AI isn't the problem. People are.

Shadow AI

Shadow AI is people using AI tools the company never approved, usually in a personal account. Almost always for real work, almost never on purpose to break a rule.

Almost half your people use AI you never approved. The ones who are best at it are usually the quietest about it. This page is about finding out where you really stand, without turning it into a manhunt.

7 min read 3 September 2026 Updated 7 September 2026
A team at work, each person with their own AI agent beside them
How it usually surfaces I found out by accident. She had the whole client proposal open in her own ChatGPT, on her own laptop. And it was better than what we had sent out. A founder, 60 people, this spring

Sound familiar

Somewhere in your building, this week.

None of these look like an incident while they are happening. That is exactly why they keep going, and why the bill arrives later.

A composite, drawn from several client conversations.

Someone working alone with their agent beside them
The monthly report was done before lunch Lucas used to need two days for it. Last month it was on your desk on Tuesday before twelve. You said nice work, he said thanks, and that was the whole conversation. He builds it in his own account now. Nobody has checked the numbers it produces, nobody else can run it, and when he leaves in April the method walks out with him.
Someone standing at their desk in the evening, agent beside her
Half eleven, the shortlist has to go out at nine Your recruiter pastes twelve CVs into a free account on her own laptop, because the system is slow and the client wants names in the morning. She is doing her job with the fastest thing she has. Those CVs now sit in a chat history you do not own and cannot delete, on a free tier where the data can be used to train the model.9 If that candidate calls to ask where their details went, there is no honest answer available.
People walking through the office, each with an agent
The policy you sent round in March Nobody argued with it. Nobody broke it where you could see either. Six months on you cannot name three people who use AI every day, or say what they put into it. You did not get compliance out of that email. You got quiet, and quiet costs the same as the thing you were trying to stop.
Shadow AI is people using AI tools the company never approved, usually in a personal account. Regular use went from 15% to 45% of employees in one year.1 One in three of them keeps it quiet.2 It is now the third most common way company data leaks out by accident.1

What the numbers say

  1. Almost half of all employees now use AI nobody signed off on. A year earlier that was 15 in 100.1
  2. Roughly a third say nothing about it, and the reason they give most often is that it gives them an edge on their colleagues. Fear comes second.2
  3. Ask a management team how many of their people use AI for real work every day and you hear 4 in 100. Ask the people themselves and it is 13.4 So most AI plans are aimed at a company that no longer exists.
  4. Blocking it holds for about a week. After that it moves to phones and home laptops, and then you see nothing at all. I have yet to run into a company where the block held.
  5. Call it what it is. A level, the second of five, where about a quarter of companies are sitting right now.

One of these has probably happened already

  • Something with a client's name on it went through somebody's personal account, and you are working out whether that touches the data processing agreement you signed with them
  • You have to write an AI policy, and you would rather have one page people follow than twelve nobody opens
  • You are buying licences next quarter and you want to know who needs what before you buy for all 80 people
  • Two or three people are clearly miles ahead, they are the ones you can least afford to lose, and right now their method is not written down anywhere

What you take away

  • One meeting you can run this week that costs you nothing
  • Four numbers worth quoting in your own leadership team, with where each one comes from
  • Where you sit on the five levels, and the one thing that moves you up
  • Five steps, in the order that works

Defining it

Most leaders meet this as a security problem. It behaves like a people problem.

Something nearly got out, and the first move is to lock it down. Block the domains, send the policy round, remind everyone of the rules.

That reading gets you half of it. The exposure is real and I am not going to talk it away. What sits underneath is ordinary behaviour. People take the quickest route to the work when the official one is slower, and they keep quiet about it when saying so out loud has a price.

The real risk isn't that people are using AI, it's pretending they're not. Amit Bendov, co-founder and CEO of Gong10

So you have two gaps, and the second one is the expensive one. There is a gap between what your people need and what you gave them. And there is a gap between what they do and what they will tell you they do. A policy closes the visible half of both, and quietly widens the other half.

The numbers

From 15% to 45% in one year.

That is regular use of unapproved AI, measured across organisations.1 Same report puts it third among the causes of accidental data leakage.

42%
of office workers use generative AI at work, and one in three of them keeps it secret
90%
of surveyed companies have people regularly using personal AI tools for work. Around 40% pay for it themselves
3×
the distance between what leaders estimate and what people actually do
What leaders estimate 4% What people actually do 13%
Share of employees using generative AI for a meaningful part of their daily work. Leaders guess low by a factor of three.4

Put those together and this stops being a story about a few rule-benders. It is most of your company, a third of them are deliberately quiet, and your own read of the situation is off by a factor of three.

