Shadow AI: The Security Risk Companies Are Underestimating

On this page
Shadow AI is employees using AI tools their employer hasn't approved, usually on personal accounts and often with company data. It's growing fast: in IBM's 2026 breach study, the share of security incidents involving shadow AI more than doubled, to 43%. The evidence suggests bans alone don't work; visibility, approved tools and clear data rules do more.
This guide explains what shadow AI is and how it differs from shadow IT, how common it is, why it's a security and compliance risk, what real incidents look like, why companies underestimate it, whether banning AI tools works, how to find and manage it, what UAE and EU rules require, and what it means for property firms.
Key takeaways
- It's already normal. About half of employees in a 47-country study by KPMG and the University of Melbourne said they had uploaded sensitive company information to public AI tools; in the UAE, 56% said they had used AI in ways that contravene policies.
- It's getting more expensive. In IBM's 2026 Cost of a Data Breach study, incidents involving shadow AI cost an average of USD 5.39 million, up from USD 4.63 million, and 49% led to data loss or compromise.
- Regulators treat it as a breach. The Dutch data protection authority says entering personal data into a chatbot against the employer's rules is a data breach, and Victoria's privacy regulator ordered ChatGPT and 14 other AI tools blocked for child-protection staff.
- Licences haven't ended it. Netskope's customer data shows the move from personal to company-managed AI accounts stalled around March 2026, with 30% of AI users still on personal apps only.
- Bans don't obviously help. Risky uploads were most common where employers had banned generative AI (67%), against 33% where there was no policy.
- UAE firms have obligations. The PDPL requires security measures, breach reporting and controls on sending personal data abroad, and DIFC firms face specific rules for AI processing.
What is shadow AI?
Shadow AI is the use of AI tools, features or agents for work without the organisation's approval or oversight. IBM defines it as the unsanctioned use of AI tools or applications by employees or end users without the approval or oversight of the IT department. The UK's National Cyber Security Centre treats it as part of shadow IT — technology used for business that the organisation doesn't know about or manage — and notes that AI used without permission is often called shadow AI.
Definition
Shadow AI — any AI tool, feature or agent used for work without the organisation's approval, visibility or controls. Common forms include a personal ChatGPT, Claude or Gemini account used for client documents, an AI browser extension or note-taker installed without review, an AI feature switched on inside approved software, and an agent connected to company email or files with someone's personal credentials.
It helps to separate four ideas that are often blurred:
| Term | What it means | Example |
|---|---|---|
| Shadow IT | Any technology used for work outside the organisation's knowledge and risk management | Work files kept in personal cloud storage |
| Shadow AI | The AI part of shadow IT: unapproved AI tools, features and agents | A client contract pasted into a personal chatbot account |
| Bring your own AI | Staff using their own AI tools at work, which may or may not be approved | A personal subscription used with a manager's blessing |
| Sanctioned AI | Tools the organisation has approved, contracted and configured | An enterprise AI workspace with no-training terms, single sign-on and audit logs |
What makes shadow AI different from older shadow IT is what happens to the data. A personal file-sharing account stores a document; an AI service also processes it, may retain it and, on some consumer plans, may use it to train models. The output then flows back into reports, emails and decisions, often without anyone checking it. IBM draws the same line: shadow IT covers any unauthorised application, while shadow AI focuses on AI tools and brings its own concerns about data, outputs and the decisions built on them.
How common is shadow AI?
Very common, though every estimate depends on who was asked and how.
What the data shows
Shadow AI in numbers
- Employees worldwide (KPMG and University of Melbourne, 2025): 58% intentionally use AI at work regularly, most often free public tools rather than ones their employer provides, and about half have uploaded sensitive company information to public AI tools. More than 48,000 people in 47 countries took part.
- UAE employees (same study): 92% intentionally use AI at work, 56% have used it in ways that contravene policies, and 72% have relied on AI output without checking its accuracy.
- Security leaders (Gartner, 302 surveyed, March–May 2025): 69% suspect or have evidence that employees use prohibited public generative AI.
- Employees (Gartner, 175 surveyed, May–November 2025): more than 57% use personal generative AI accounts for work, and 33% admit putting sensitive information into unapproved tools.
- AI users (Microsoft and LinkedIn, 31,000 surveyed, 2024): 78% brought their own AI tools to work.
- Network data (Netskope customers): the share of AI users on personal apps fell from 78% to 47% over 2025, then the shift stopped around March 2026; 30% now use only personal apps and 14% use both.
