New · The guide “Mastering Claude at work”, free. Download it →

Last reviewed:

What is shadow AI? Definition and pitfall to avoid

Shadow AI refers to the use of generative AI models by employees without validation or framing from their company. Widespread in 2025-2026, it creates legal, financial (leakage of business data to public models), and quality (unaudited outputs integrated into client deliverables) risks.

Shadow AI is the AI equivalent of shadow IT, extended in 2024-2025 to nearly all companies. The figures converge: 35.9% of US workers used generative AI by December 2025 (Federal Reserve Bank of St. Louis), a significant portion in shadow mode, without declaration to their employer. A PagerDuty/Wakefield Research survey (fielded April 2026, 1,250 office professionals in non-IT roles at companies with $500M+ revenue) quantifies the scale on the corporate side: 66% have used an AI tool they believed was not permitted, and 88% shared work-related information with it — including 34% customer data and 31% financial or confidential documents. Four mechanisms feed shadow AI. The free nature of consumer tools (ChatGPT, Claude.ai): an employee only needs a personal email address. Perceived performance: public models produce useful results immediately. Slowness of official deployment: between identifying a need and providing a validated tool, several months often pass. Lack of explicit policy: without a written AI policy, employees interpret silence as tacit authorisation. These mechanisms show up in the data: 89% of users first adopted the tool in their personal life, 44% use it to work around the limits of company-approved tools, and 38% have delivered AI-assisted work without disclosing it. Frequent consequences: transmission of confidential documents to external models, use of outputs in deliverables without legal review.

Concrete example

An 80-employee HR consulting firm detects in 2025, during a GDPR audit, that 45 consultants use ChatGPT from their personal account to prepare client assessments. Estimated cumulative volume: 8,000 conversations over 9 months, containing personal data of about 1,200 individuals (candidates, evaluated employees). Company response: formal information to the persons concerned, legal audit, implementation of a written AI policy, deployment of a validated internal tool (Claude Enterprise with European hosting), mandatory training. Total cost of the incident: 95,000 euros, including the audit, client communication, training, and three departures of employees not wanting the new framework.

A second, larger-scale publicly documented case: Samsung Semiconductor (Korea), March-April 2023. Three separate incidents in 20 days saw engineers submit proprietary source code, internal meeting notes and chip test data to ChatGPT (free account, data re-usable for training under the terms of service at the time). Samsung responded in April 2023 with a company-wide ban on ChatGPT across corporate devices and networks, then announced work on an in-house LLM. The incident served as a sector-wide wake-up call: Amazon, Apple, JPMorgan and Verizon adopted similar restrictions in the following months.

Comparison

Shadow IT, shadow AI and BYOD: what sets them apart
Shadow ITShadow AIBYOD
ScopeUnsanctioned apps or SaaSGenerative models (ChatGPT, Claude.ai) via personal accountsPersonal devices used at work
Primary riskSecurity, data governance, uncontrolled spendData leakage + reuse by public models for trainingEndpoint security, work/personal boundary
DetectionMDM / proxy audits, card statementsDNS audits + surveys + deliverable reviewMandatory enrolment or network blocking
Typical framingApproved SaaS catalogueWritten AI policy + official channel of equivalent performanceBYOD policy + MDM on enrolled devices
Emergence≈ 2010 (consumer SaaS)2023 (public release of ChatGPT)≈ 2010 (personal smartphones at work)
GDPR impactVaries by processed dataHigh as soon as personal data is sent to the LLMVaries by access and enrolled apps

FAQ

What's the difference between shadow AI and shadow IT?

Shadow IT refers to unsanctioned digital tools (SaaS, apps). Shadow AI is its 2024-2026 extension: use of generative models (ChatGPT, Claude.ai) via personal accounts, with an added risk — transmitted data is often used to train or improve the public models.

Is using ChatGPT in shadow AI illegal?

Not per se, but it often breaches GDPR (or equivalent laws) when employees send personal data — candidates, clients, staff — to a public model without a legal basis or informing the individuals. The controller (the company) remains liable for processing carried out through these tools.

How can I detect shadow AI in my organisation?

Three signals: proxy or DNS audits for the relevant domains (chatgpt.com, claude.ai, gemini.google.com), non-punitive anonymous surveys, and deliverable analysis (LLM-typical phrasing, uncorrected hallucinations). 2026 surveys put real usage between 60 % and 90 % depending on size and sector.

Why do employees use AI in shadow mode?

Four documented reasons: free consumer tools, immediate productivity gains, slow official rollout (often several months), and lack of an explicit policy — silence gets read as tacit permission. 89 % of shadow users first adopted the tool in their personal life.

How do you frame shadow AI without killing innovation?

Three non-negotiables: publish a one-page AI policy (allowed tools, banned data, outputs requiring review), quickly open an official channel of equivalent performance, and prioritise training over sanction. Blocking without an alternative creates permanent workarounds.

What does a shadow AI incident actually cost?

Publicly documented in 2025: €95,000 for an 80-person HR consultancy after 45 consultants were found using ChatGPT on client data — legal audit, client communication, training, three resignations. Indirect costs (trust erosion, GDPR non-compliance) are typically far higher.

See also

Further reading

The Rapid Adoption of Generative AI, Federal Reserve Bank of St. Louis, 2025 (external resource)

Sources

  1. The Rapid Adoption of Generative AI, Bick, Blandin & Deming, Federal Reserve Bank of St. Louis Working Paper 2024-027C, revised 2025. https://www.stlouisfed.org/on-the-economy/2025/feb/impact-generative-ai-work-productivity (accessed 2026-05-24)
  2. CNIL recommendations on AI and GDPR compliance, 2024 (resource available in French only). https://www.cnil.fr/fr/intelligence-artificielle (accessed 2026-05-26)
  3. PagerDuty Shadow AI Survey, conducted by Wakefield Research, fielded 9-20 April 2026 (1,250 office professionals in non-IT roles, companies with $500M+ revenue, US/UK/JP/AU, margin of error ±2.8 pts). https://www.pagerduty.com/newsroom/shadow-ai-workplace-survey-2026/ (accessed 2026-07-06)

← Back to glossary

Address copied