decisions, whether that is estimates, drafts, or analyses. An error inside an unmanaged tool propagates into your business with no review trail, and most organizations lack the AI governance framework that would catch it.

How Do You Combat Shadow AI?

1. Find out what is actually happening

You cannot govern what you have never measured. Start with an AI usage audit. This will identify which AI tools are being used within your organization without your knowledge.

2. Publish a short, usable AI policy

Not a 40-page legal document. A one-page policy that answers the questions employees actually have: which tools are approved, what data may never enter any AI tool, and who to ask when unsure. A policy people can follow beats a policy that would impress an auditor.

3. Give people a sanctioned path that is faster than the shadow path

This is the move that does the heavy lifting. Approve one capable AI tool for broad use, enable enterprise-tier data protections on it, and make access instant. Then try to close the specific gaps that drove people to shadow tools in the first place.

4. Put guardrails where the data moves

Policy tells people what to do. Controls catch what they miss. Browser-level monitoring, DLP rules tuned for AI destinations, and access controls on your most sensitive data stores shrink the blast radius of the exposures that will still happen.

5. Make AI literacy part of onboarding and keep it going

Most shadow AI starts with someone who genuinely didn’t know pasting information was a data transfer. Short, role-specific training about what the tools do with your data, what the law requires, and what an AI answer is worth turns every employee into a sensor. Refresh it quarterly, because the tools change monthly.

If you want to learn more about these five steps, we discuss them in depth in our latest webinar, Copilot, Claude, or Something Else? Why That's the Last Decision, Not the First.

How NetCov Helps

If those five steps sound intimidating to do on your own, you’re not alone. NetCov has helped many organizations head down the right path when it comes to AI governance. We offer an AI readiness assessment that includes an AI readiness score, a risk and compliance map, prioritized use cases tailored to your industry, and a 90-day roadmap. If this sounds interesting to you, contact us. We’d love to help.

FAQ

What is shadow AI in simple terms?

Shadow AI is any AI tool an employee uses for work without their employer’s approval or visibility. Most often it is a personal account on a tool like ChatGPT or Claude, or an AI feature inside an everyday app.

How common is shadow AI?

Very. UpGuard’s 2025 report found over 80% of employees use unapproved AI tools at work, and IBM found one in five organizations has already experienced a breach linked to it.

Is shadow AI the same as shadow IT?

It's related, but riskier. Shadow IT puts data in unmanaged places, while shadow AI can send data into third-party models where it may be retained or used for training, beyond your ability to control or delete it.

What is the fastest way to reduce shadow AI use?

Decide what AI tool works best for your organization, make sure it is secure, and roll it out to your organization. When employees know that there is one tool that the whole organization is able to use, they are less likely to participate in shadow AI use.

Who should own shadow AI governance?

It needs joint ownership: IT and security for tooling and controls, legal and compliance for exposure, and leadership for the policy and culture. There needs to be a named owner. Unowned policies are unread policies.