Key insights
- Employees frequently turn to external unsanctioned or "shadow" AI tools due to unmet demand
- Organizations that rely solely on restrictive policies risk driving AI use underground
- Clear guidance, role-based training, manager engagement and safe feedback channels help make responsible AI use the path of least resistance
What is Shadow AI?
Unsanctioned or "shadow" AI tool usage occurs when employees reach for external tools because enterprise tools lack functionality, usability, awareness or speed.
The rise in "bring your own AI to work" trend was largely well-intentioned. Back in 2024, as organizations were just beginning to evaluate the use cases, employees had already started experimenting with external AI tools to work faster and navigate everyday challenges.
Three years on, almost two in three (63%) organizations have formally integrated AI into their day-to-day operations, with 80% of users already reporting productivity and revenue gains, according to the 2026 Gallagher AI Adoption and Risk global survey. Despite the pace of adoption, organizations often lack the AI governance guardrails needed to support responsible use. Indeed, just half of employers have communicated their AI strategy to the workforce.
With three in four employees regularly using commercial AI tools outside the approved channels, it exposes organizations to shadow AI risks like confidential data leakage, creating governance blind spots while introducing decision-making risks.1 The average cost of a shadow AI-related breach today stands at $670,000.2 That number is only likely to rise.
"Shadow AI is more than just an unmanaged risk," says Sonya Poonian, AI Transformation Director, Workforce and Employee Experience at Gallagher. "It's often a signal that governance, communication and AI enablement have not kept pace with employee demand. In many cases, employees aren't intentionally bypassing policy; they are trying to solve business problems and may be unaware of approved tool or lack the confidence and training to use them effectively."
For leaders, the solution lies not only in strengthening controls, but in ensuring better enablement and clearer pathways to responsible adoption with a people-first lens. In other words, this means making enterprise-approved AI more accessible, useful and intuitive than alternatives.
Why employees turn to unapproved 'shadow AI' tools
Today, most businesses are actively exploring the ROI of AI, in turn shifting pressure on employees to deliver results. This, coupled with inadequate AI change management, can leave employees unaware of the full AI capabilities available to them. In such cases, external AI tools are perceived as a familiar and accessible workaround.
At the same time, psychological safety in the workplace — or a lack thereof — is a significant factor prompting shadow AI risks. Employees may hide their use of unapproved AI tools if they fear for their jobs or a loss of recognition for their work.
Unlike previous workplace technologies, AI often delivers value through highly individualized workflows, making training harder to standardize. As Gallagher's survey findings reveal, just 62% of organizations are providing on-the-job learning for their enterprise AI tools, suggesting many employees are still left to navigate the learning curve on their own.
The result often creates an environment where employees feel pressure to appear AI-proficient. Rather than draw attention to gaps in their knowledge, nearly half overstate their confidence in the technology and prefer to conceal their non-approved (shadow) AI usage.1
Indeed, shadow AI risks become harder to detect in organizations where communication is overly focused on AI misuse, risks and policy-heavy clampdowns. Employees become less likely to disclose the tools and substitutes they use.
"The employees deriving the greatest value from AI are often those most eager to innovate," notes Aidan Hewitt, divisional director of Cultural Change Consulting at Gallagher. "If governance is perceived as a barrier rather than an enabler, organizations risk losing some of their most capable AI adopters."
He adds, "Conversely, creating an environment conducive to suggestions, where employees can safely explain why they are using third-party tools — even anonymously — can help organizations gain valuable insight into where adoption is falling short."
Risks of shadow AI: How ungoverned AI use creates business liabilities
Concerns surrounding unsanctioned AI often focus on the exposure of confidential and proprietary data. However, the bigger challenge is accountability. When work is delegated to external tools, organizations can lose decision-making visibility and create new opportunities for phishing, credential theft and other social engineering attacks.
The risk becomes more complex as agentic AI is embedded into everyday workflows without proper AI governance in place. These systems can access applications, process data and execute tasks with minimal oversight. Without clear ownership and lifecycle management, obsolete agents may continue operating long after their intended use.
Not all AI-related incidents resemble cyber events. AI sycophancy — that is, the tendency of AI to reinforce existing assumptions with unwarranted confidence — can weaken critical thinking as employees begin outsourcing decisions rather than tasks.