Treat these as signals, not a census. The KPMG authors warn that social-desirability bias probably means their figures understate the problem; Gartner's employee survey covers only 175 people; Microsoft's figure measures people bringing their own AI, not whether it was approved; and vendor telemetry reflects each vendor's own customers. But every source points the same way: a large share of workplace AI use happens outside what IT has approved.
Why is shadow AI a security risk?
Because it moves company and client data into systems the organisation doesn't control, and because the tools themselves can be a way in.
What the data shows
What shadow AI incidents cost (IBM, 2026)
- Share of incidents: across the 602 breached organisations IBM studied, the share of security incidents involving shadow AI more than doubled, from 20% to 43%.
- Cost: USD 5.39 million on average, up from USD 4.63 million a year earlier, against a global average breach cost of USD 4.99 million.
- Consequences: data loss or compromise in 49% of shadow-AI incidents and operational disruption in 42%; in about one in five, organisations reported paying a regulatory fine.
- Middle East: breaches in IBM's Saudi Arabia and UAE sample averaged USD 8.00 million, the second-highest figure after the United States.
IBM's 2025 edition had already found that shadow-AI breaches were more likely to expose customers' personal information: 65% of them did, against 53% of breaches overall. The risks break down into seven kinds:
| Risk | How it happens | Documented example |
|---|---|---|
| Data leakage | Staff paste documents, spreadsheets or chat histories into a personal AI account | A contractor's ChatGPT upload exposed data on 2,031 people in New South Wales |
| Training and retention | Consumer plans may use what's entered to train models unless the user opts out | OpenAI's terms for its services for individuals |
| No visibility | Company logs show a visit to an AI site, not what was typed | Victoria's privacy regulator on ChatGPT use in a government department |
| Fake AI tools | Malware disguised as an AI app | A fake AI art program led to the theft of about 1.1 TB of Disney Slack data |
| Connected apps | AI apps and agents hold tokens that open email, files and CRM systems | Stolen tokens from the Salesloft Drift app were used to export data from many Salesforce instances |
| Unsanctioned agents | Staff and developers build or connect agents that take actions | Gartner tells security leaders to identify sanctioned and unsanctioned agents |
| Unchecked output | AI-written text enters reports and decisions without review | ChatGPT-generated text in a child-protection court report contained inaccurate information that downplayed risks to the child |
The Drift case wasn't shadow AI — customers had approved the app — but it shows what a stolen token can do: Google's threat intelligence team found attackers used compromised tokens to export data and then search it for credentials. An AI app or agent that someone connects to company email or a CRM with personal credentials carries the same kind of key, with no one watching it. The wider risks of agents that act on accounts are covered in multi-agent systems and personal AI agents.
What does a shadow AI incident look like?
Published cases are few, because most organisations don't disclose them, but the ones that have surfaced through regulators and courts follow a pattern: a time-pressed employee, a sensitive file and a tool nobody approved.
| Case | What happened | Outcome |
|---|---|---|
| Victoria, Australia (reported December 2023) | A child-protection worker entered case details, including names and risk-assessment information, into ChatGPT to help draft a report for the Children's Court. Nearly 900 staff, almost 13% of the department, had accessed ChatGPT in the second half of 2023. | The privacy regulator found the department had seriously contravened privacy principles on data accuracy and security, and ordered it to block ChatGPT and 14 other AI tools for child-protection staff until November 2026. |
| New South Wales, Australia (March 2025) | A former temporary worker uploaded a spreadsheet with 10 columns and more than 12,000 rows from a flood-recovery housing program to ChatGPT. | 2,031 people were affected, with names, addresses, dates of birth and health information exposed. The authority now blocks uploads of personal information to AI tools. |
| Netherlands (2024) | Breach notifications included a GP-practice employee entering patients' medical data into a chatbot and a telecom employee entering a file of customer addresses. | The Dutch data protection authority warned organisations that such use is a data breach. |
| Disney (2024) | An employee downloaded a program posted on GitHub as an AI art generator. It contained malware that gave the attacker access to the victim's personal computer and saved passwords. | About 1.1 TB of data was taken from thousands of internal Slack channels. The attacker agreed to plead guilty in May 2025. |
| Samsung (2023) | Sensitive internal data leaked to ChatGPT. | Samsung temporarily restricted generative AI on company devices and internal networks, TechCrunch reported. |
Is putting company data into ChatGPT a data breach?
It can be. The Dutch data protection authority, which enforces the GDPR in the Netherlands, says employees often use chatbots on their own initiative and against what they agreed with their employer, and put it plainly: "If personal data have been entered in the process, this means there is a data breach." Where chatbot use is company policy, it isn't a breach, the regulator added, but it often still isn't permitted by law.
