Field Notes / Enterprise Security
Shadow AI: 67% of staff use AI at work, 18% of firms have a policy for it
Shadow AI is the new shadow IT, and it is a wider attack surface than any tool your security team chose. Here is what the gap between adoption and governance costs you, and the programme that closes it before a regulator or an attacker finds it first.
01 The scale of shadow AI
You already have an AI estate. You just cannot see most of it. The tools your staff reach for arrived without a purchase order, a security review or a line in the asset register, and they now touch email, source code, customer records and finance. The numbers below are what that looks like across the market in 2026.
Read the two figures at the top together and the risk becomes obvious. Two in three of your people use AI for work. Fewer than one in five of you have written down a single rule for it. The average enterprise runs 14 distinct AI tools, and the IT team can usually name four or five of them Productiv 2026 . Only 12% of organisations can produce a complete inventory of the AI in use Gartner 2026 . The rest are guessing.
02 How shadow AI opens doors
Shadow AI does not fail in one dramatic way. It opens several doors at once, and each one hands an attacker or a regulator a different route in. Here is what our operators walk through most often on enterprise engagements.
The first door is data leakage to the model provider. When a member of staff pastes a customer list or a clinical dataset into a public tool, that data leaves your control and lands under GDPR, HIPAA or an industry-specific regime, with no data-processing agreement behind it. Samsung learned this the hard way and banned public chatbots in 2023 after engineers leaked semiconductor designs. The pattern repeats wherever the tool is faster than the policy.
The second door is the coding assistant that quietly became a business platform. More than half of Claude Code users at major firms are not developers Anthropic 2026 . They use it to scrape leads, automate CRM workflows against live databases, process invoices and forecasts, and manage deployment scripts. Every one of those tasks grants the tool access to a sensitive system. Compromise one user's project configuration, and an attacker inherits whatever that person could reach: API keys, database credentials, the finance stack, the lot.
The third door is the supply chain you never reviewed. Shadow AI tools bolt on through browser extensions, API keys and OAuth grants that skip security approval by design. Each one is a dependency your team does not know exists. The fourth door is judgement. Without a clear policy, every member of staff decides in the moment what counts as confidential, and marketing's answer rarely matches legal's. The tool does not know the difference, so it treats your crown jewels and your press release exactly alike.
03 What it exposes you to
The McKinsey Lilli breach is the useful comparison, because McKinsey at least knew the system existed and put some controls around it. Shadow AI gives you the same risk profile with none of the visibility. The Lilli platform exposed 95 internal system prompts, 22 unauthenticated endpoints and 46.5 million messages. Your shadow tools have prompts you have never read, connections you have never audited, and data volumes you cannot measure. You get McKinsey's exposure without McKinsey's head start.
That exposure lands as direct regulatory risk, not just a security headache. Every time a member of staff sends personal data to an AI tool without a data-processing agreement, you have a GDPR gap. The EU AI Act adds hard duties for high-risk systems from 2 August 2026, with fines up to €15 million or 3% of global turnover, rising to €35 million or 7% for prohibited practices EU 2024/1689 . Article 9's risk-assessment duty applies even when the deployment was unofficial. Sector rules stack on top: HIPAA in healthcare, FCA and FINRA in financial services, ITAR in defence. Shadow AI routinely breaches all of them, and "we did not know" closes no case.
04 Closing the gap
You close shadow AI by turning invisible use into governed use, and it is a finite programme rather than an open-ended one. Start with discovery in the first fortnight: inventory every tool from network traffic, OAuth logs, expense reports and browser audits, map what data flows into each, then interview department heads to catch the two to three times more tools the monitoring missed. You come out of it able to name your AI estate, which puts you ahead of 88% of organisations.
Policy comes next, and it earns its keep only if it is specific. Name the sanctioned tools, state which data classes may touch each one, and list the prohibited use cases in plain language a department head can follow. Then wire in the technical controls: AI-aware data-loss prevention that spots sensitive data heading for an AI API, a central AI gateway that routes and logs every call, and hardened configurations for the tools you keep. The outcome is that your people keep the productivity and you keep the audit trail.
The last stage is proof, and it is where most programmes quietly lapse. Adversarial testing of your sanctioned AI systems shows whether prompt injection, system-prompt extraction or a poisoned retrieval pipeline can actually break them, and it produces the report Article 9 asks a regulator to see. Prompt injection alone affects roughly 73% of production AI applications OWASP LLM 2025 , so a one-off test ages fast. RTP Robin lets your team re-run those same attacks as tools and configs change, so the picture stays current between formal assessments rather than going stale the day the report is signed.
- Inventory every AI tool from traffic, OAuth grants, expense and browser audits, then confirm with department interviews
- Map the data flow for each tool: what goes in, where it is processed, what comes out
- Publish a specific AI acceptable-use policy naming sanctioned tools and prohibited data
- Deploy AI-aware DLP and route every AI call through a central, logged gateway
- Commission adversarial testing of sanctioned systems, then re-test on a recurring cycle so compliance holds
References
Sources
- Salesforce. 2026 Workforce AI Survey: Adoption, Governance, and Risk. Salesforce Research, 2026. salesforce.com
- Cyberhaven. Data Loss in the Age of AI: Enterprise Exposure Report. Cyberhaven Labs, 2025. cyberhaven.com
- Productiv. SaaS Intelligence: AI Tool Sprawl in the Enterprise. Productiv, 2026. productiv.com
- Gartner. AI Governance Survey: Maturity Across Industries. Gartner, 2026. gartner.com
- Anthropic. Claude Code Enterprise Usage Patterns. Anthropic, 2026. anthropic.com
- OWASP. Top 10 for Large Language Model Applications, 2025 Edition. OWASP Foundation, 2025. owasp.org
- European Parliament and Council. Regulation (EU) 2024/1689 (Artificial Intelligence Act). Official Journal of the European Union, 2024. artificialintelligenceact.eu