Quick Answer: Shadow AI is the use of AI tools, models or agents inside an organisation without the approval, knowledge or oversight of the people accountable for them. The shadow AI risk is not only data exposure. It is that an organisation cannot govern what it cannot see, and cannot keep the capability once the person who built it leaves.
Active agents in the Microsoft 365 ecosystem grew fifteen times in a single year, and eighteen times inside large enterprises, according to Microsoft’s Work Trend Index 2026. The striking part is not the scale but the location. None of it arrived through procurement. It happened inside software organisations already own, built by people using the tools they were handed.
The same research found that only one in five people using AI at work are somewhere their organisation’s readiness matches their own capability, and a further one in ten have skill their employer has no structure to absorb.
That gap is where shadow AI sits: work being done and tools being built that the organisation cannot see well enough to say what is running, who is accountable, or what it reaches.
What is shadow AI?
Shadow AI is any use of artificial intelligence inside an organisation that has not been approved, reviewed or recorded by the people responsible for technology, security and risk. It covers the model, anything built on it, and the accounts those things run under. In practice it looks ordinary:
- A finance analyst pastes a draft forecast into a consumer chatbot to tidy the commentary before the board sees it.
- A support lead wires an inbox summariser to a personal API key so overnight tickets arrive sorted.
- A developer runs a coding assistant with access to production repositories.
None of them are behaving badly. Each has found a faster way to do the job they were hired for. In every case the organisation holds no record of it.
Shadow AI and shadow IT are not the same problem
Shadow IT described unapproved software brought into a business, and the consequences were mostly commercial: an unknown licence, an unbudgeted renewal, a gap in the asset register. Shadow AI changes what is at stake, because it changes what the tool does with company information. An unapproved file store holds data. An unapproved model processes it, and where that input goes, how long it is kept and what else it informs are questions nobody can answer.
From unsanctioned use to unsanctioned building
Early shadow AI meant asking a model questions. Increasingly it means building an AI agent that acts on its own. That is roughly the distance between generative and agentic AI, and it is a different problem: one concerns what information leaves, the other what actions get taken.
That distinction matters because of how agentic AI systems acquire their permissions. The UK’s National Cyber Security Centre notes that an agent running without proper isolation may use the credentials available to the account it runs under. An agent built inside a personal account inherits that person’s access, and in the audit logs the activity looks like that person working, only faster and in far greater volume.
Security teams call these shadow agents.
Why shadow AI happens
Shadow AI is usually treated as a failure of control. The evidence points more towards a failure of supply.
IBM research published in November 2025 found that eighty per cent of office workers surveyed across North America used AI in their roles, while only twenty two per cent relied solely on tools their employer provided. Close to forty per cent preferred outside tools because the features were better. People do not route around the sanctioned option for the sake of it, but when it does not do the job.
Microsoft’s 2026 research reaches the same conclusion from the other direction. Organisational conditions, meaning culture, manager support and how people are evaluated, accounted for roughly twice as much of AI’s measured impact as an individual’s mindset.
Why it stays hidden
Under-reporting is not incidental to shadow AI. It is structural. Microsoft’s 2024 Work Trend Index found that seventy eight per cent of people using AI at work were bringing their own tools, and that fifty two per cent were reluctant to admit using it on their most important tasks, with fifty three per cent saying it made them look replaceable.
The pattern is uncomfortable. The more valuable the work somebody does with AI, the stronger the reason not to mention it. Usage surveys undercount for the same reason, and a blanket ban pushes activity out of sight rather than ending it.
The risks of ungoverned AI use
Shadow AI risk is usually presented as a set of separate concerns. It is better understood as one problem seen from four angles, since each follows from the same missing thing: a record of what exists.
Data exposure and breach cost
IBM’s Cost of a Data Breach Report 2025, based on six hundred breached organisations across seventeen industries, found that one in five had a breach linked to shadow AI, adding as much as 670,000 US dollars to the average cost.
What was lost matters as much as the cost. Sixty five per cent of those breaches exposed customer personal information, against fifty three per cent across all breaches studied. Intellectual property was exposed less often but cost most per record, at 178 US dollars.