Why it happens

Three things, and they feed each other.

The work moved faster than procurement

A tool shows up, spreads by word of mouth, and is in daily use inside a week. A licence decision takes a quarter. Somewhere in that quarter the habit sets, and habits are harder to shift than tools.

Being honest about it costs something

This is the part I think most companies get wrong. When people were asked why they hide their AI use, the answer that came back most often was wanting an edge over colleagues. Fear of the rules came further down the list.2

A secret advantage over colleagues 36% Fear of job cuts, no policy, or more work 30% Doubt about their own ability 27% Fear of how they will be judged 24% Avoiding IT approval 21%
Why people keep their AI use to themselves.2
Nobody is hiding anything out of spite. They are hiding it because the last person who asked got a no. Paul Musters

That fear of being judged is well founded, by the way. People who use AI get judged more harshly on competence and motivation by the colleagues around them.5 So the quiet is rational. Nobody is hiding anything out of spite. They are hiding it because the last person who asked got a no.

You have no picture of who works how

Most companies know which licences they bought. Almost nobody knows how their people actually work: who runs whole workflows through it, who uses it to fix their spelling, who quietly rebuilt their job around it eight months ago. Ethan Mollick calls the heaviest of these users secret cyborgs, people who keep their methods to themselves.6 They tend to be your strongest performers, and they are invisible to exactly the organisation that could learn the most from them.

Your best AI users are invisible to exactly the organisation that could learn the most from them. Paul Musters

That third one is why this comes back after every crackdown. You are treating the tool you can see instead of the way people work, which you cannot.

Where does your company actually sit?

Anonymous, six questions, three minutes. The result names your level, what it costs you there, and what changes one step up.

Do the Culture Level scan
Two colleagues at a desk, each with their own agent beside them

Do this first

The test, this week.

One meeting. No software. It only works if you get the first thirty seconds right.

  1. Say out loud that nobody is in trouble and that nothing gets taken away this week.
  2. Ask which AI tools people actually use for work, and whether those are personal or company accounts.
  3. Watch who answers first and who stays quiet. The quiet ones are usually not the non-users.
  4. Ask what they use it for, not just what they use. “ChatGPT” tells you nothing. “I paste the client contract in to summarise it” tells you everything.

Whatever comes back, the distance between that and your approved list is your exposure. If nobody names a personal account, do not file that as a clean result. That is a reading on trust, and the answer sits somewhere else.

There is a harder version I use with clients. Pick the task your team does most often with AI. Ask three people, separately, to walk you through how they do it, step by step. If three different workflows come back, you are looking at the level below the one you thought you were on.

Where it sits

Shadow AI belongs to one level, and it peaks there.

In the five AI Culture Levels we use with clients, this behaviour belongs to one level. It is the signature of Level 2.

01Campfire60%
02Wild West25%Shadow AI peaks here
03Blueprint10%
04Engine4%
05Ecosystem1%
Share of organisations per level. Level 2 is daily individual use with no shared standard, and it holds about a quarter of the market.12

Level 2, Wild West, is daily individual use with no shared standard. Everyone has found something that works and nobody does it the same way. How normal the hiding is at this level shows up everywhere in the research: 48% of desk workers would be uncomfortable telling their manager they used AI for a common task,7 and roughly 59% use unapproved tools while most companies have not touched their acceptable-use policy since.8

Level 3, Blueprint, is where it drops. Documented workflows, one place where the good prompts live, AI in the first week of onboarding. Shadow AI does not vanish there, and I would not trust anyone who promises you it does. It shrinks, because the sanctioned way is finally as good as the private one.

One thing worth knowing before you diagnose yourself. Most teams are not on one level. Engineering is often two levels ahead of finance. We read the company at the lowest function, not the highest, because that is where next quarter's work actually is.

What a measurement shows that the meeting does not

An Operating Profile in use. Personality type and AI level in one profile, with the agents that fit it.

It measures two things per person: how somebody thinks and works, and how far along they are with AI. That second part is what makes this visible. Somebody running whole workflows through a personal account shows up differently from somebody using AI to tidy an email, and those two people need completely different things from you.

Someone working with their own orange agent alongside their profile
Level 3, running whole workflowsShe already rebuilt her week around it. What she needs from you is a sanctioned route for work she is doing anyway, and permission to say out loud how she does it.
Someone working with their own blue agent alongside their profile
Level 1, tidying emailsHe tried it twice and went back to how he worked before. Policy does nothing for him. He needs one task where it clearly beats his current way, and someone to show him.

