The numbers move around depending on who's counting, but they all point the same way. A global study of 6,000 knowledge workers found half of employees use AI tools their company never provided. PagerDuty's 2026 survey found 66% of office professionals at large companies had used AI at work while believing it broke policy. Verizon's 2026 breach report clocked shadow AI detections rising fourfold in a year.
Different populations, different definitions — so don't stack those percentages against each other. What they agree on is the shape of the thing: unapproved AI use is ordinary behaviour now, and most employers have no idea how much of it is going on.
The visibility gap is the real story
The striking number isn't usage. It's the distance between usage and what management thinks is happening.
In the Teramind research, 78% of executives said they had a clear picture of AI use inside their organisation. Measured against what employees actually reported doing, the real figure was closer to 23%.
That gap is why policies here keep failing. A policy written for an imagined 20% adoption rate is a completely different document from one written for a real 50%. The first thinks it's handling exceptions. The second would have to be built for the default.
What people are pasting in
The data findings are where this stops being theoretical. In one US survey, 65% of employees said they use AI tools their employer hasn't approved — and 71% of those admitted feeding in sensitive material: customer details, employee records, internal documents.
Freshworks found 86% of IT leaders had at least one negative incident tied to unapproved AI in the past year. Nearly a quarter had more than three.
The motive isn't rebellion. BlackFog found 60% of employees would take risks to hit a deadline. That's what this is. Someone has a report due at five, the approved tool is slow or doesn't exist, and a browser tab solves it in four minutes. Nobody in that moment is thinking about data governance.
What actually helps
Banning it works badly, because the pressure that caused it doesn't go anywhere. The organisations doing better on this have mostly done three things.
They gave people an approved tool that's actually good. Most shadow AI is a substitute for a missing or mediocre sanctioned option. Make the official tool fast and capable and the reason to route around it mostly evaporates.
They drew the line at data types, not tools. "Never paste customer records, credentials, unreleased financials or personnel files into any external system" is a rule someone can follow at 4:55pm. A list of approved vendors is out of date within a quarter.
They made it safe to say so. The moment using AI counts as confessing to something, visibility disappears — and visibility is exactly what management is missing.
If you're one of the statistics
The practical advice is short. Assume anything you type into a consumer AI account may be kept and used under that platform's terms, not your employer's. Keep customer data, credentials and personnel files out of it completely. And if the approved tool is bad, say so somewhere it can actually get fixed — the gap between what's sanctioned and what's usable is generating this entire mess.
Image: cottonbro studio, via Pexels





