Shadow AI is the AI tooling running inside your company that nobody approved. Not smuggled in by bad actors. Signed up for by a product manager on a Tuesday because it saved her an afternoon, paid on a personal card or not paid for at all, and never mentioned to anyone.
It is the fastest-growing category of software in most organisations right now, and almost none of it appears on the spend report that finance reviews.
How big is it really
Bigger than most inventories suggest, though the honest answer is that nobody knows precisely, and the published numbers disagree with each other more than the coverage admits.
Microsoft’s 2025 Work Trend Index found that 78% of people using AI at work are bringing their own tools, outside IT approval. Salesforce’s State of IT research put it lower, at 65% of employees using at least one AI tool their IT or security team has not sanctioned. Other vendor surveys in 2026 report figures as high as 98% of organisations. The spread is not a rounding error.
The gap comes from definitions rather than from anyone being wrong. Does a browser extension count? A free ChatGPT account on a work laptop? An AI feature that a vendor switched on inside a tool you already licensed? That last one is doing a lot of work in these numbers, and it is the category nobody has a policy for, because nothing was installed and nobody signed up for anything.
Treat any single shadow AI percentage you see as an argument rather than a measurement. What holds across all of them is the direction and the rough shape: most companies, most employees, growing fast.
Why it is different from ordinary shadow IT
Shadow IT is decades old and the playbook is well worn. Someone buys Dropbox, IT finds out, it gets consolidated. Annoying, bounded, solved.
Three things make the AI version behave differently.
The data leaves. A rogue project management tool holds your task list. A rogue AI tool holds whatever your employee pasted into it, and people paste a lot. Salesforce found 27% of employees have put confidential company data into public AI tools. That is not a permissions problem you can fix after the fact. The text is already gone, possibly into a training set, and there is no revoking it.
It is free, so procurement never sees it. Shadow IT used to surface through expense reports, because software cost money. The free tier is the entire problem here. No invoice, no card charge, no renewal, no vendor record. Your spend management platform is structurally blind to it, and every dashboard you own will keep reporting that everything is fine.
It arrives inside tools you already bought. The vendor ships an AI assistant into the product next quarter and it is on by default. Nobody adopted anything. Your approved software is now doing inference against your data under terms most buyers have not read since the original signature.
What it actually costs
Gartner’s 2025 research puts some numbers on this. Organisations without governance structures spend 2.5 times more on AI incident remediation than those with controls in place, and it projects shadow AI will cost enterprises more than $40 billion by 2027. Only 34% of organisations have a formal shadow AI detection program at all.
Worth reading those with the usual caution, since analyst projections about emerging categories have a poor track record and the firms publishing them sell governance advice. The 34% figure is the interesting one anyway, because it is a measurement rather than a forecast, and it says two thirds of companies are not looking.
The costs that land first are duller than a breach and more likely:
- Duplicate spend you cannot see. Four teams on four AI writing tools, three of them free until the trial ends and someone expenses an upgrade.
- Data in places your DPA does not cover. Which becomes a real problem the first time a customer asks where their data goes, or an auditor does.
- Work that depends on an account nobody owns. The workflow runs on a tool registered to someone’s personal email. That person leaves. Nobody can log in.
- Vendors that vanish. The AI tooling market is churning hard, and a free tool with no contract gives you no notice period and no data export commitment when it goes. See what happened to Lattice HRIS customers, and that was a paid product with eight months of notice.
Why banning it does not work
The instinct is a blanket prohibition. It fails, reliably, for a reason worth understanding before you try it.
People adopt these tools because they work. Someone found a way to do a two-hour task in ten minutes, and a policy telling them to stop is a policy telling them to be slower at their job. What a ban produces is not less usage. It is the same usage on personal devices, where you have no visibility at all, and where the employee now has a reason not to tell you when something goes wrong.
The organisations getting this right treat it as a supply problem. If people are reaching for unsanctioned tools, the sanctioned ones are missing, too slow to get approved, or nobody knows they exist. We cover what to write instead in Writing a Shadow AI Policy That People Will Actually Follow.
Start by looking
You cannot make decisions about an inventory you do not have, and the first pass costs nothing. Your SSO logs, OAuth grants, expense reports and DNS traffic already contain most of the answer, which is the subject of How to Find Shadow AI in Your Company Without Buying a Tool.
What that exercise tends to surface is not a security horror story. It is a list of eleven tools doing four jobs, two of which you are paying for twice, and one of which is holding something it should not. That list is worth having before somebody else compiles it for you.
CopperFeed tracks what changed in SaaS and AI tooling as it happens, including the AI features vendors switch on inside products you already own.
Figures here come from published vendor and analyst research, attributed inline. Shadow AI statistics vary widely by definition and methodology, so treat any single number as indicative.