Shadow AI: What It Is, What It Costs, and How Enterprises Govern It
An inventory of AI applications is no longer an inventory of enterprise AI use. And a sanctioned AI tool is not the same as governed AI execution.
Definition
What is shadow AI?
Shadow AI is the use, development or deployment of artificial intelligence for organizational work outside sufficient organizational approval, visibility or governance. It can include employees using personal AI accounts, but the category now extends beyond unauthorized chatbots to AI coding assistants, model APIs, locally hosted models, agents, MCP servers and AI-enabled workflows operating outside established controls.
Microsoft’s current definition explicitly encompasses AI-powered tools and agents used without IT awareness or approval, including unauthorized coding assistants, local agents, MCP servers and agentic command-line tools. Netskope’s 2026 research similarly reports that shadow-AI discovery has expanded beyond personal AI applications to agents, MCP servers and local AI infrastructure.
Shadow AI is not limited to whether procurement approved a particular vendor. The governance question can involve the AI asset, the account being used, the data entering it, its integrations and permissions, or the business workflow being executed.
The Evidence
Shadow AI at a glance
Six figures from 2026 research, each shown with the population it was measured against.
30%
used only personal AI applications
Netskope AI Report 2026 (observed enterprise AI users; another 14% used both managed and personal)
43%
reported security incidents involving shadow AI
IBM Cost of a Data Breach 2026 (602 breached organizations; up from 20% in the prior study)
$5.39M
average cost of a breach involving shadow AI
IBM 2026, among breached organizations studied, vs. a $4.99M global average that year
39.7%
of AI interactions involved sensitive data
Cyberhaven 2026 AI Adoption & Risk Report (telemetry across 222 companies)
38%
have a formal, comprehensive AI policy
ISACA 2026 AI Pulse Poll (3,400+ digital-trust professionals; 90% believed employees were using AI)
26%
say leadership is clearly aligned on AI
Microsoft 2026 Work Trend Index (20,000 AI-using knowledge workers across 10 markets)
Taxonomy
The five forms of shadow AI
Not every instance looks like an employee with a personal chatbot tab open.
That last case is why enterprises should distinguish AI asset visibility from AI execution visibility. Using an approved AI system does not automatically make the system itself shadow AI — but the execution practices inside it can still be invisible.
Surface Area
What counts as shadow AI today?
Shadow AI now has a much broader technical surface than consumer chatbots alone.
| Example | Why it can become shadow AI |
|---|---|
| Personal ChatGPT, Claude, Gemini or other AI account | Organizational work occurs outside enterprise account controls |
| Unapproved AI SaaS application | Security and IT may lack visibility into the application and its data practices |
| AI coding assistant | Proprietary code or technical context can enter an unmanaged AI workflow |
| Model API | Developers can embed AI into applications without normal AI governance |
| Local LLM | Models can operate on endpoints outside centralized inventory and oversight |
| AI agent | An agent can access data, invoke tools and execute actions |
| MCP server | It can connect AI systems with enterprise tools and resources outside established controls |
| Agentic CLI | AI capabilities can enter developer workflows through endpoint tools |
| Embedded AI feature | A sanctioned SaaS vendor can introduce AI functionality into an already-approved application |
| Unregistered internal AI workflow | The individual components may be approved while the combined business process remains insufficiently governed |
The unit of governance is shifting from “which AI websites are employees visiting?” toward “which AI systems, connections and execution practices are participating in enterprise work?”
Methodology
How common is shadow AI?
There is no single percentage. Different studies measure different populations, so here they are side by side with what each one actually covers.
| Measure | Source | Method / population | Finding | Important limitation |
|---|---|---|---|---|
| Personal vs. managed AI use | Netskope AI Report 2026 | Platform telemetry, Jun. 2025 – Jul. 2026 | 30% personal-only; 14% personal + managed | Measures users in Netskope's observed environment, not all employees globally |
| Sensitive data in AI interactions | Cyberhaven 2026 AI Adoption & Risk Report | Telemetry across 222 companies | 39.7% of AI interactions involved sensitive data | Does not establish that every interaction caused a harmful disclosure |
| Shadow-AI security incidents | IBM Cost of a Data Breach 2026 | 602 breached organizations | 43%, up from 20% in the prior study | Breached organizations are not representative of all organizations |
| Formal comprehensive AI policy | ISACA 2026 AI Pulse Poll | 3,400+ digital-trust professionals | 38% | Policy existence does not establish policy effectiveness |
| AI leadership alignment | Microsoft 2026 Work Trend Index | 20,000 AI-using knowledge workers across 10 markets | 26% report clear, consistent leadership alignment | Measures employee perceptions of organizational alignment |
Survey evidence tells us what employees and organizations report. Telemetry tells us what participating security platforms observe. Breach research tells us what appears among organizations that have already experienced a breach. Three different questions, three different populations. What they agree on: AI adoption is occurring outside fully managed enterprise paths at meaningful scale.
