Shadow AI does not require a speculative threat model. The behavior is ordinary.
Someone is stuck on a draft. Internal tools feel slow, there is no approved assistant yet, or the approved one is unavailable on their device. They open a personal ChatGPT (or Claude, or Gemini) session, paste the hard paragraph, and ask for a cleaner version. Maybe it is a customer email. Maybe it is a vendor assessment. Maybe it is notes from a sensitive conversation with names still attached.
They feel efficient. The model returns something useful. The text—and whatever personal or confidential data rode along—has now left the organization’s control boundary.
That is the practitioner version of shadow AI. Not science-fiction autonomous agents (though those are arriving). Everyday knowledge work, powered by paste.
What we mean by shadow AI
Shadow AI is the use of AI tools, apps, or services without IT/security approval and without the oversight a governance model assumes. It is shadow IT with a much larger data blast radius, because the “integration†is often just a clipboard.
Airia’s 2026 compilation of shadow AI statistics is a useful single entry point for CISOs because it aggregates widely cited survey findings. Among the data points it surfaces (with original survey attributions in the piece):
- Microsoft’s Work Trend Index (May 2024) is the correct primary for 78% of AI users at work bringing their own AI tools (BYOAI) outside IT approval — not a 2025 Work Trend Index / Frontier Firm report.
- The same May 2024 Work Trend Index figures commonly cited include 75% of knowledge workers using AI at work and related BYOAI / unapproved-tool signals. Secondary compilations sometimes mislabel the year; prefer the primary: https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part
- Salesforce’s State of IT (2024) is cited for 65% of employees using at least one AI tool not approved by IT/security, and 27% of enterprise employees having entered confidential company data into public AI tools.
- Cyberhaven (2024) is cited for 11% of data pasted into ChatGPT and similar tools containing sensitive or confidential information, with source code frequently appearing among sensitive AI-related events.
- IBM (2024) is cited for only 24% of organizations having implemented AI-specific data loss prevention controls.
Be careful with secondary compilations: open underlying reports for board-level claims. The directional story matches real interviews and assessments. People use these tools. Some put confidential text into them. Most security programs still cannot see the prompts.
Why unstructured data makes this hard
Structured database exfiltration usually leaves a trail—queries, exports, pipelines. Shadow AI thrives on unstructured and semi-structured text:
- Draft articles and internal memos
- Customer support threads
- Contracts and redlines
- HR case notes
- Spreadsheets copied into the prompt window
- Screenshots and PDF text extracted into chat
DLP built for file transfers and email attachments can miss free-text prompts in a browser session, especially on personal accounts or unmanaged devices.
In product, professional services, and knowledge-work environments, content itself is often both the product and the risk. Confidential commercial material, customer personal data, and employee information can all look like “just text†to a busy professional trying to meet a deadline.
What actually goes wrong (beyond “the model trains on my dataâ€)
People fixate on training-data opt-out settings. Those matter, but they are not the whole risk register.
From a privacy and governance perspective, shadow AI creates several concrete issues:
1. Unauthorized disclosure to a processor never assessed. There may be no data processing agreement, no subprocessors list, no residency commitment, and no incident path with that vendor for that use.
2. Purpose limitation failure. Data collected for service delivery gets reused as prompt fuel for convenience.
3. Loss of control over retention and deletion. Organizations cannot honor a deletion request for text sitting in a consumer AI history they do not administer.
4. Confidentiality and privilege problems. HR, finance, and sensitive investigative content can lose protections once shared outside the organization.
5. Security follow-on risk. Prompts can include credentials, internal URLs, architecture details, or access pathways useful to an attacker if accounts or histories are compromised.
6. Fairness and accuracy externalities. People paste incomplete personal data into tools and act on the output as if it were reviewed truth.
Samsung’s well-known case of engineers pasting proprietary code into ChatGPT became the cautionary headline for a reason. The more ordinary version happens daily with customer and employee text.
