A 2026 Snapshot of the Shadow AI Risk Landscape
Explore the state of Shadow AI risk in 2026, how AI use and access are changing, and what IT teams should watch as they prepare for 2027.
Shadow AI risk is becoming harder to define, and even harder for IT teams to see.
A few years ago, the problem was relatively straightforward: an employee used an AI tool the company had not approved. Today, AI can arrive through personal accounts, appear as a feature inside approved software, handle sensitive company information, or connect directly to business systems.
In this article, we look at the latest workplace AI data, how Shadow AI risk is changing, and what these trends could mean for IT teams heading into 2027.
1. AI Adoption Is Moving Faster Than Oversight
AI is no longer an experiment happening at the edge of the workplace. By 2026, it has become part of everyday business operations. But the numbers also reveal a less visible story: organizations may be adopting AI officially while employees are building their own AI workflows underneath that formal adoption.
Enterprise AI adoption continues to accelerate
AI has moved firmly into mainstream business use.
McKinsey’s 2025 global survey found that 88% of respondents said their organizations use AI in at least one business function. Generative AI use reached 79%, compared with 65% in the previous survey.
The growth is also visible at the employee level. Cyberhaven’s 2026 research shows how far adoption can go. At organizations leading in AI adoption, 71.4% of employees were using generative AI.
How often employees use AI is increasing too. Cyberhaven’s earlier 2025 analysis found that workplace AI usage frequency had grown 4.6 times in one year and 61 times over two years.

Together, these numbers show how quickly AI is becoming part of everyday work. Adoption is no longer limited to a small group experimenting with new technology. In some organizations, AI is already used by a majority of the workforce. Employees are also using it far more frequently than they were just a few years ago.
The next question is where all of that adoption is coming from. How much is happening through company-provided AI, and how much is being introduced independently by employees?
How much AI use is happening outside IT control?
The growth of workplace AI is not coming only from tools provided by employers. Employees are also bringing their own AI into their daily work.
This pattern was already visible in 2024. Microsoft and LinkedIn surveyed 31,000 people across 31 countries and found that 78% of AI users were bringing their own AI tools to work, a trend they called Bring Your Own AI, or BYOAI.
Netskope reported in 2025 that 72% of generative AI users were accessing popular AI applications through personal accounts. Cyberhaven’s 2026 research shows that the pattern differs considerably by platform. It found that 32.3% of ChatGPT usage and 24.9% of Gemini usage occurred through personal accounts. The share was much higher for Claude at 58.2% and Perplexity at 60.9%.

These studies point to the same underlying behavior: employees do not always wait for their organizations to provide AI before using it for work.
For IT, this means the approved AI tools list shows only part of the picture. A large share of real AI use is happening in accounts, browsers, and apps that IT never set up.
2. How Shadow AI Risk Is Changing
Shadow AI used to be easier to spot: an employee using an unapproved AI tool. That is changing. AI now sits inside existing software, handles company data, and connects directly to business systems.
The risk is shifting from which AI employees use to what that AI can access and do.

From unauthorized tools to embedded AI
The obvious Shadow AI case is an employee opening a tool that IT has never approved. But that is becoming the easier case to find. The harder one is AI appearing inside software the company already trusts.
A project management tool adds an AI assistant. A CRM introduces automatic summaries. A browser adds AI features. None of these necessarily look like a new application entering the company, so they can easily escape the usual software review process.
The scale of embedded AI is already significant. Netskope found that 75% of users interacted with applications containing generative AI features, compared with just 4.9% actively using standalone GenAI applications.
This creates a situation for IT: the application may be approved while the AI inside it has never been evaluated.
That is why we think the boundary between sanctioned AI and Shadow AI is becoming less clear. Knowing which applications the company uses is no longer enough. IT increasingly needs to know where AI capabilities exist inside those applications too**.**
Read more: Embedded AI Risk: When Approved Software Introduces Unapproved AI
From AI usage to sensitive data exposure
Knowing that an employee uses AI tells us very little about the actual risk. What they share with it matters more.
An employee asking AI to rewrite a public email is very different from an engineer pasting source code into the same tool. The application is the same, but the exposure is not.
Cyberhaven’s 2026 research reveals how common this has become. It found that 39.7% of data movements into AI tools involved sensitive information, including source code, research and development materials, regulated data, and other confidential information.
This is why we think measuring Shadow AI by the number of tools or users only tells part of the story. AI usage tells us how widespread adoption is. What employees share with AI tells us much more about the potential risk.
From data submission to persistent data access
There is another change we think deserves more attention.
Most Shadow AI discussions focus on what employees actively put into AI: a prompt, a file, a piece of code, or a customer record.
But employees no longer have to bring the data to AI. They can bring AI to the data.
AI tools can connect to email, cloud storage, calendars, collaboration platforms, CRMs, development tools, and other business systems. Instead of uploading a document every time, an employee may authorize an AI tool to retrieve information directly from one of these systems.
AI access can also outlast the task it was granted for. This means IT needs visibility beyond the AI tool itself: who authorized it, what systems it can reach, and what permissions remain active.
3. Shadow AI Is Ultimately a Visibility Problem
Looking across these changes, we see Shadow AI increasingly as a visibility problem. Policies matter, but they depend on IT knowing what AI exists, how it is being used, and what it can access.
We cannot assess Shadow AI risk from the tool name alone. The same AI application can represent different levels of risk depending on who uses it, what they use it for, and what company data and systems it can reach.
For IT teams, we think that visibility needs to happen at three levels.
Tool visibility: What AI exists?
The first question sounds simple: What AI is being used across the organization?
But the answer now goes beyond maintaining a list of ChatGPT, Claude, Gemini, or other standalone AI tools. As we saw earlier, AI can also appear inside browsers, platforms, and other applications already in the company’s software inventory.
This means an AI inventory cannot be static. IT needs to account for both new AI applications entering the workplace and new AI capabilities appearing inside existing software.
Learn more about: Shadow IT Discovery Tool: What to Look for Before You Choose One
Usage visibility: Who is using it and why?
Discovering an AI tool is only the beginning.
IT also needs context around how it is being used. A tool tested occasionally by one employee presents a different situation from one that has quietly become part of a team’s daily workflow.
The purpose matters too. Using AI to brainstorm ideas is not the same as using it to analyze customer records, review contracts, write production code, or process internal documents.
This is why simply labeling an application approved or unapproved can miss important context. IT needs to understand who is using the AI, how often, and for what kind of work.
Explore more: A Practical Shadow IT Policy Template for Modern IT Teams
Access visibility: What company systems and data can it reach?
The final layer is understanding what sits behind the AI.
That includes the data employees actively give it, but increasingly also the systems the AI has permission to access. An AI tool connected to email, cloud storage, a CRM, or a development environment creates a different risk profile from the same tool used only for general questions.
This is where data and access visibility come together to complete your AI governance. IT needs to understand what company information is moving through AI, which systems it can connect to, and what permissions remain active.
4. What IT Teams Should Watch in 2027
Based on what we see today, Shadow AI could become harder to manage in 2027 as AI moves from simply using company data to taking actions with it.