Whether the data is also used to train models depends on the plan:
| Service and plan | Is your content used to train models? |
|---|---|
| ChatGPT for individuals | It may be, unless the user opts out in settings |
| ChatGPT Business, Enterprise, Edu and the API | Not by default |
| Claude Free, Pro and Max | The user chooses; if they allow training, chats are kept for five years |
| Claude for Work and the Anthropic API | Not by default |
| Microsoft Copilot and Copilot Chat (enterprise data protection) | No: prompts, responses and data accessed through Microsoft Graph aren't used to train foundation models |
| Gemini in Google Workspace | Not without the customer's permission or instruction |
No-training terms solve one problem, not all of them. Business data still leaves your network, may be retained, and can reach people who shouldn't see it once AI tools are connected to company systems. Netskope, a security vendor, reports that "downstream" violations — an AI service returning sensitive data that a user or agent isn't authorised to access — more than doubled over the past year, from 12 to 31 a week in the average organisation, as companies connected AI to more data stores.
Why do companies underestimate shadow AI?
Five blind spots recur in the evidence.
- They can't see it. Victoria's privacy regulator noted that organisations can't view staff prompt histories in ChatGPT, even when staff log in on the organisation's own systems; browsing logs show a visit to the site, not what was entered.
- They assume licences solved it. Buying enterprise AI moved many people, but Netskope's data shows the shift stopped around March 2026: 44% of AI users still use personal apps, alone or alongside managed ones.
- Governance is going backwards. IBM found 68% of breached organisations lacked AI governance to manage AI or detect shadow AI, up from 63%; the share requiring IT approval for AI deployments fell from 45% to 38%; and only 19% coordinate their governance and security teams.
- It's moving to agents. Gartner says employees and developers are adopting agentic AI and no-code tools in ways that drive unmanaged agent proliferation, and that security leaders must identify both sanctioned and unsanctioned agents. Netskope saw users of MCP, the open standard for connecting AI to tools and data, rise 250% in ten weeks.
- Approved access isn't the same as safe use. In January 2026, Politico reported that the acting director of CISA, the US cybersecurity agency, had uploaded contracting documents marked for official use only to ChatGPT under a special exception, setting off automated security warnings. The agency said the use was brief and limited.
Gartner expects the problem to grow: it predicts that by 2030 more than 40% of enterprises will have security or compliance incidents linked to unauthorised shadow AI.
Common misconception
"Shadow AI is a malicious-insider problem." It rarely is. The NCSC says shadow IT is seldom the result of bad intent; it usually comes from staff struggling to get work done with sanctioned tools. Treating it as misconduct pushes it further underground, while treating it as unmet demand tells you which tools to approve.
Should companies ban AI tools?
A blanket ban on its own doesn't appear to work, but blocking specific tools for specific roles is sometimes the right call.
The strongest warning comes from the KPMG and University of Melbourne study. Uploading sensitive information to public AI tools was most common among employees whose organisations had banned generative AI (67%) or had a policy guiding its use (56%), compared with 33% where there was no policy and 38% where staff weren't sure. The authors concluded that outright bans may be ineffective and that having a policy doesn't guarantee compliance. It's a correlation, not proof — organisations handling more sensitive data may be more likely to ban AI in the first place — but it's a warning against assuming a ban equals control.
The counter-case is Victoria. Its privacy regulator decided that in child protection the risk of harm was too great to manage with policy and guidance alone, and required network-level blocking of named AI tools plus regular scanning for new ones. Samsung took a similar, temporary step in 2023.
The pragmatic answer is to block where the harm would be severe or the tool is unsafe, and everywhere else to make the approved route easier than the unapproved one.
What this means
The goal isn't zero AI use; it's zero unseen AI use with sensitive data. When employees can get a good approved tool quickly, they have less reason to go around the rules, and the cases that remain stand out.
How do you find and manage shadow AI?
Start with discovery, then make approved tools the easy default and put technical controls where the data is most sensitive.
A shadow AI programme in five steps
- 01Discover
- Web and cloud-app logs
- OAuth app grants
- No-blame staff survey
Find what's actually in use
- 02Decide
- Risk-tier each tool
- Approve, restrict or block
- Fast request route
Say yes quickly to low risk
- 03Provide
- Enterprise AI workspace
- No-training terms
- Single sign-on and audit logs
Make the approved tool better
- 04Protect
- Data rules by class
- Upload blocking for IDs
- Connector reviews
Control where data can go
- 05Train and review
- Role-based training
- Live AI register
- Quarterly review
Keep the inventory current
- Build an inventory. NIST's generative AI profile suggests listing generative AI systems in the organisation's AI inventory, keeping approved lists of AI technology and service providers, and updating acceptable-use policies to cover contractors, consultants and other third parties. For UAE federal bodies and critical infrastructure operators, the national AI cyber security policy requires an up-to-date inventory of AI and machine-learning assets.
