Shadow AI: You're Probably Using AI Your Company Never Approved
Be honest: have you ever pasted a work email, a customer’s message, or a chunk of a document into ChatGPT, Claude, or some other AI tool your company never officially blessed — just to get the thing done faster?
If so, you’re in the majority. Survey after survey lands in the same place: somewhere between half and three-quarters of employees use AI tools their employer never approved. It’s so common it has a name now: Any AI tool people use for work that the company hasn’t formally sanctioned or secured — usually a consumer app accessed through a personal account, outside IT’s view. It’s the AI-era version of “shadow IT,” where employees quietly adopt whatever software actually helps them, approval or not. . And here’s the tell that this isn’t a fringe behavior: in one survey, 46% of people using unsanctioned tools said they’d keep using them even if their company explicitly banned them.
That’s not a workforce full of rule-breakers. It’s a workforce that found tools that genuinely help and isn’t willing to give them up. Which makes this worth understanding clearly — because most Shadow AI is completely harmless, and a small slice of it can quietly get you (or your company) into real trouble.
Why it exploded (it’s not rebellion)
People don’t reach for unapproved AI to be sneaky. They reach for it because it works — often better and faster than whatever the company officially offers, if it offers anything at all. When the sanctioned option is “nothing” or “a clunky internal tool,” and the unsanctioned option turns an hour of drudgery into ten minutes, the outcome isn’t surprising. People optimize for getting their work done.
So the interesting question was never “how do we stop this?” It’s “which uses are fine, and which are the ones that actually bite?”
The whole risk comes down to one thing: what you put in
Here’s the mental model that sorts it out. The risk of Shadow AI has almost nothing to do with getting an answer from an AI, and almost everything to do with what you paste in to get it.
When you paste text into a consumer AI tool through a personal account, that text leaves your company’s control. Depending on the product and its settings, it can be stored and even used as The material an AI model learns from. On many free or personal tiers, the things you type in can be retained and fed back into improving the model — which means a snippet of confidential text you pasted could resurface or leak influence elsewhere later. Business and enterprise tiers usually promise in writing that they won’t do this; consumer versions often make no such guarantee. The setting is worth checking on any tool you use. . That’s the whole ballgame. It’s why the same action can be totally fine or genuinely dangerous depending entirely on what the text is.
Genuinely risky — don’t paste these into an unapproved consumer tool:
- Customer or client data that identifies a real person — names, emails, account numbers, support tickets with personal details.
- Anything under an NDA or marked confidential — contracts, unreleased plans, internal financials.
- Credentials, API keys, or passwords.
- Proprietary source code, unless your company has approved a tool for it.
Almost certainly fine — paste away:
- Rewording or tightening your own draft that contains nothing sensitive.
- Brainstorming, outlining, or thinking out loud.
- Summarizing or explaining something that’s already public.
- Generic “how do I phrase this” and “what am I missing” questions.
Picture the difference concretely. A support rep pasting a customer’s full complaint — name, account, the works — into a personal ChatGPT account to draft a reply is taking a real risk. That same rep pasting “help me write a warm, apologetic reply to a frustrated customer whose order was late” — with no identifying details — is doing something completely safe. Same tool, same task. The only thing that changed is what went in.
Why banning it backfires
If you’re the manager reading this and reaching for the “block it” button — pause. That 46%-would-keep-using-it-anyway number is the warning. Ban the approved-but-safe tools and people don’t stop; they just move to their phones and personal accounts, where you have zero visibility and zero control. You’ve traded a manageable risk for an invisible one.
The organizations handling this well do the opposite of banning. They give people a sanctioned tool that’s actually good — a business-tier account that contractually won’t train on company data — plus a clear, short rule about what never gets pasted anywhere. A safe path people actually want to use beats a blocked path they’ll route around every time. (That’s the whole idea behind a one-page AI policy.)
How to use AI at work without becoming the cautionary tale
You don’t have to stop using AI. You just need a few habits that keep you on the safe side of the line:
- Default rule: if you’d hesitate to post it publicly, don’t paste it. That one instinct catches most of the danger.
- Strip the identifiers first. Anonymize before you paste — swap real names, accounts, and numbers for placeholders. The AI helps just as well with “[customer]” as with a real name.
- Use the approved tool if one exists, and prefer business/enterprise accounts, which typically promise not to train on your inputs.
- Check the data settings on whatever you use — many tools let you turn off chat history and model training. Do it.
- When you’re not sure, ask. “Is it okay to use AI for this?” asked out loud is a leak prevented. A quiet guess is how accidents happen.
None of this requires you to understand the technology deeply. It’s the same caution you’d apply to any place outside the company’s walls: be careful what you carry out.
The takeaway
Shadow AI is nearly universal, mostly harmless, and occasionally a genuine hazard — and the difference between those last two is entirely in your hands, because it’s entirely about what you paste. Keep the sensitive stuff in, use the tools freely for everything else, strip identifiers when in doubt, and push for a sanctioned option instead of a quiet workaround. You don’t have to choose between using AI and being responsible with it. You just have to know where the line is — and now you do.
Sources: The finding that roughly half of employees use unsanctioned AI tools — and that ~46% would keep using them even if banned — comes from Software AG’s workforce research, reported by CIO; other 2026 surveys put the share of employees using their own AI tools even higher (into the 70s%). Whether AI providers retain or train on what you type depends on the specific tool and plan — always check its data settings.
Related: Write a One-Page AI Policy Your Team Will Actually Follow for the manager’s side of this, and Do You Have to Tell People You Used AI? for the honesty question that sits right next to the safety one.