Inherited permissions
Guidance published by the National Cyber Security Centre in August 2026 sets out that every agent should hold its own identity, distinct from human users, with credentials scoped to the task. Where that does not happen, an agent operates with whatever the host account can reach, and the NCSC frames those credentials as defining the scale of what can go wrong.
An unsanctioned agent is rarely a new door into the organisation. It is an existing door, opened far more often and far faster than the person it belongs to ever would.
Accountability and compliance
A study of two thousand technology executives published by the IBM Institute for Business Value in June 2026 found that seventy per cent said teams were deploying technology faster than IT could track, and seventy seven per cent said AI adoption was outpacing their governance capability. Those organisations reported an average of fifty four agent incidents over the year, seventeen per cent severe enough to take more than four hours to contain.
The regulatory position is straightforward. UK GDPR and the Data Protection Act 2018 apply to personal data placed into any tool, approved or not. Approval status changes who knew, not the obligation, and not who answers for it.
Capability that leaves with the person
There is a fourth risk, rarely named, and it is not a security risk at all. Much of the value of AI agents in business comes from encoding knowledge that was never documented. When somebody does that inside an agent held in a personal account, the organisation gets the benefit for as long as they stay. On the day they leave the output stops, and what made it work was never written down, because writing it down was the thing the agent replaced.
No leaver process catches this. A handover checklist asks about documents, accounts and access. It does not ask what the person automated.
Who owns an AI agent an employee built?
In the UK the legal position is more settled than most people assume. Section 11(2) of the Copyright, Designs and Patents Act 1988 provides that where a work is made by an employee in the course of their employment, the employer is the first owner of any copyright in it, subject to any agreement to the contrary. An agent built by an employee to do their job, on company time, usually falls inside that.
So the organisation owns it. That is where the conversation normally stops, and it is the wrong place to stop, because ownership and possession are different things.
A company can own something it cannot open. The prompt sits in a personal account, the credentials are personal, the integrations were authorised by an individual, and the reasoning behind why the agent works lives partly in its configuration and partly in the head of whoever built it. A right of ownership does not survive an account being closed, and cannot be exercised against a system nobody can reach.
The organisation is left with an asset that appears on no register, cannot be inspected or improved by anyone else, and cannot be handed on.
Why this is a governance question, not a legal one
The instinct is to reach for the employment contract. In most cases it is already sufficient, and strengthening it changes nothing, since the problem was never entitlement.
The capability is lost because of where it was built, not who owns it. Ownership and access become the same thing only when agents are built, held and run somewhere the organisation controls, which is why central custody sits early in any credible AI maturity model. GrowthNation serves every agent centrally through its Agent Vault, so the work built for an organisation stays with that organisation as individuals move on.
Governed and ungoverned AI compared
The gap between the two is not a gap in employee behaviour. The same person, doing the same task with the same tool, produces a very different risk profile depending on where the work sits and how much the organisation can see. Most of the difference comes down to visibility and identity, both of which an AI maturity assessment can measure directly.
| Dimension | Ungoverned AI use | Governed AI use |
| Visibility | The organisation cannot produce a list of what is running or who built it | Every model, tool and agent appears in a maintained inventory |
| Identity | Activity runs under a person’s account and appears in logs as that person | Each agent holds its own identity, distinct from human users |
| Permissions | Inherits whatever the host account can reach | Scoped to the task, with the shortest workable credential lifetime |
| Accountability | No named owner until an incident is already being investigated | A named individual or team is accountable before deployment |
| Continuity | Capability is lost when the person who built it leaves | Capability is held centrally and passes to the next person in the role |
| Measurement | Value is anecdotal and cannot be defended in a budget round | Hours saved and usage are tracked per agent and per team |
How to reduce shadow AI risk
AI governance is usually framed as a brake on adoption. The evidence suggests the opposite. The IBM Institute for Business Value found that organisations building control directly into their AI systems had twenty five per cent fewer incidents than those relying on manual governance, and deployed sixteen times more agents.
Four things matter more than the rest:
- Start with an inventory, not a policy. A policy describes intended behaviour. An inventory records actual behaviour, and is the first thing any AI readiness assessment should establish. Only one of the two can be checked.