- Look in several places. Web and cloud-app logs show which AI services are used; reviews of OAuth grants show which AI apps can reach mail, files and the CRM; an anonymous survey with an amnesty reveals the rest. After the Drift theft, Google advised organisations to review all connected third-party integrations and to revoke and rotate their credentials.
- Offer an approved tool that's as good as the free one. Business tiers with no-training defaults, single sign-on and audit logs remove the main reasons to use personal accounts.
- Write data rules people can remember. Use three or four classes — public, internal, confidential, and personal or ID data — each mapped to the tools where it's allowed.
- Use technical controls where it matters. The NSW authority now blocks uploads of personal information to AI tools; Victoria required network-level blocking plus scanning for new tools.
- Manage agents as identities. Microsoft's 2026 Work Trend Index tells IT teams to treat agents as managed entities with identities, permissions, policy enforcement and lifecycle management; Gartner adds incident-response playbooks for agent risks.
- Train for behaviour, not awareness. Gartner says existing security awareness efforts have failed to reduce generative AI risk and recommends adaptive, behaviour-based programmes with AI-specific tasks. The European Commission expects staff using ChatGPT at work to be told about specific risks such as hallucination.
These controls slot into a wider AI governance framework — risk tiers, an accountable committee and monitoring in production — and the same logic applies to AI browsers, which send page content to the cloud and can act on staff accounts.
What do UAE and EU rules say about shadow AI?
No law mentions shadow AI by name, but several apply to it.
| Rule | Who it covers | What matters for shadow AI |
|---|---|---|
| UAE Personal Data Protection Law (Federal Decree-Law 45 of 2021) | Organisations processing personal data of UAE residents, whether based in the UAE or abroad; DIFC and ADGM run their own regimes | Security measures (Article 20), reporting personal data breaches (Article 9) and rules on transferring personal data abroad (Articles 22–23) |
| DIFC Regulation 10 | DIFC firms processing personal data through autonomous and semi-autonomous systems | A register of AI processing activities, an Autonomous Systems Officer in some cases, and assessment of high-risk processing |
| ADGM Data Protection Regulations 2021 | ADGM-registered entities | Enforced by ADGM's Office of Data Protection |
| UAE National Cyber Security Policy for AI (v1.1, 2025) | Federal ministries and authorities, and non-government critical information infrastructure | An up-to-date AI asset inventory and management of AI supply-chain risk |
| EU AI Act, Article 4 | Providers and deployers of AI systems covered by the Act | AI literacy for staff and others using AI on their behalf |
Three details matter for UAE firms. First, the PDPL's implementing regulation still hadn't been issued as of March 2026, according to Chambers and Partners, which has limited enforcement; the law gives companies six months to comply once it is. Second, the law's definition of personal data explicitly includes identification numbers, so passport and Emirates ID copies are squarely covered. Third, if a consumer AI service processes data outside the UAE — and the employee rarely knows where it does — pasting personal data into it raises the law's cross-border questions.
In the EU, the AI Act's literacy duty has applied since February 2025, with national enforcement from August 2026. The Digital Omnibus amendments that took effect in mid-July 2026 kept the obligation but no longer prescribe a specific level of literacy, and the Commission says no certificate is needed. For a company whose staff use ChatGPT, it expects employees at least to be informed of specific risks such as hallucination. This section is a summary, not legal advice.
What should real-estate firms do about shadow AI?
Property businesses hold exactly the data shadow AI leaks: passport and Emirates ID copies, tenancy contracts, bank letters and buyers' finances, much of it moving through WhatsApp and agents' own phones.
No regulator has published a real-estate shadow AI incident in the sources reviewed for this guide. The closest parallel is the NSW case: a temporary worker uploading a housing-program spreadsheet with names, addresses, dates of birth and financial commentary. Brokerages that rely on freelance agents and outsourced marketing teams carry the same exposure, which is why NIST's guidance extends acceptable-use policies to contractors and consultants.
Common patterns worth checking for in a brokerage or developer:
- Pasting a buyer's passport or ID details into a chatbot to fill in forms or draft documents
- Uploading tenancy contracts or sale agreements to translate or summarise them
- Feeding exported WhatsApp chats into an AI tool to write follow-ups
- AI note-takers recording client calls without an approved vendor
- Personal AI assistants connected to the CRM or company email
A practical checklist:
- Choose one approved AI workspace with business terms and single sign-on, and connect it where agents already work, such as the CRM.
