9 minute read

98% of enterprises have employees using unsanctioned AI tools. 43% have already pasted sensitive company information into them. The bans don’t work. Ignoring it is now a measurable financial liability. A consultant’s guide for senior leaders who want to get ahead of their own organisation.

Every senior leader I speak with in 2026 has a version of the same conversation. The CIO says the organisation has paused its formal AI rollout “until governance is in place.” The CMO mentions, almost in passing, that the content team has been using ChatGPT for months. The CFO asks, slightly too casually, whether the free-tier models are “safe to use on unpublished forecasts.” Meanwhile, the official AI policy is still in draft.

This is shadow AI: the use of unsanctioned AI tools inside the enterprise, on enterprise data, without IT visibility or leadership oversight. It is not a fringe behaviour. A 2025 Gartner analysis of more than 500 enterprises found that 68% of employees regularly use AI tools their organisation has not formally approved. Deloitte’s 2026 State of AI in the Enterprise found that worker access to AI rose by roughly 50% during 2025 — while only one in five organisations has a mature governance model. Other industry surveys now put the share of enterprises with some level of unsanctioned AI use at close to 98%.

The uncomfortable truth for senior leaders: your AI policy is already being written. It is being written by each individual employee, on each personal account, with every paragraph of customer data, financial forecast, or source code pasted into a free-tier chatbot. Unless you actively choose otherwise, your policy is going to be whatever those thousands of individual decisions happen to add up to.

The previous posts in this series dealt with the AI you deliberately deploy. This one deals with the AI your organisation is already using — whether you authorised it or not.

📊 Leadership Signal: If formal rollout is paused but teams are already using public AI tools, governance delay is now creating unmanaged exposure, not preventing it.

The problem is not your employees

It is tempting to treat shadow AI as an employee discipline issue. It is not. The people using unsanctioned AI tools are not rogue actors. They are productive, well-intentioned employees trying to meet the expectations their leaders have set for them. A 2025 study by the National Cybersecurity Alliance found that 43% of employees have shared sensitive work information with AI tools without their employer’s permission — and the same workers report that AI makes their work faster, better, and more responsive. When the approved tool is six months behind the free one, when IT approval takes three weeks and the deadline is Friday, employees do what employees always do: they find a path.

Shadow AI is a symptom of three gaps:

  • A capability gap — the approved tool is worse than the free one employees can access from their phones.

  • A clarity gap — employees don’t know what is encouraged, what is conditional, and what is off-limits.

  • A speed gap — the pace of approval inside the enterprise is slower than the pace of expectation outside it.

Close those gaps and shadow AI shrinks. Leave them open and no amount of policy documentation will matter.

✅ Leadership Action: Close one gap per month: capability first, clarity second, speed third. Sequenced intervention outperforms blanket restrictions.

The leadership paradox: the C-suite is modelling the behaviour

Here is the part most governance discussions quietly skip. Microsoft’s 2026 Data Security Index found that nearly 70% of presidents and C-suite executives openly prioritise speed over data privacy when adopting new AI tools. Leaders are not just failing to stop shadow AI — in many organisations, they are the power users. The senior partner drafting the board deck through ChatGPT on their iPad. The regional CFO summarising confidential deal terms through Claude before an investor call. None of them considers themselves reckless. They are moving fast because their calendars demand it.

The signal this sends is unambiguous. When leaders behave this way and then ask their teams to wait for policy, the policy is dead on arrival. BCG’s 2025 workforce survey found that only around a quarter of frontline workers say their leaders provide sufficient guidance on AI. The gap is not because leaders are absent. It is because leaders are doing the same thing their employees are doing — just with bigger stakes attached.

What shadow AI actually costs

Until recently, shadow AI risk was described mostly in hypothetical terms — “imagine if your customer data ended up in a training set.” In 2025 and 2026, the numbers arrived.

IBM’s 2025 Cost of a Data Breach Report — one of the most widely referenced security benchmarks in the industry — found that breaches involving high levels of shadow AI cost enterprises on average $670,000 more per incident than comparable breaches without it. Roughly one in five organisations surveyed reported a breach directly tied to shadow AI usage, and 97% of organisations that experienced an AI-related security incident lacked appropriate AI access controls. Containment for shadow AI breaches also takes approximately one week longer than average — because the security team cannot immediately identify who used which tool, when, and with what data.

The cost stack extends beyond the direct breach:

Risk category What it looks like in practice
Data leakage Proprietary code, customer data, financial forecasts, or M&A material pasted into free-tier models with broad data retention rights.
Regulatory exposure GDPR and EU AI Act violations when personal data is processed by non-approved providers or non-EU jurisdictions without legal basis.
IP contamination Content generated on unapproved tools may carry unclear ownership, training-data provenance issues, or licence conflicts.
Decision quality risk Business decisions made partly on hallucinated or unverified outputs that were never reviewed through formal processes.
Audit and forensic cost When incidents occur, investigators can’t quickly trace who used which tool or what data crossed the boundary.

