Home / Blog

What Is Shadow AI? How To Gain Visibility into Unsanctioned AI Tools

Shadow AI is spreading faster than most policies can track. Learn what it is, why it's risky and how workforce intelligence closes the visibility gap.

Suzanne Carroll

By Suzanne Carroll

What Is Shadow AI? How To Gain Visibility into Unsanctioned AI Tools
Table of contents

The average organization now runs seven AI tools — up from just two in 2023 — according to ActivTrak’s 2026 State of the Workplace report. Additional research indicates that most of that growth is happening outside IT’s line of sight. This gap between adoption and oversight is what security and IT leaders now call shadow AI, and closing it has become one of the defining IT tool governance challenges of 2026.

What is shadow AI?

Shadow AI refers to AI tools, models or AI-embedded features that employees use for work without formal review or approval from IT or security. It includes everything from a manager pasting a sales deck into a public chatbot to a developer running proprietary code through an unauthorized AI coding assistant. These unseen tools can lead to privacy issues, data leaks or other potential breaches; this is why AI tool visibility is crucial. 

The risk is rarely malicious. Employees adopt these tools because they solve a problem faster than the sanctioned alternative, not because they intend to expose company data.

ActivTrak integrated AI insights to provide a deeper look into common forms of shadow AI tools including:

  • Public generative AI chatbots used for drafting, summarizing or analyzing sensitive documents
  • Personal AI coding assistants connected to production codebases
  • AI features embedded inside already-approved SaaS platforms, but never reviewed by security
  • Browser extensions and plugins that route company data through third-party AI models

In 2023, Samsung banned employee use of ChatGPT after engineers uploaded proprietary source code to the platform while trying to debug it faster. The incident became a widely cited example of how one well-intentioned shortcut can expose sensitive intellectual property. It’s also why shadow AI is now a board-level concern rather than a niche IT issue.

Shadow AI vs. shadow IT: What’s different

Shadow IT describes any unapproved technology — apps, devices or cloud services — running inside an organization without IT’s knowledge. Shadow AI is a subset of that broader problem, but it behaves differently.

Most shadow IT requires installing software or provisioning an account, which leaves a discoverable trail. Shadow AI often requires nothing more than opening a browser tab, which makes it far harder to catch with traditional network or device-based detection.

Shadow AI vs. shadow IT at a glance

Shadow ITShadow AI
Typical entry pointUnapproved app or device installPublic website, browser tab or embedded feature
Detection methodNetwork and endpoint discoveryBehavioral and usage-pattern visibility
Primary riskUnmanaged software sprawlData exposure through model inputs
Growth driverConvenience and costSpeed and individual productivity

Why shadow AI is spreading inside your organization

Tool sprawl is now the norm, not the exception. The average organization uses seven AI tools, and 83% of organizations use six or more, per ActivTrak’s 2026 State of the Workplace report.

Meanwhile, employees are outpacing policy. McKinsey’s 2025 State of AI survey found that 88% of organizations now use AI in at least one business function, yet most remain in early piloting stages rather than governed, scaled deployment.

Only 3% of users currently fall into the productivity ‘sweet spot’ where AI usage translates into measurable performance gains, according to the same ActivTrak data. The other 97% are either underusing sanctioned tools or improvising with unsanctioned ones.

Employees turn to unsanctioned AI because:

  • Approved tools feel slower or more restrictive than public alternatives
  • Policy and training haven’t kept pace with how quickly new AI tools appear
  • Employees rarely see a clear line between using AI and using AI without permission

The real risks of unsanctioned AI use

The most immediate risk is data leakage. Every prompt submitted to an unmanaged AI tool is a potential exposure point for source code, customer records or strategic plans.

Compliance exposure compounds the problem. Gartner has warned that more than 40% of organizations will face security or compliance incidents tied to unauthorized AI tools by 2030, a figure that should concern every regulated industry.

There’s also an unvetted-output risk: decisions built on AI-generated content that no one reviewed for accuracy or bias. IBM’s June 2026 Tech Leader Study found 70% of technology executives note that AI deployment is now faster than IT is able to track, and two-thirds say they’re responsible for AI systems over which they don’t hold full control.

What’s at stake:

  • Intellectual property and customer data entered into unapproved tools 
  • Regulatory violations in privacy-sensitive industries like finance and healthcare
  • Business decisions built on AI outputs no one has fact-checked

How to detect shadow AI in your organization

Most shadow AI detection strategies start and end at the network layer: CASBs, proxy logs and endpoint agents that flag known AI domains. That approach misses AI tools used on personal devices or accessed outside the monitored network.

Workforce analytics closes that gap by looking at how work actually gets done, not just what traffic crosses the firewall. Behavioral usage data — which applications employees spend time in, how that mix has shifted, and where new tools appear — surfaces unsanctioned AI adoption that network tools alone can’t see.

ActivTrak’s Technology Usage and AI Insights capabilities  apply this approach, giving leaders visibility into software and AI adoption patterns across the organization from a single dashboard.

This kind of visibility reveals:

  • Sanctioned or unsanctioned AI tools used by the company
  • How usage intensity compares across teams, departments and locations
  • Where license spend and shadow tool adoption overlap, so IT can consolidate rather than simply block

Building a practical AI governance strategy

Banning AI outright rarely works, and it tends to push usage further into the shadows. A practical governance strategy combines clear policy, viable sanctioned alternatives and ongoing visibility into one framework rather than three disconnected initiatives.

That framework should:

  • Publish a plain-language AI usage policy that defines what data can and can’t be shared with AI tools.
  • Offer sanctioned AI alternatives that are genuinely competitive with the shadow tools employees already prefer.
  • Monitor adoption continuously through workforce management and productivity management tools, so governance evolves with real usage instead of a static annual review.

Combining these three elements shifts the conversation from restriction to enablement and creates a policy employees follow instead of one they try to maneuver around.

Governance starts with visibility

Shadow AI isn’t going away, and blocking it outright only pushes the problem further out of view. Governance starts with visibility, and visibility starts with understanding how work and AI adoption actually intersect across your organization.

ActivTrak’s AI Insights gives IT and security leaders a clear view into AI and software usage, alongside the broader features and solutions that make up the ActivTrak platform.

See how it works, explore options built for enterprise and hear from customers already closing their AI visibility gap.

Uncover the shadow IT in your organization. Request a demo of ActivTrak’ or contact our team to talk through your AI governance strategy.

Share this article

Meet the author

Array
Suzanne Carroll
Sr. Director, Product
Suzanne Carroll is Vice President of Product Management at ActivTrak and has 15 years of experience of designing and implementing data solutions for consumer and SAAS products, search engines, classifiers and machine learning solutions. She directs product and d... Read more
Suzanne Carroll is Vice President of Product Management at ActivTrak and has 15 years of experience of designing and implementing data solutions for consumer and SAAS products, search engines, classifiers and machine learning solutions. She directs product and design for ActivTrak’s reports, analytics and performance.
View author articles

Getting started is easy. Be up and running in minutes.