AI agents will be able to do more
Most AI risk today focuses on what AI can see. AI agents add another question: What can AI do?
An agent may be able to send messages, update records, create files, or complete tasks across business systems.
For IT, permissions will need to cover not only what AI can access, but what actions it is allowed to take.
AI will connect to more business tools
Technologies such as Model Context Protocol (MCP) are making it easier for AI to connect with databases, files, development tools, and business applications.
One AI tool could therefore reach several company systems through different connections. IT may need to understand not only which AI tools employees use, but also what those tools are connected to.
Existing software can change without IT adding anything
A company may approve a SaaS application today, but that application could later add an AI assistant, agent, or new AI integration through a normal product update.
Nothing new appears in the software inventory, yet the risk profile has changed. This means approving an application once may no longer be enough.
AI discovery will need to become continuous
These changes can happen quickly. Employees can add AI tools, new connections can appear, and existing software can gain new AI capabilities.
A yearly or quarterly inventory only shows one point in time. That is why we expect IT teams to move toward continuous visibility into what AI exists, what it connects to, and what it can do.
If 2025 and 2026 were about measuring how much AI employees use, we expect 2027 to focus more on what that AI can reach and what it can do.
FAQs
1. Is using a personal AI account at work always considered Shadow AI?
Not necessarily. If an organization explicitly allows personal AI accounts and defines how they can be used, the activity may not be considered Shadow AI. The problem arises when AI is used for company work without IT’s knowledge, review, or appropriate controls.
2. Who should be responsible for managing Shadow AI?
Shadow AI should not sit with one team alone. IT can provide technology visibility, security teams can evaluate data and access risks, legal and compliance teams can define requirements, and business teams can explain how AI is actually being used. Clear ownership between these groups is more practical than treating Shadow AI as only a security issue.
3. Should companies block unapproved AI tools?
Blocking can be appropriate for high-risk tools or use cases, but blocking everything may simply push employees toward alternatives that are harder to see. A more practical approach is to combine restrictions with approved alternatives, clear usage rules, and ongoing discovery.
4. How often should organizations review their AI inventory?
A fixed annual review is increasingly difficult to rely on because AI tools and features change quickly. Organizations should review their inventory whenever new applications, integrations, or major AI capabilities appear, while moving toward more continuous discovery where possible.
5. What should IT do when it discovers an unknown AI tool?
Discovery should trigger investigation, not an automatic ban. IT should first identify who is using the tool, its business purpose, what data it handles, what systems it connects to, and what permissions it has. That context can then inform whether the tool should be approved, restricted, replaced, or blocked.
Final Thoughts
Shadow AI is becoming more difficult to separate from the rest of the technology environment. It can appear as a new tool, an existing software feature, or a connection to company systems.
For IT teams, that makes visibility increasingly important. Knowing what technology exists is the starting point for understanding where unknown or unmanaged risks may be hiding.
If you want to start with your network, try the AssetLoom Free Network Scanner. It helps you discover devices on your local network and identify details such as IP addresses, MAC addresses, hostnames, vendors, open ports, and device types, giving you a clearer picture of what is actually connected.
References
- McKinsey & Company. The State of AI: Global Survey 2025. McKinsey: The State of AI 2025
- Cyberhaven. 2026 AI Adoption & Risk Report. Cyberhaven: 2026 AI Adoption & Risk Report
- Cyberhaven. 2025 AI Adoption & Risk Report. Cyberhaven: 2025 AI Adoption & Risk Report
- Microsoft & LinkedIn. 2024 Work Trend Index: AI at Work Is Here. Now Comes the Hard Part. Microsoft & LinkedIn: 2024 Work Trend Index
- Netskope Threat Labs. Cloud and Threat Report: Generative AI 2025. Netskope: Cloud and Threat Report – Generative AI 2025