Shadow AI Is a Governance Problem
Most owners know their people use AI. Fewer are aware of what company information has gone into those tools, on what terms, and who approved it.
That gap is called shadow AI. Shadow AI is when people use AI for company work outside anything the business has approved or can see. That usually means well-meaning employees are using their personal AI account for company purposes. It is usually treated as an adoption issue. It is more useful to read it as a governance one.
Consider what happens at companies that have already done the obvious thing. A 2026 survey of 1,005 workers at U.S. companies with 500 or more employees, all of which provide paid access to approved AI tools, found that 89 percent had entered company data into an AI tool. Seventy-nine percent had entered genuinely sensitive information such as customer records, financial data and logins. Thirty-one percent had entered login credentials or software access keys. Half said they had ignored their employer’s AI restrictions, and 26 percent had used a personal device or account to reach a tool the company blocks.¹
These are organizations that chose a tool, paid for it and set rules. Buying the licences settled the adoption question. It did not settle the governance one.
The exposure is straightforward. Company information is moving through tools nobody approved and nobody can review. Work is being done in ways nobody has written down. And when a customer, an insurer or an auditor asks how your company uses AI, the truthful answer is that senior leaders do not know.
The instinct is to treat this as a discipline problem. That usually isn’t the most helpful perspective to take. Among people using personal accounts for work, 39 percent say the employer’s tool is too slow or difficult to get and 33 percent say it does not fit their needs.¹ Rules that make the approved path harder than the unapproved one push the activity further out of view.
So, what can we do about it? First, find out what is actually in use, asked as a question about making work easier rather than as an audit. People will tell you. Second, provide a commercial tool at least as good as what they found on their own, because the safe path has to be the easy path. Third, write down in plain language which categories of information may go into which tool, and what to do when someone is unsure.
Then train your people on AI. Among workers who felt confident about what they could share with AI at work, 82 percent had received formal training. Among those who were not confident, only 46 percent had.¹
Start by asking three people what AI tool they used last week. It’s insight into whether your business will need to adopt a stronger AI governance posture.
Source
¹ Zapier, “79% of workers have entered sensitive info like logins into AI,” July 29, 2026. Survey of 1,005 U.S. workers at companies with 500 or more employees, all of which provide employees with paid access to AI tools for business use.