Cost
What does shadow AI cost?
$5.39M
Average breach involving shadow AI
Among the 602 breached organizations in IBM’s 2026 study
$4.99M
Global average breach cost
Across all breaches in the same 2026 study
The costs breach accounting does not capture
Financial loss is one dimension. Poorly governed AI also creates operational costs that never appear in an incident ledger:
- Work that cannot be reproduced
- Outputs whose provenance cannot be established
- Duplicated prompts and workflows
- Inconsistent processes across teams
- AI-assisted decisions that cannot be reconstructed
- Dependencies on privately maintained instructions
- Outdated workflows that continue to be reused
- Governance work performed retrospectively rather than by design
These issues connect shadow AI to a broader problem: AI Execution Debt.
Root Cause
Why do employees use shadow AI?
Shadow AI is often framed primarily as an employee-compliance problem. That explanation is incomplete.
Employees route around the sanctioned path when the sanctioned path does not adequately serve the task they need to complete. That failure takes several forms:
- The organization has not provided an approved AI option
- The approved option lacks required capabilities
- Obtaining access takes too long
- Employees do not know which tools are permitted
- Governance guidance is unclear
- The sanctioned workflow creates excessive friction
- Employees learned effective practices outside the formal AI environment
The organizational context supports this reading. ISACA’s 2026 poll found widespread perceived AI use but only 38% of respondents reporting a formal, comprehensive organizational AI policy. Microsoft’s 2026 Work Trend Index found only 26% of surveyed AI users saying leadership was clearly and consistently aligned on AI.
AI adoption happens at individual-user speed while enterprise governance operates at organizational speed.
A governance strategy has to address that mismatch rather than assuming policy publication alone will remove it.
The Shadow AI Demand Model
Treat an instance of unsanctioned AI use as information about the organization, not only as a policy violation. This is a PromptFluent framework, not an industry standard.
A real task exists
Someone believes AI can help perform actual work. That represents demand.
The sanctioned path failed somewhere
Availability — no approved solution exists. Capability — the approved solution cannot do the task. Speed — access takes too long. Awareness — a solution exists but the employee does not know about it.
The governance layer did not capture the work
The organization loses both risk visibility and useful information about where AI demand exists.
Instead of asking only “who used an unauthorized tool?” also ask:
“What were they trying to accomplish, and why did the governed path fail to serve that task?”
Shadow-AI discovery then becomes both a risk signal and a demand signal for enterprise AI.
Comparison
Shadow AI vs. shadow IT
Shadow AI evolved from shadow IT, but AI changes both the risk surface and the unit of governance.
| Shadow IT | Shadow AI |
|---|---|
| Unauthorized software or cloud service | Unmanaged AI apps, models, agents, APIs and execution |
| Often creates a procurement, identity or access footprint | Can begin with a free account, API key, local model or embedded capability |
| Primary governance object is often the application | Governance can extend to model, account, data, prompt, agent, workflow and action |
| Software generally executes predefined functionality | Generative AI produces probabilistic outputs |
| Application discovery can reveal much of the problem | Discovering the AI application may not reveal what work is occurring inside it |
| Primarily human-operated | Agents can increasingly execute multi-step actions |
| Access can often be revoked | Information already disclosed to an external system cannot simply be “unsubmitted” |
The most important distinction is not that shadow AI is entirely different from shadow IT. It is that AI makes application-level visibility insufficient for some governance questions.
Adjacent Problem
Shadow AI vs. AI agent sprawl
Shadow AI
AI operating outside sufficient organizational visibility, approval or governance.
AI agent sprawl
Proliferation of agents without adequate coordination, lifecycle management, ownership or rationalization.
An agent can therefore be:
- Sanctioned and well governed
- Sanctioned but part of an agent-sprawl problem
- Unauthorized, and therefore shadow AI
- Both unauthorized and part of agent sprawl
The distinction matters because remediation differs. Shadow AI requires discovery, assessment and governance. Agent sprawl additionally requires lifecycle management, ownership, architecture and rationalization.
Risk
What are the biggest shadow AI risks?