Same team, same tool, two different problems. A tool inventory puts these two people in the same row.

At team level you see where it concentrates, and in most teams it is not spread evenly. It sits with three or four people who found something that works. Usually the ones you can least afford to annoy.

About emaho

emaho measures one Operating Profile per person: personality type and AI level in a single profile. On that we build a personal set of AI agents that fit how that person works, inside the tools they already use. Fifteen minutes to complete, first profile free, built for companies between 20 and 500 people.

Fifteen minutes per person. No credit card, no strings.

A team working out their way of doing things at the whiteboard, agents alongside

What to do

Five steps. The order matters more than the pace.

Start by asking, before you write a word of policy. Anything written before you know the real picture will aim at the wrong behaviour. Then close the tooling gap inside thirty days: buy licences where people already are, not where you wish they were. That single move takes out most of the exposure, because a good part of shadow AI is people paying out of their own pocket for a workaround.

Write one page, not twelve. What may go into an AI tool, what may not, who to ask when it is unclear. If a new hire cannot read it in two minutes and act on it, it does not exist.

Be honest about the gaps that still exist. Rajeev Rajan, CTO at Atlassian11

I would put that line on the same page. A policy that pretends everything is covered gets read once and believed never.

Then give people something better than what they built themselves. This is the part policy cannot do, and it is where a measurement earns its keep. A setup that fits how somebody actually works beats a personal account. Nothing else holds.

And measure again in a quarter. This is not a thing you fix once. It reopens every time a new tool arrives, which at the moment is roughly monthly.

The price of leaving it

It leaks out through the account you cannot see.

The exposure gets the attention and it is real. Third most common cause of accidental leakage,1 and around 65% of employees using ChatGPT sit on the free tier where the data can be used to train the model.9 In practice that shows up as three fairly boring things: content in a chat history the company does not own and cannot delete, no record of which document went where when a client asks, and a data processing agreement you may have broken without anyone noticing. Of the three costs on this page, this is still the one least likely to reach you this year.

The second is that you are making decisions on a picture that is wrong by a factor of three. Every AI plan built on the idea that adoption is low aims at the wrong problem. You end up buying beginner training for people who are three levels past you.

The third costs the most and shows up last. When your best users learn that being open about how they work carries a risk, they stop being open about how they work. You lose the map. And the people who could have drawn it for you stop offering. The month one of them resigns, you find out that the way half your reporting got done was never written down.

Run the meeting, then send me what came out of it

Tell me what your team said and I will tell you which level it points to and what I would do first. You get an answer rather than a calendar link.

Message me on WhatsApp

The common ones

Shadow AI, the questions people actually type

What is shadow AI?
Shadow AI is people using AI tools their employer never approved, usually in a personal account and usually for real work. It covers a recruiter running CVs through a free ChatGPT account and a finance lead building the monthly report in a tool nobody in IT has heard of. Regular use of unapproved AI went from 15% to 45% of employees in one year, according to Verizon's 2026 Data Breach Investigations Report.
How common is shadow AI at work?
Common enough that it is now the normal case rather than the exception. Verizon measured regular use of unapproved AI at 45% of employees in 2026, up from 15% a year earlier. MIT found in 2025 that 90% of surveyed companies have people using personal AI tools for work, and around 40% of those people pay for the subscription out of their own pocket.
Why do employees hide that they use AI?
The reason people give most often is that it gives them an advantage over colleagues, named by 36% in Ivanti's 2025 Technology at Work study. Fear of job cuts or a missing policy follows at 30%, doubt about their own ability at 27%, and fear of being judged at 24%. That last one is well founded: a Duke University study published in PNAS found that people who use AI are judged more harshly on competence and motivation by colleagues.
How do you find out how much unapproved AI is being used in your company?
Not by auditing accounts, because the ones who are best at it are the quietest. emaho reads organisations on five AI Culture Levels with an anonymous scan of six questions and three minutes. Shadow AI is Level 2 behaviour, Wild West, where about a quarter of companies sit right now.
Is shadow AI a security risk?
Yes, and the risk is more ordinary than most people picture. Unapproved AI is the third most common cause of accidental data leakage in Verizon's 2026 report, and Prompt Security found around 65% of employees using ChatGPT sit on the free tier, where the data can be used to train the model. The typical incident is a document pasted into a personal account, not a break-in.
What can go wrong if someone pastes client data into a personal AI account?
Three things, roughly in order of how likely they are. The content sits in a chat history the company does not own and cannot delete, which becomes a problem the moment the client asks. On a free tier that data can be used to train the model. And if you signed a data processing agreement with that client, you may be in breach of it without knowing which document went where.
Should we block ChatGPT at work?
Blocking stops the use you can see and moves the rest to phones and home laptops, where you see nothing at all. It only works when the approved alternative is genuinely better and available the same week. Without that, a block is a way of not knowing rather than a way of being safer.
How do I find out which AI tools my team is really using?
Ask, in one meeting, and open by saying out loud that nobody is in trouble and nothing gets taken away this week. Then ask what people use and what they use it for, because the tool name tells you nothing and “I paste the client contract in to summarise it” tells you everything. A licence list from IT will miss the personal accounts, which is where most of it sits.
Where can I read about the other AI challenges around control and oversight?
This is one of 25 AI challenges emaho documents. Shadow AI sits in the Control group, next to agents without rules and checking that quietly stops.
What should an AI policy actually say?
One page: what may go into an AI tool, what may not, and who decides when it is unclear. If a new hire cannot read it in two minutes and act on it, it does not exist in practice. Write it after you have asked people what they use, otherwise it aims at behaviour you have never measured.
Does buying more licences make shadow AI go away?
It removes the largest and cheapest slice, the people paying for their own workaround. It does not remove the part where somebody's personal setup fits their work better than the company one. That part needs a measurement per person rather than a purchase.
Is shadow AI a sign that we are behind on AI?
It is a sign you are at Level 2 of five in the emaho AI Culture Levels, Wild West, where about a quarter of companies sit. People have found things that work and nobody has turned that into how the team works. Level 1, where almost nothing happens at all, is both more common and more expensive.