- Ban ID documents, bank details and client financials from any unapproved AI tool, and block uploads technically where you can.
- Put freelancers, agencies and contractors under the same policy and contract terms.
- Review every quarter which AI apps have OAuth access to company email, drives and the CRM.
- Keep an AI register; DIFC firms processing personal data through AI systems need one anyway.
- Decide in advance who assesses whether a paste of client data is a reportable breach under the PDPL.
Final takeaway
Shadow AI is what happens when employees find AI more useful than their employer's rules allow. The evidence says it's widespread, increasingly costly and spreading from chatbots to agents and connected apps, and that bans on their own don't make it go away. Companies that get ahead of it do three things: they find out what's actually in use, give people an approved tool as good as the one they'd use anyway, and draw clear lines around the data that must never leave. For UAE firms holding passport copies and client finances, those lines are also what data protection law expects.
AI strategy
Working out where AI fits in your business?
I help teams separate the use cases worth automating from the ones that only demo well — then build the workflow, the integrations and the guardrails.
Sources
Primary sources checked for this article. Figures reflect the dates shown.
- Cost of a Data Breach Report 2026 — IBM (research by Ponemon Institute), July 29, 2026
- Cost of Data Breach — IBM, November 17, 2025
- What Is Shadow AI? — IBM, March 5, 2026
- Shadow IT guidance — UK National Cyber Security Centre, August 14, 2026
- Trust, attitudes and use of artificial intelligence: A global study 2025 — University of Melbourne and KPMG, May 1, 2025
- Trust, attitudes and use of artificial intelligence: A global study 2025 — UAE insights — University of Melbourne and KPMG, May 1, 2025
- AI at Work Is Here. Now Comes the Hard Part — Microsoft and LinkedIn (Work Trend Index), May 8, 2024
- 2026 Work Trend Index report: Agents, human agency, and opportunity — Microsoft, May 5, 2026
- Gartner Identifies Critical GenAI Blind Spots That CIOs Must Urgently Address — Gartner, November 19, 2025
- Gartner Identifies the Top Cybersecurity Trends for 2026 — Gartner, February 5, 2026
- Cloud and Threat Report: 2026 — Netskope Threat Labs, January 6, 2026
- Netskope AI Report: 2026 — Netskope Threat Labs, July 27, 2026
- Investigation into the use of ChatGPT by a Child Protection worker — Office of the Victorian Information Commissioner, September 24, 2024
- OVIC finds department responsible for breaches of privacy through use of ChatGPT — Office of the Victorian Information Commissioner
- Caution: use of AI chatbot may lead to data breaches — Autoriteit Persoonsgegevens (Dutch Data Protection Authority), August 6, 2024
- Resilient Homes Program data breach — NSW Government (NSW Reconstruction Authority), March 27, 2026
- Santa Clarita Man Agrees to Plead Guilty to Hacking Disney Employee's Computer, Downloading Confidential Data from Company — U.S. Attorney's Office, Central District of California, May 1, 2025
- Widespread Data Theft Targets Salesforce Instances via Salesloft Drift — Google Threat Intelligence Group, August 26, 2025
- Samsung bans use of generative AI tools like ChatGPT after April internal data leak — TechCrunch, May 2, 2023
- Trump's acting cybersecurity chief uploaded sensitive government docs to ChatGPT — TechCrunch, January 28, 2026
- How your data is used to improve model performance — OpenAI Help Center
- Is my data used for model training? — Anthropic Privacy Center, August 18, 2026
- Updates to Consumer Terms and Privacy Policy — Anthropic, August 28, 2025
- Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat — Microsoft Learn
- Generative AI in Google Workspace Privacy Hub — Google Workspace Help
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) — NIST, July 2024
- AI Literacy - Questions & Answers — European Commission, July 27, 2026
- Data protection laws — The Official Platform of the UAE Government (u.ae), December 4, 2025
- Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (Arabic text) — UAE Government
- Personal Data Protection Law — UAE Artificial Intelligence Office
- Data Protection & Privacy 2026 — UAE: Trends and Developments — Chambers and Partners, March 10, 2026
- Regulation 10 on Personal Data Processed through Autonomous and Semi-Autonomous Systems — DIFC Commissioner of Data Protection, August 27, 2024
- ADGM Office of Data Protection — Abu Dhabi Global Market
- National Cyber Security Policy for Artificial Intelligence (v1.1) — UAE Cyber Security Council, November 2025