What strong AI-related privacy and security reviews examine
When a process might involve GenAI—approved or not—questions should force specificity:
- What categories of personal or confidential data could enter a prompt?
- Is there an approved enterprise AI path with logging, retention controls, and contractual cover?
- Can the organization detect paste or upload patterns to unsanctioned AI domains?
- Do DLP policies understand prompt-style exfiltration, not only file moves?
- Are managers quietly rewarding speed in ways that punish people for using slower approved tools?
- For research and customer workflows, where is the line between legitimate tooling and unacceptable disclosure?
If the answer to detection is “we send an annual reminder,†residual risk is high.
A control stack that respects how people work
Bans alone fail. People route around friction when deadlines are real. Mature programs layer governance with usable alternatives.
1. Make the approved path good enough
If the sanctioned assistant is hard to access, slow, or useless on the tasks people care about, shadow AI is rational behavior. Provide an enterprise-approved option with:
- Clear data-use terms
- Admin controls and audit logs
- Retention settings aligned to policy
- Guidance on what may and may not be pasted
2. Write policy people can apply in ten seconds
“No sensitive data in public AI†is incomplete. Give examples:
- Allowed: brainstorming public marketing slogans with no personal data
- Not allowed: customer records, employee cases, non-public financials, credentials, confidential product plans
Publish a short decision tree. Train managers, not only new hires.
3. Detect what you can without pretending you see everything
Useful signals include:
- DNS/proxy/SSE logs for consumer AI destinations
- Browser controls that warn or block unsanctioned AI categories
- DLP rules for high-risk content patterns on web uploads and paste-adjacent channels
- CASB/SaaS controls where enterprise identities are used
Accept residual risk on fully personal devices off-network—then reduce the business reasons to use them for work content.
4. Tie shadow AI back to DSPM and data minimization
If sensitive unstructured stores are widely accessible, more people can paste more dangerous text. Least privilege and cleanup of redundant, obsolete, or trivial data reduce the fuel available for accidental prompts.
5. Treat incidents as learning, not only punishment
When someone pastes something they should not, the response should include containment (session history, vendor notice if needed), coaching, and a product question: why was the approved path not used?
Regulatory framing without panic
Organizations do not need the EU AI Act to care about this. Classic privacy law already cares about unauthorized disclosure, processor due diligence, and accountability. Sector rules and contracts often go further.
Where AI-specific regimes apply, inventory and governance gaps become even harder to defend. Airia’s roundup notes that many organizations still lack formal shadow AI detection programs and cannot produce a complete inventory of AI tools in use. Whether or not every cited figure is adopted wholesale, that maturity gap is widely observed.
CISSP domain alignment
Shadow AI is an Asset Security problem first—unstructured data leaving controlled boundaries—then an identity, operations, and governance problem. Programs that still design DLP only for files will keep missing sentences. Programs that still design AI governance only for official pilots will keep missing the clipboard.
Actionable takeaway
Run a two-week shadow AI reality check:
- Interview ten high-output knowledge workers (support, product, sales, engineering, finance). Ask which AI tools they used last week—not which tools are approved.
- Compare that list to the official inventory.
- For the top unsanctioned tool, measure whether security can see usage at all.
- Ship one improvement: either a better approved assistant or a browser/SSE control on the riskiest consumer AI destinations for managed devices.
- Add two concrete prompt examples to acceptable-use guidance this month.
Shadow AI is not mainly a story about rogue employees. It is a story about unstructured data, weak approved alternatives, and controls still designed for files instead of sentences. Fix those, and the paste problem gets smaller fast.
Sources
- Airia — Shadow AI Statistics: Key Data Points Every CISO Needs in 2026 (compiles Microsoft Work Trend Index, Salesforce State of IT, Cyberhaven, IBM, and other cited surveys — verify primary sources for board use)
- Microsoft Work Trend Index (May 2024) — AI at Work Is Here. Now Comes the Hard Part (primary for the 78% BYOAI figure; not a 2025 Work Trend Index report)
- NIST AI Risk Management Framework