The governance question is not merely which AI tool the employee used. It is:
What information entered the AI workflow, under what policy, for what purpose, and what happened next?
Detection
How do organizations detect shadow AI?
Shadow-AI discovery is primarily a security and observability function.
Network and proxy telemetry
CASB, SASE and secure web gateways can identify traffic to AI services and, depending on implementation, enforce policy.
Endpoint and browser telemetry
Endpoint agents and browser controls provide visibility into AI applications and data movement.
Identity signals
SSO and directory data distinguish organization-managed accounts from personal ones and reveal AI operating outside enterprise identity.
AI asset discovery
Modern discovery needs to cover applications, APIs, agents, local AI infrastructure and MCP servers — not SaaS applications alone.
Procurement and expense signals
Individual subscriptions and unapproved vendor spend remain useful shadow-IT indicators.
Employee disclosure
Telemetry shows that something happened. Employees can explain what task they were performing and why the sanctioned path did not serve it.
PromptFluent is not a network-level shadow-AI discovery, CASB, DLP or endpoint-security product. Those technologies address an important problem: finding and controlling AI activity occurring outside approved enterprise boundaries.
Strategy
Is blocking AI the solution to shadow AI?
Not by itself.
Blocking a high-risk application can be appropriate when its use creates unacceptable security, privacy or compliance risk. But blocking addresses access to a tool. It does not eliminate the business task that caused someone to seek the tool.
The prohibition-only cycle
- business demand
- unavailable sanctioned path
- unauthorized workaround
- detection
- blocking
- unresolved business demand
The stronger governance objective is to reduce both the risk and the incentive to leave the sanctioned environment. That means combining controls with viable approved alternatives.
Framework
How can enterprises govern shadow AI?
A mature approach can be organized around six capabilities. Treat them as a sequence, not a menu.
Discover
Identify the AI actually participating in enterprise work: applications, personal vs. enterprise accounts, model APIs, local models, coding assistants, agents, MCP servers, AI-enabled integrations and emerging execution surfaces.
Inventory
Maintain an authoritative inventory of sanctioned AI assets and accountable owners. It should answer more than “which vendor did we buy” — which systems are approved, who owns them, what they may do, and which enterprise resources they can reach.
Classify
Risk is contextual. Classify by data sensitivity, business purpose, model or provider, autonomy, external connectivity, decision impact, regulatory relevance, human oversight and the consequences of failure.
Govern
Define what is permitted, prohibited, conditional, subject to approval, subject to human review, and subject to additional monitoring or records. Policy establishes authority — but policy alone is not execution.
Provide a better sanctioned path
Give employees capabilities that solve the tasks creating demand: approved tools, reusable instructions, governed prompts, approved workflows, clear ownership and guidance without unnecessary friction. The goal is not making unauthorized AI harder to use. It is making governed AI easier to use correctly.
Monitor execution
For repeatable, consequential or regulated AI-assisted work: which prompts and instructions were used, which workflow ran, which model or version participated, who owned and approved it, what changed, and what execution evidence exists.
Why detection alone is not enough
Detection answers where unmanaged AI is occurring. It does not answer why the employee left the governed path, or how the underlying work should be performed going forward. A useful remediation loop:
- Discover
- Understand the task
- Classify the risk
- Provide a governed path
- Monitor execution
- Use residual shadow AI as feedback
This turns shadow-AI discovery from a recurring enforcement exercise into an input to enterprise AI operating design.
Maturity
From shadow AI to governed AI execution
A second-order problem appears once enterprises succeed at moving employees onto approved AI platforms. The platform is sanctioned. The execution layer may still be poorly governed.
Stage 1
Shadow AI
What AI activity don't we adequately see or govern?
Stage 2
Visible AI
What AI is actually being used?
Stage 3
Sanctioned AI
Which AI systems and uses have we approved?
Stage 4
Governed AI
What policies, ownership and controls apply?
Stage 5
Governed AI Execution
Can we manage and understand how AI-mediated work is actually executed?
A sanctioned tool is not the same as governed execution.
This is the distinction most shadow-AI programs eventually encounter.
Where PromptFluent Fits
Discovery is a security problem. Execution is ours.
PromptFluent addresses the execution layer enterprises confront as they bring AI into governed use. It is an enterprise AI execution infrastructure and governance platform, and a system of record for prompts, workflows, governance and execution intelligence — so important AI practices stop living in personal documents, ad hoc prompt collections and disconnected workflows.
Shadow AI and AI Execution Debt
An enterprise can substantially reduce shadow AI by standardizing on sanctioned platforms and still accumulate AI Execution Debt if the prompts and workflows operating inside those platforms remain fragmented or poorly governed.