- Ask what people have automated, not which tools they use. The tool list is the visible surface. The automation list is where the business value and the dependency sit.
- Give agents their own identities and scoped permissions. Following NCSC guidance makes activity attributable and stoppable, and separates what an agent can reach from what its builder can.
- Make the sanctioned route faster than the unsanctioned one. Where the supply problem goes unaddressed, discovery tooling finds the same activity next quarter under new names.
What good looks like
The end state is not an organisation with less AI in it. It is one that can answer four questions without going looking: what is running, who is accountable, what each can reach, what each has saved. That last one is what an AI scorecard exists to answer.
Getting there means finding the automation that already exists before an incident finds it. GrowthNation interviews every team about how they actually work, surfacing what people have already automated alongside what is still waiting to be.
The evidence
These figures come from four studies published between 2024 and 2026, with sample sizes and dates so each can be weighed.
| Source | Finding | Sample | Date |
| Microsoft Work Trend Index | Active agents in the Microsoft 365 ecosystem grew 15x year on year, and 18x in large enterprises | Telemetry plus 20,000 AI users across 10 markets | May 2026 |
| IBM Institute for Business Value | 70% say teams deploy technology faster than IT can track; 77% say adoption outpaces governance | 2,000 technology executives across 33 geographies | June 2026 |
| IBM Institute for Business Value | An average of 54 agent incidents per organisation in the year, 17% of them high severity | 2,000 technology executives across 33 geographies | June 2026 |
| IBM Cost of a Data Breach | One in five breached organisations had a shadow AI incident, adding up to 670,000 US dollars | 600 breached organisations across 17 industries | 2025 |
| IBM Cost of a Data Breach | Intellectual property was exposed less often than personal data but cost the most per record, at 178 US dollars | 600 breached organisations across 17 industries | 2025 |
| National Cyber Security Centre | Agents should hold their own identity; without isolation an agent may use the credentials of the account it runs under | UK government guidance | August 2026 |
| Microsoft Work Trend Index | 78% of AI users brought their own tools to work; 52% were reluctant to admit using AI on important tasks | 31,000 knowledge workers across 31 markets | 2024 |
Most organisations find their shadow AI after an incident rather than before. We map how each team actually works, surface the automation already running, and hand back agents the organisation owns and can measure. See how it works.
Frequently asked questions
What is shadow AI?
Shadow AI is the use of AI tools, models or agents inside an organisation without the approval, knowledge or oversight of the people accountable for technology and risk. It ranges from an employee pasting company information into a consumer chatbot to an unregistered agent running workflows against internal systems.
What is the difference between shadow AI and shadow IT?
Shadow IT describes unapproved software or hardware brought into an organisation, a procurement and licensing issue. Shadow AI describes unapproved AI use, where the tool processes company information rather than storing it, so the organisation loses sight of where that information goes and how it is reused.
How much does shadow AI cost an organisation?
IBM’s Cost of a Data Breach Report 2025, based on six hundred breached organisations, found that one in five had experienced a breach linked to shadow AI, adding as much as 670,000 US dollars to the average breach cost. Intellectual property was exposed less often than personal data but carried the highest cost per record, at 178 US dollars per record.
Who owns an AI agent built by an employee?
In the UK, section 11(2) of the Copyright, Designs and Patents Act 1988 provides that where a work is made by an employee in the course of their employment, the employer is the first owner of any copyright in it, subject to any agreement to the contrary. Legal ownership does not guarantee practical access. An agent built in a personal account may belong to the organisation while being impossible to reach once that person leaves.
Does banning AI tools reduce shadow AI risk?
No. Prohibition tends to increase shadow AI risk by moving activity out of view rather than stopping it. Microsoft research in 2024 found that fifty two per cent of people using AI at work were reluctant to admit using it on their most important tasks, with a similar proportion saying it made them look replaceable. Organisations get better results by providing capable approved tools and making the sanctioned route the faster one.
How do you find shadow AI in an organisation?
Start with an inventory rather than a policy, since a policy describes intended behaviour while an inventory records actual behaviour. Ask teams what they have automated rather than which tools they use, because the automation carries the business value. Give every agent its own identity and scoped permissions so activity is attributable, and monitor it as you would any other user activity.