23/07/2026

Shadow AI: the risks of unsanctioned AI tools at work

Insights

Data & AI

Insights

Back

For many businesses, AI is no longer a future consideration, it’s already embedded in how teams work. A McKinsey Global Survey on AI reports that half of organisations have adopted AI in two or more business functions, up from less than a third in 2023.

But as adoption accelerates, so does a quieter risk: shadow AI. When employees use generative AI tools without any oversight from their IT team, the result can be security breaches, compliance violations and inconsistent quality, often without anyone in the business realising until it’s too late.

What is shadow AI?

Shadow AI is the unsanctioned use of generative AI tools and features by employees, often without their organisation’s knowledge or any oversight from their IT team.

User-friendly, open-source AI platforms mean staff can access powerful AI capabilities in a few clicks, with no procurement process and no sign-off, just convenience and a productivity boost.

The problem is that the risks of shadow AI extend far beyond typical software risks. Unlike an unauthorised app, an AI tool can absorb, store and even learn from the data it’s given, which makes the consequences harder to contain and harder to reverse.

As adoption of shadow AI keeps increasing, organisations will need to weigh up the broader risks and business implications, and take a proactive approach to turn shadow AI from a risk into a benefit.

The risks of shadow AI

Used without proper governance, AI tools can introduce security risks, data breaches and compliance violations, all of which can lead to serious financial, legal and reputational damage.

Strict controls are also essential to stop incorrect AI-generated content from influencing business decisions, whether that’s a report, a customer response or a strategic plan.

There’s also the data question. When employees put corporate data into AI systems that store or process information externally, that information can be left exposed to unauthorised access, often without anyone intending it to happen.

So how should organisations respond to the risks of shadow AI?

Managing shadow AI

Managing shadow AI should be part of a proactive approach that combines technological governance, employee education and continuous operational oversight. At a minimum, this means:

  • Approved AI tools: a clear list of what’s sanctioned for use and what isn’t.
  • Usage guidance: practical advice on secure data use, so staff know what they can and can’t put into an AI tool.
  • Risk assessments: regular reviews to catch new tools and new risks before they become a bigger issue.
  • Compliance checks: making sure AI use aligns with your wider security and regulatory obligations.

Handled well, managing the risks of shadow AI isn’t just about damage control. It’s an opportunity to move employees onto fully authorised, secure AI tools and unlock the productivity benefits properly, without the risk.

Not sure how much shadow AI is already in your business?

That uncertainty is usually the first sign it’s worth finding out. Our team can help you assess your exposure, build an AI usage policy and put the right governance in place, so your business gets the benefits of AI without carrying the risk on its own.

Share post