For a large enterprise, the aggregate exposure is no longer a compliance footnote. It is a board-level liability that most cyber insurance policies written before 2024 do not explicitly cover.

Why bans don’t work

The instinctive leadership response to shadow AI is familiar: block it. Put ChatGPT on the firewall blocklist, issue a policy memo, run a training module. This approach was famously attempted early by Samsung in 2023, after internal engineers pasted proprietary semiconductor source code into ChatGPT during debugging. Samsung banned the tool company-wide. The data was already gone.

Bans fail for two reasons. First, they don’t change the underlying demand — the work still needs to be done, the deadlines are still there, and employees route around the block through personal devices, personal accounts, or the roughly 70% of AI interactions that by 2026 will happen inside SaaS products employees already legitimately use. Second, bans push usage further into the shadows. Once employees understand their AI use is officially forbidden but operationally necessary, they stop reporting incidents and flagging risky edge cases to IT. The organisation loses the one thing it needs most: visibility.

Every governance framework that has actually worked in the last two years starts from the same premise: you cannot govern what you are pretending doesn’t exist.

⚠️ Watch Out: Blocking tools without creating a better approved path pushes AI use underground and makes incidents harder to detect and contain.

A governance playbook that actually works

The enterprises that are handling shadow AI well are not the ones with the thickest policy binders. They are the ones that have done three things in sequence.

  1. Surface usage before sanctioning it. Before writing any policy, invest in visibility. Run an anonymous internal survey on AI usage. Deploy network and endpoint monitoring that identifies AI traffic without punishing users. Ask managers in each function to candidly list which tools are being used and for what. The goal is not to catch people — it is to size the problem honestly. Leaders who skip this step invariably write policies for a workforce that does not exist.

  2. Provide a safe default that is actually better than the shadow option. One study of healthcare enterprises found that when approved, enterprise-grade AI tools were provided, unsanctioned use dropped by nearly 90%. The lesson scales to every industry. If the approved tool is slower, clunkier, or six months behind the public model, employees will keep routing around it. Procurement and security need to optimise for the user experience as aggressively as they optimise for risk, or the governance model will never take hold.

  3. Publish a one-page permission framework, per function. Not a 40-page policy. A single page, per team, that answers three questions: where is AI encouraged, where is it conditional (and on what), and where is it off-limits? Examples help more than rules. “Yes to drafting customer emails; no to pasting customer PII. Yes to brainstorming pricing scenarios; no to uploading unpublished financials.” Signed by the function head. Visible on the intranet. Revisited quarterly.

These three moves, done together, compress the shadow AI problem faster than any ban ever has. They also produce something no policy document can: a living map of how AI actually flows through the organisation.

💡 Key Insight: Visibility plus a better default plus clear boundaries is the minimum viable governance stack for shadow AI. Remove any one layer and risk returns.

The leader’s 30-day plan

A concrete sequence for a senior leader who wants to get in front of this in the next month:

  • Week 1 — Commission a cross-functional shadow AI audit. Include IT, security, legal, HR, and a senior line-of-business representative. Make clear to employees that the purpose is visibility, not enforcement.

  • Week 2 — Identify the top three functions with the highest shadow AI usage and the highest data sensitivity. These are your intervention priorities.

  • Week 3 — Commit to an approved enterprise-grade tool for each of those functions, with a deployment date inside 60 days. Ruthless on user experience — if it’s worse than the free version, it will fail.

  • Week 4 — Publish the one-page permission framework for each function, signed by the function head. Pair it with a short, non-punitive communication that acknowledges the reality of current usage and names the path forward.

Inside 90 days, revisit. The organisations that do this consistently report that declared AI usage goes up (because employees stop hiding it) and shadow AI risk goes down (because the approved path is now genuinely faster). That is the shape of governance working.

The consultant’s takeaway

Shadow AI is not a compliance problem waiting for a compliance fix. It is a leadership test. The AI your organisation is already using is a reflection of where the capability gap, the clarity gap, and the speed gap sit inside your operating model. Closing those gaps is the work.

The leaders who will come out of 2026 with a governed, productive AI estate are not the ones who banned the tools or bought the most licences. They are the ones who looked honestly at what was already happening inside their organisation, built a credible alternative, and were clear with their people about where the lines actually are.

The question is not whether your organisation has a shadow AI problem. It does. The question is whether you are going to write the policy — or whether your employees already have.

✅ Leadership Action: In the next 30 days, run a cross-functional shadow AI audit, name the top three high-risk functions, and publish one-page usage boundaries with an approved enterprise-grade alternative.

Updated: