Tackling shadow AI risks calls for clear AI governance, employee training and incident preparedness. This will help build a culture of trust and responsible AI use across the enterprise.

Key insights

  • Employees frequently turn to external unsanctioned or "shadow" AI tools due to unmet demand
  • Organizations that rely solely on restrictive policies risk driving AI use underground
  • Clear guidance, role-based training, manager engagement and safe feedback channels help make responsible AI use the path of least resistance

What is Shadow AI?

Unsanctioned or "shadow" AI tool usage occurs when employees reach for external tools because enterprise tools lack functionality, usability, awareness or speed.

The rise in "bring your own AI to work" trend was largely well-intentioned. Back in 2024, as organizations were just beginning to evaluate the use cases, employees had already started experimenting with external AI tools to work faster and navigate everyday challenges.

Three years on, almost two in three (63%) organizations have formally integrated AI into their day-to-day operations, with 80% of users already reporting productivity and revenue gains, according to the 2026 Gallagher AI Adoption and Risk global survey. Despite the pace of adoption, organizations often lack the AI governance guardrails needed to support responsible use. Indeed, just half of employers have communicated their AI strategy to the workforce.

With three in four employees regularly using commercial AI tools outside the approved channels, it exposes organizations to shadow AI risks like confidential data leakage, creating governance blind spots while introducing decision-making risks.1 The average cost of a shadow AI-related breach today stands at $670,000.2 That number is only likely to rise.

Three out of four employees regularly use commercial AI tools outside the approved channels, exposing organizations to shadow AI risks.

"Shadow AI is more than just an unmanaged risk," says Sonya Poonian, AI Transformation Director, Workforce and Employee Experience at Gallagher. "It's often a signal that governance, communication and AI enablement have not kept pace with employee demand. In many cases, employees aren't intentionally bypassing policy; they are trying to solve business problems and may be unaware of approved tool or lack the confidence and training to use them effectively."

For leaders, the solution lies not only in strengthening controls, but in ensuring better enablement and clearer pathways to responsible adoption with a people-first lens. In other words, this means making enterprise-approved AI more accessible, useful and intuitive than alternatives.

Why employees turn to unapproved 'shadow AI' tools

Today, most businesses are actively exploring the ROI of AI, in turn shifting pressure on employees to deliver results. This, coupled with inadequate AI change management, can leave employees unaware of the full AI capabilities available to them. In such cases, external AI tools are perceived as a familiar and accessible workaround.

At the same time, psychological safety in the workplace — or a lack thereof — is a significant factor prompting shadow AI risks. Employees may hide their use of unapproved AI tools if they fear for their jobs or a loss of recognition for their work.

If governance is perceived as a barrier rather than an enabler, organizations risk losing some of their most capable AI adopters.
Aidan Hewitt, divisional director of Cultural Change Consulting at Gallagher

Unlike previous workplace technologies, AI often delivers value through highly individualized workflows, making training harder to standardize. As Gallagher's survey findings reveal, just 62% of organizations are providing on-the-job learning for their enterprise AI tools, suggesting many employees are still left to navigate the learning curve on their own.

The result often creates an environment where employees feel pressure to appear AI-proficient. Rather than draw attention to gaps in their knowledge, nearly half overstate their confidence in the technology and prefer to conceal their non-approved (shadow) AI usage.1

Indeed, shadow AI risks become harder to detect in organizations where communication is overly focused on AI misuse, risks and policy-heavy clampdowns. Employees become less likely to disclose the tools and substitutes they use.

"The employees deriving the greatest value from AI are often those most eager to innovate," notes Aidan Hewitt, divisional director of Cultural Change Consulting at Gallagher. "If governance is perceived as a barrier rather than an enabler, organizations risk losing some of their most capable AI adopters."

He adds, "Conversely, creating an environment conducive to suggestions, where employees can safely explain why they are using third-party tools — even anonymously — can help organizations gain valuable insight into where adoption is falling short."

Risks of shadow AI: How ungoverned AI use creates business liabilities

Concerns surrounding unsanctioned AI often focus on the exposure of confidential and proprietary data. However, the bigger challenge is accountability. When work is delegated to external tools, organizations can lose decision-making visibility and create new opportunities for phishing, credential theft and other social engineering attacks.

The risk becomes more complex as agentic AI is embedded into everyday workflows without proper AI governance in place. These systems can access applications, process data and execute tasks with minimal oversight. Without clear ownership and lifecycle management, obsolete agents may continue operating long after their intended use.

Not all AI-related incidents resemble cyber events. AI sycophancy — that is, the tendency of AI to reinforce existing assumptions with unwarranted confidence — can weaken critical thinking as employees begin outsourcing decisions rather than tasks.

Build Responsible AI Adoption at Scale

Empower employees with the training and guidance needed to reduce shadow AI risk.

Discover More

The exposure to such shadow AI risks is particularly acute in sectors such as healthcare and higher education, where confident outputs may receive insufficient scrutiny despite their impact on patient outcomes, student welfare and institutional reputation.

The impact of unsanctioned AI use goes beyond cybersecurity, notes Lenin Lopez, senior vice president, Executive and Financial Risk at Gallagher. "Inadequate AI governance checks can create exposures across cyber, employment practices, professional liability, privacy, fraud and operational resilience."

Ascribing responsibility for shadow AI incidents is rarely straightforward. This ambiguity is a major potential driver of complex GenAI-related claims and equally challenging underwriting scenarios.

How leaders can prevent shadow AI and enable AI resilience

Successful AI adoption depends on fostering trust in the workplace, which in turn depends on clear communication. This includes articulating AI strategy, including approved tools, data-sharing boundaries, expectations for responsible use and where employees can turn for guidance.

Because AI relies heavily on prompts and user inputs, communication should also include practical guardrails around responsible use and data handling. Equally important is creating feedback loops that help identify unmet needs, adoption barriers and gaps in enterprise capabilities.

Middle managers play a critical role here. "Your frontline teams look up to the person they report to," says Aidan Hewitt, noting that employees often mirror the behaviors they observe. "Expectations around third-party AI use can be perceived as less clear, as compared to other organizational policies such as annual leave and expenses. In this environment, managers become an important line of defense against shadow AI."

Shadow AI ultimately highlights how deeply AI has been integrated into day-to-day work. Additionally, effective usage also requires shared accountability and responsibility. Which is why, rather than being solely a governance challenge, such instances serve as a signal of employee demand and a measure of adoption maturity.

In practice the most effective AI transformations balance governance with empowerment.
Sonya Poonian, AI Transformation Director, Workforce and Employee Experience, Gallagher 

A people-first approach can do more than reduce risk; it can quicken adoption, build trust and foster innovation. As Sonya Poonian says, "In practice the most effective AI transformations balance governance with empowerment. Success comes from reducing risk while enabling employees to adopt AI confidently, responsibly and at scale."

She adds, "Organizations that achieve this balance build trust, accelerate value realization and create an operating model that can evolve alongside new use cases, emerging technologies and changing regulatory expectations."

A people-first approach: Three ways to manage shadow AI

Because shadow AI emerges through everyday employee choices, effective management depends on providing the right support structure to build AI readiness:

Ultimately, organizations that gain the greatest value from AI will be those that make responsible adoption the easiest path forward.

Published August 2026