Shadow AI and Prompt Debt
An organization could have zero unauthorized AI applications and still have hundreds of employees independently maintaining competing prompts for the same processes. That is not necessarily shadow AI. It is still Prompt Debt.
The strategic objective is larger than eliminating unauthorized AI: move from invisible AI use toward visible, governable and measurable AI execution.
FAQ
Shadow AI FAQs
What is a simple definition of shadow AI?
Shadow AI is AI used, built or deployed for organizational work outside sufficient organizational approval, visibility or governance. It can include personal AI accounts, unauthorized applications, APIs, local models, coding assistants, agents, MCP servers and unregistered AI workflows.
Is using ChatGPT at work shadow AI?
Not automatically. Using an organization-approved enterprise ChatGPT environment in accordance with applicable controls is not inherently shadow AI. Using a personal account for company work can constitute shadow AI when that activity occurs outside the organization's approved and governed path. The same principle applies to Claude, Gemini and other AI systems.
Are AI agents shadow AI?
Not inherently. An inventoried, approved and governed AI agent is not shadow AI simply because it is autonomous. An agent created, connected or deployed outside applicable organizational controls can become shadow AI.
Can an approved AI tool still create governance problems?
Yes. Tool approval does not mean that every prompt, workflow, agent or AI-assisted process operating through that tool is consistently governed. This is why enterprises increasingly need to distinguish AI asset governance from AI execution governance.
What is the difference between shadow AI and shadow IT?
Shadow IT concerns technology adopted outside established IT controls. Shadow AI is closely related but introduces additional governance questions around models, prompts, context, outputs, agents and AI-mediated actions. Discovering an application may be sufficient to identify much of a shadow-IT problem. With AI, discovering the application may still leave the organization unable to explain what AI-mediated work occurred inside it.
What percentage of employees use shadow AI?
There is no single defensible universal percentage, because studies measure different populations and behaviors. Netskope's 2026 telemetry found 30% of observed enterprise AI users using only personal AI applications and another 14% using both managed and personal applications. Other surveys measure policy violations, organizational governance or breach involvement rather than the same behavior, so the figures are not interchangeable.
What does shadow AI cost?
IBM's 2026 breach research found that among the 602 breached organizations studied, breaches involving shadow AI averaged $5.39 million, compared with a $4.99 million global average across all breaches in that year's study. It describes the breaches in that study, not an expected loss for every organization.
Is shadow AI illegal?
Not inherently. Legal and regulatory consequences depend on what AI is used for, which information is processed, contractual obligations, jurisdiction, industry and applicable AI or data-protection requirements. Shadow AI can nevertheless make compliance harder because the organization may lack visibility, records, controls or accountable ownership.
How do you detect shadow AI?
Organizations can use network and proxy telemetry, CASB and SASE controls, endpoint and browser monitoring, identity signals, AI asset discovery, procurement data and employee disclosure. Modern discovery increasingly needs to cover agents, APIs, MCP servers and local AI infrastructure as well as browser-based AI applications.
Does an AI acceptable-use policy stop shadow AI?
Not by itself. Policies establish organizational rules and authority, but they do not automatically provide an approved alternative, detect violations or enforce controls at the point of use. Effective governance combines policy with discovery, usable sanctioned capabilities, technical controls, ownership and monitoring.
Should companies block unauthorized AI?
They should block AI use where the risk justifies it, but blocking should not be the entire shadow-AI strategy. The business task that caused the employee to seek AI still exists. Enterprises should pair appropriate restrictions with governed alternatives that adequately serve legitimate work.
Who owns shadow-AI governance?
Responsibility commonly spans security, IT, privacy, legal and compliance, AI governance, and the business functions performing the work. The important requirement is explicit accountability rather than assuming shadow AI belongs exclusively to one function.
How does PromptFluent help enterprises govern shadow AI?
PromptFluent addresses the AI execution governance layer. Security and discovery technologies can identify unauthorized AI applications and other unmanaged AI assets. PromptFluent helps enterprises manage the prompts, workflows, governance practices and execution intelligence involved in putting AI to work. That makes PromptFluent complementary to shadow-AI discovery rather than a replacement for it.
Does PromptFluent detect unauthorized AI applications?
PromptFluent is not a network or endpoint shadow-AI discovery product. Security technologies are better suited to discovering traffic, applications, accounts, agents and data movement outside the PromptFluent environment. PromptFluent addresses what happens as enterprises establish a governed execution path for AI work.
