The average organization now runs seven AI tools — up from just two in 2023 — according to ActivTrak’s 2026 State of the Workplace report. Additional research indicates that most of that growth is happening outside IT’s line of sight. This gap between adoption and oversight is what security and IT leaders now call shadow AI, and closing it has become one of the defining IT tool governance challenges of 2026.
What is shadow AI?
Shadow AI refers to AI tools, models or AI-embedded features that employees use for work without formal review or approval from IT or security. It includes everything from a manager pasting a sales deck into a public chatbot to a developer running proprietary code through an unauthorized AI coding assistant. These unseen tools can lead to privacy issues, data leaks or other potential breaches; this is why AI tool visibility is crucial.
The risk is rarely malicious. Employees adopt these tools because they solve a problem faster than the sanctioned alternative, not because they intend to expose company data.
ActivTrak integrated AI insights to provide a deeper look into common forms of shadow AI tools including:
- Public generative AI chatbots used for drafting, summarizing or analyzing sensitive documents
- Personal AI coding assistants connected to production codebases
- AI features embedded inside already-approved SaaS platforms, but never reviewed by security
- Browser extensions and plugins that route company data through third-party AI models
In 2023, Samsung banned employee use of ChatGPT after engineers uploaded proprietary source code to the platform while trying to debug it faster. The incident became a widely cited example of how one well-intentioned shortcut can expose sensitive intellectual property. It’s also why shadow AI is now a board-level concern rather than a niche IT issue.
Shadow AI vs. shadow IT: What’s different
Shadow IT describes any unapproved technology — apps, devices or cloud services — running inside an organization without IT’s knowledge. Shadow AI is a subset of that broader problem, but it behaves differently.
Most shadow IT requires installing software or provisioning an account, which leaves a discoverable trail. Shadow AI often requires nothing more than opening a browser tab, which makes it far harder to catch with traditional network or device-based detection.
Shadow AI vs. shadow IT at a glance
| Shadow IT | Shadow AI | |
| Typical entry point | Unapproved app or device install | Public website, browser tab or embedded feature |
| Detection method | Network and endpoint discovery | Behavioral and usage-pattern visibility |
| Primary risk | Unmanaged software sprawl | Data exposure through model inputs |
| Growth driver | Convenience and cost | Speed and individual productivity |
Why shadow AI is spreading inside your organization
Tool sprawl is now the norm, not the exception. The average organization uses seven AI tools, and 83% of organizations use six or more, per ActivTrak’s 2026 State of the Workplace report.
Meanwhile, employees are outpacing policy. McKinsey’s 2025 State of AI survey found that 88% of organizations now use AI in at least one business function, yet most remain in early piloting stages rather than governed, scaled deployment.
Only 3% of users currently fall into the productivity ‘sweet spot’ where AI usage translates into measurable performance gains, according to the same ActivTrak data. The other 97% are either underusing sanctioned tools or improvising with unsanctioned ones.
Employees turn to unsanctioned AI because:
- Approved tools feel slower or more restrictive than public alternatives
- Policy and training haven’t kept pace with how quickly new AI tools appear
- Employees rarely see a clear line between using AI and using AI without permission
The real risks of unsanctioned AI use
The most immediate risk is data leakage. Every prompt submitted to an unmanaged AI tool is a potential exposure point for source code, customer records or strategic plans.
Compliance exposure compounds the problem. Gartner has warned that more than 40% of organizations will face security or compliance incidents tied to unauthorized AI tools by 2030, a figure that should concern every regulated industry.
There’s also an unvetted-output risk: decisions built on AI-generated content that no one reviewed for accuracy or bias. IBM’s June 2026 Tech Leader Study found 70% of technology executives note that AI deployment is now faster than IT is able to track, and two-thirds say they’re responsible for AI systems over which they don’t hold full control.
What’s at stake:
- Intellectual property and customer data entered into unapproved tools
- Regulatory violations in privacy-sensitive industries like finance and healthcare
- Business decisions built on AI outputs no one has fact-checked
How to detect shadow AI in your organization
Most shadow AI detection strategies start and end at the network layer: CASBs, proxy logs and endpoint agents that flag known AI domains. That approach misses AI tools used on personal devices or accessed outside the monitored network.
Workforce analytics closes that gap by looking at how work actually gets done, not just what traffic crosses the firewall. Behavioral usage data — which applications employees spend time in, how that mix has shifted, and where new tools appear — surfaces unsanctioned AI adoption that network tools alone can’t see.
ActivTrak’s Technology Usage and AI Insights capabilities apply this approach, giving leaders visibility into software and AI adoption patterns across the organization from a single dashboard.
This kind of visibility reveals:
- Sanctioned or unsanctioned AI tools used by the company
- How usage intensity compares across teams, departments and locations
- Where license spend and shadow tool adoption overlap, so IT can consolidate rather than simply block
Building a practical AI governance strategy
Banning AI outright rarely works, and it tends to push usage further into the shadows. A practical governance strategy combines clear policy, viable sanctioned alternatives and ongoing visibility into one framework rather than three disconnected initiatives.
That framework should:
- Publish a plain-language AI usage policy that defines what data can and can’t be shared with AI tools.
- Offer sanctioned AI alternatives that are genuinely competitive with the shadow tools employees already prefer.
- Monitor adoption continuously through workforce management and productivity management tools, so governance evolves with real usage instead of a static annual review.
Combining these three elements shifts the conversation from restriction to enablement and creates a policy employees follow instead of one they try to maneuver around.
Governance starts with visibility
Shadow AI isn’t going away, and blocking it outright only pushes the problem further out of view. Governance starts with visibility, and visibility starts with understanding how work and AI adoption actually intersect across your organization.
ActivTrak’s AI Insights gives IT and security leaders a clear view into AI and software usage, alongside the broader features and solutions that make up the ActivTrak platform.
See how it works, explore options built for enterprise and hear from customers already closing their AI visibility gap.
Uncover the shadow IT in your organization. Request a demo of ActivTrak’ or contact our team to talk through your AI governance strategy.
