45% of professionals use shadow AI tools – here’s how to manage the risks

0
1
45% of professionals use shadow AI tools – here’s how to manage the risks


Maria Korneeva/Moment/Getty Images

ZDNET’s key takeaways

  • Shadow AI puts firms and their data at risk.
  • Business leaders should let people play with AI.
  • Carefully established guidelines are key to success. 

Shadow AI is rapidly becoming a massive issue for organizations. Research suggests 45% of employees used unsanctioned AI tools in the previous 30 days, and 36% used confidential data alongside these services.

Tal Carmi, CIO at technology specialist WalkMe, whose firm published its State of Digital Adoption 2026 report based on a global survey of 3,750 professionals, told ZDNET that the research shows shadow AI is often a symptom of a wider adoption problem: staff bypass sanctioned tools if they are difficult to use, do not fit naturally into existing workflows, or fail to help them get work done.

Also: Just 13% of professionals are confident using AI – how top companies solve this skills gap

“Usually, it’s not for malicious reasons,” he said, referring to why professionals use unsanctioned AI tools.

“It’s because they found a tool that does something and it’s better than whatever services the company provides. If they can’t find the sweet spot, people go where they can. And I think some of that approach is due to a lack of education.”

His firm’s research backs up Carmi’s assertion: 34% of professionals did not know which AI tools their employer had approved, and only 21% had been warned about their employer’s AI policies.

However, while professionals might use unsanctioned AI tools unwittingly or with the best of intentions, their errant actions can have serious consequences for their organizations.

Sensitive data can leak through tightly secured enterprise firewalls. Professionals’ unsanctioned use of AI services can also put businesses at risk of breaking rules and regulations, with potentially huge financial penalties.

Take the updated EU AI Act and Article 50, which introduces new transparency obligations. Companies that fail to comply could receive fines of €15 million, or 3% of total worldwide annual turnover.

Also: Why replacing staff with AI backfires – and 5 ways smart leaders generate real value instead

Carmi said the risk of shadow AI means bosses and professionals must maintain an uneasy balance between enabling and constraining emerging technologies.

“The easy thing would be to give the user an unrestricted toolset, which would be great for the employee, but horrible for the company and the CISO,” he said.

“The best approach for the CISO is a completely highly controlled, very limited toolset, which would be horrible for the employee.”

So, how can companies get the right balance? Business leaders said managing shadow AI relies on two key approaches: letting people play and establishing acceptable guidelines.

Let people play, carefully

Kirsty Roth, chief operating officer at Thomson Reuters, told ZDNET that finding the balance in her organization relies on a careful strategy, one that doesn’t prevent people from exploring AI before the constraints are put in place.

“The best people in your organization are curious when new things come out,” she said. “And whether it’s a new ChatGPT model or a new service from Claude, people want to go and play with it.”

Also: ‘Specialists aren’t required’: How to stay valuable in an AI agent workplace today

Roth recognized some of these explorations will be unsanctioned. Her own firm’s 2026 Future of Professionals Report found a third of lawyers, accountants, and compliance professionals use AI tools their organization has not approved, rising to 41% among those who say their firm is moving too slowly on AI.

However, while she acknowledged that unsanctioned use of AI tools can land a business in hot water, she also said that it’s difficult to constrain people until you understand the value of the services that they’re eager to exploit.

At Thomson Reuters, her wait-and-see strategy gave people some wiggle room to explore AI.

“Early on, we just tracked AI,” she said. “We didn’t stop it. We made sure we knew where they were going. We knew if we tried to block it, they’d probably do other things that are potentially worse, like move company data onto a personal device.”

Also: Companies embracing AI the most are hiring more people – including entry-level

By tracking AI explorations, Roth and her team developed a strategy that allowed professionals to test tools safely.

“We worked with the teams to say, ‘Right, we’ve got you proper access. We’d like you to switch to this service,’ and made sure we understood what they were using, and then quickly gave them the same things, but in an authorized channel where it was within our sandbox, the data wasn’t going anywhere, and the information around the company IP couldn’t be exposed.”

Roth said Thomson Reuters benefits from sophisticated cyber capabilities that show when people are moving information in or out. She advised other business leaders to proceed with care and establish a strategy that ensures their business doesn’t risk missing out on the potential competitive advantages that employee explorations into AI can bring.

“Early on, you could see people trying to use things because they were curious, and I think probably the art is to find a way to go with that and give them what they want versus being overly prescriptive and just find out that people are doing things in the wrong way.”

Establish accepted guidelines

WalkMe’s Carmi agreed that it’s essential for business leaders to create visibility into which AI tools employees use, what information they share, and how people rely on AI in their day-to-day work.

Also: AI is getting better at your job, but you have time to adjust, according to MIT

Without that understanding, organizations can’t govern AI use effectively or demonstrate responsible practice.

“I think success is about enablement and knowledge transfer. If they are using a tool, or they’re thinking about using it, try to understand why. Do you have a solution for them? Do you have something else that works?” he said.

“Because if you get them an AI tool that gives them 80% of the value, but is completely sanctioned, I think most people will say, ‘Okay, I’ll use it,’ especially once you make them aware that unsanctioned use is an actual risk to themselves and their companies.”

Like Carmi, Gill Haus, CIO at Chase, told ZDNET it’s crucial to recognize that very few people will use unsanctioned tools maliciously.

“I don’t know if I’d call it shadow AI because ‘shadow’ implies that someone’s off in the corner doing something we don’t want them to do,” he said.

Also: The new enterprise AI expert every company needs – and why

Haus said his organization’s AI controls are embedded in LLM Suite, Chase’s internal agentic platform that staff can use to ask questions, review documents, and create specifications.

LLM Suite was released in summer 2024 and provides access to large language models (LLMs) in a secure environment. This approach means Chase employees, both in the IT department and across the wider business, can try things with confidence and know they’re not breaking any rules.

“We want people to be using the technology to learn,” he said. “Everything goes through our trusted secure pipeline, meaning there isn’t a shadow.”

Also: AI agents are your new colleagues – how to get the best results

Haus advised other business leaders and their professionals to establish similar AI guidelines.

“Companies need to put thought into how to release these technologies because they are very powerful, and there’s lots of hype,” he said.

“Doing AI in a controlled, responsible way is the only way that we would do it. I believe it’s also the only way for other companies. Then, when people are using AI, you have confidence that if, for some reason, they make a mistake and do something wrong, you’re still in control.”