How does prompt governance relate to shadow AI?
Business-critical prompts can remain fragmented and poorly governed even inside sanctioned AI platforms. Prompt governance brings management discipline to those instructions by treating them as enterprise assets rather than disposable text. This addresses a governance problem that can persist after unauthorized tools have been eliminated.
How does AI workflow governance relate to shadow AI?
AI-supported work increasingly combines prompts, models, context, human decisions, tools and multiple execution steps. When those workflows develop independently, organizations can lose visibility into how AI-assisted work is being performed even when individual technologies are approved. AI workflow governance extends governance from the AI asset into the business process.
Can PromptFluent help move an organization from shadow AI to governed AI?
PromptFluent can support the governed execution portion of that transition. A useful progression is: Shadow AI, Visible AI, Sanctioned AI, Governed AI, Governed AI Execution. Security and discovery technologies help expose unmanaged AI. Enterprise governance determines what should be permitted. PromptFluent addresses the infrastructure and governance needed for the prompts and workflows through which sanctioned AI is executed.
Glossary
Shadow AI glossary
- Shadow AI
- AI use, development or deployment for organizational work outside sufficient organizational approval, visibility or governance.
- Shadow IT
- Technology adopted or used outside established IT approval and management processes.
- Sanctioned AI
- AI systems or uses that an organization has formally permitted under applicable policies and controls.
- AI agent
- An AI-enabled system capable of pursuing objectives and performing actions using models, tools or external systems.
- MCP server
- Infrastructure implementing the Model Context Protocol to make tools, resources or capabilities available to compatible AI applications.
- AI agent sprawl
- Proliferation of AI agents without sufficient coordination, ownership, lifecycle management or rationalization.
- Prompt governance
- Organizational management and governance of prompts as reusable AI execution assets.
- AI workflow governance
- Governance of the multi-step processes through which AI participates in organizational work.
- AI execution governance
- Governance of how AI-mediated work is actually executed, including prompts, workflows, models, versions, ownership, approvals and execution evidence.
- Prompt Debt
- Accumulated organizational consequences of fragmented, inconsistent, outdated or poorly governed prompt practices.
- AI Execution Debt
- Accumulated unmanaged, inconsistent, fragmented, outdated, poorly governed or unmeasured AI execution practices.
- Shadow AI Demand Model
- PromptFluent's framework for interpreting shadow-AI activity as evidence of a real business task, a failure in the sanctioned path and a gap in organizational visibility.
More definitions in the PromptFluent glossary.
Sources
Every figure on this page, and where it came from
Last evidence verification:
- 1
Microsoft — Understand Shadow AI in the Microsoft 365 admin center
Microsoft Learn, 2026. Current definition and examples covering AI-powered tools and agents, unauthorized coding assistants, local agents, MCP servers and agentic CLIs.
- 2
Netskope Threat Labs — Netskope AI Report 2026
Platform telemetry covering June 2025 – July 2026. Supports the 30% personal-only and 14% mixed managed-and-personal figures, and the expansion of discovery toward agents, MCP servers and local AI infrastructure.
- 3
IBM / Ponemon Institute — Cost of a Data Breach Report 2026
Published July 29, 2026. Research covering 602 breached organizations. Supports the $4.99 million global average breach cost and the 2026 shadow-AI breach findings.
- 4
Cyberhaven Labs — 2026 AI Adoption & Risk Report
Telemetry across 222 companies. Supports the finding that 39.7% of observed AI interactions involved sensitive data, and documents expanding use of agents and coding assistants.
- 5
ISACA — 2026 AI Pulse Poll
Published May 5, 2026. More than 3,400 digital-trust professionals. Supports the findings that 90% believe employees are using AI and 38% report a formal, comprehensive AI policy.
- 6
ISACA — Adopted, Not Governed: AI Blind Spot at the Heart of Enterprise Risk
Published March 23, 2026. Survey of 681 European digital-trust professionals. Supports the 59% incident-halting uncertainty and 11% complete-confidence findings.
- 7
Microsoft — 2026 Work Trend Index: Agents, Human Agency, and the Opportunity for Every Organization
Published May 5, 2026. Survey of 20,000 AI-using knowledge workers across 10 markets. Supports the 26% leadership-alignment finding.
Assess your AI execution governance
Shadow-AI discovery tells you where AI has escaped the governed path. The next question is whether the governed path itself can support repeatable, accountable enterprise AI execution.
Related: AI Governance Hub · AI Governance Framework · Prompt Governance · Prompt Debt