From here

By Friday you can know where your team really stands.

Right now your picture comes from whoever happens to talk about it. Fifteen minutes per person replaces that with something you can act on, starting with yourself.

  1. Amnesty first, questions secondSay out loud that nobody is in trouble. Without that you are measuring fear rather than usage.
  2. Ask what people use, not whether they shouldThe profiles show who runs whole workflows through a personal account, which is a supply problem rather than a discipline problem.
  3. Close the gap that created itEvery shadow tool exists because the approved one was slower. Fix that and the shadow closes itself.

First profile free · no credit card · built for companies of 20 to 500 · you decide what your team gets to see

Not ready to put your team in anything yet? Start with the level of the company instead. The Culture Level scan is six questions, three minutes, and asks nothing of you.

Paul Musters

Paul Musters

Fifteen years of leadership and team development in Dutch scale-ups. That practice now sits in software: one Operating Profile per person, with agents that actually fit. He writes these pages from what he runs into with clients, not from a research summary.

LinkedIn · paul@emaho.world · WhatsApp

Sources and numbers used on this page
  1. Verizon, Data Breach Investigations Report, 2026. Regular use of unapproved AI at work rising from 15% to 45% of employees in a year, and unapproved AI third among the causes of accidental data leakage.
  2. Ivanti, Technology at Work, 2025. 42% of office workers using generative AI at work, one in three of them keeping it quiet, and the reasons they give: an advantage over colleagues 36%, fear of job cuts or a missing policy or more work 30%, doubt about their own ability 27%, fear of being judged 24%, avoiding IT approval 21%.
  3. MIT, 2025. 90% of surveyed companies with people regularly using personal AI tools for work, around 40% of them paying for a subscription themselves.
  4. McKinsey, January 2025. Leaders estimating 4% of employees use generative AI for a meaningful part of their daily work, employees themselves reporting 13%.
  5. Duke University, published in PNAS, 2025. People who use AI at work being judged more harshly on competence and motivation by colleagues.
  6. Ethan Mollick, Wharton School. The term secret cyborgs for heavy AI users who keep their methods to themselves.
  7. Slack Workforce Index, 2024. 48% of desk workers saying they would feel uncomfortable telling their manager they used AI for a common task.
  8. JumpCloud, 2026. Roughly 59% of employees using unapproved AI tools, while most companies have not updated their acceptable-use policy.
  9. Prompt Security, 2025. Around 65% of employees using ChatGPT on the free tier, where the data can be used to train the model.
  10. Amit Bendov, co-founder and CEO of Gong, quoted by Axios, May 2025.
  11. Rajeev Rajan, CTO at Atlassian, quoted by Axios.
  12. emaho AI Culture Levels. Share of organisations per level, calibrated against BCG 2025 and McKinsey 2025.

Numbers are quoted as published. Where a figure is described as roughly or around, that is how the source states it.