Shadow AI: How to Find Out If Your Team Is Already Using AI
Your team is probably already using AI tools you have not approved. Shadow AI is not a hypothetical risk. Here is how to find out how much of it is happening.

Adam Nameh
October 6, 2026 · 9 min read
In This Article
- How common shadow AI is
- Why it happens even at well-run companies
- What shadow AI costs when it goes wrong
- A quick self-check for IT and department leads
- What to do with what you find
- Building a shadow AI inventory without starting a panic
- Writing a policy people will follow
- What a realistic 60-day response looks like
- How this differs from a standard security audit

Shadow AI is any AI tool an employee uses for work without IT's knowledge or approval, from a personal ChatGPT account used to draft a client email to a free browser extension that summarizes documents. Most companies assume this is rare. The data says otherwise.
How Common Shadow AI Is
Microsoft's own 2024 Work Trend Index, based on a survey of 31,000 workers across 31 markets, found that 78% of generative AI users bring their own AI tools to work, rising to 80% at small and medium-sized companies. More strikingly, 52% of people using AI for important work tasks say they are reluctant to admit it. Separately, a Gartner survey of cybersecurity leaders found 69% suspected or had direct evidence of employees using generative AI tools their company had not approved.
Why It Happens Even at Well-Run Companies
Shadow AI is rarely rebellion. It is almost always a gap: an employee has a real task, no approved tool handles it well, and a free AI tool is one browser tab away. The faster a company's official rollout moves, the less room shadow AI has to fill that gap. The slower it moves, the more it grows.
Shadow AI and BYOAI, employees bringing their own AI tools to work, describe largely the same behavior from two angles. Shadow AI is the governance risk framing IT and security teams use. BYOAI is the adoption-pattern framing that explains why it happens in the first place. Our BYOAI post covers that second half in more detail.
What Shadow AI Costs When It Goes Wrong
Shadow AI incidents more than doubled this year, from 20% to 43% of AI-related security incidents, now averaging $5.39 million per breach, up from $4.63 million the year before. IBM's 2026 Cost of a Data Breach Report found that 21% of those incidents, roughly one in five, led to a regulatory fine, and that 92% of organizations that had an AI-related breach had no AI access controls in place when it happened.
A Quick Self-Check for IT and Department Leads
Answer these honestly about your own team, not the company's official policy.
Has anyone on the team pasted a client name, contract detail, or financial number into a free AI chatbot in the last month? If you are not sure, the honest answer is probably yes.
Does the team have an approved AI tool that covers the tasks people use free tools for today? If not, shadow AI is filling a real gap, not just a bad habit.
Would an employee know who to ask before trying a new AI tool for a work task? If there is no clear answer, there is effectively no policy, whatever is written down somewhere.
Has IT ever reviewed browser extension or app installs specifically for AI tools? Most companies that check are surprised by what they find already installed.
Does anyone track which AI tools different teams are using, even informally? If the honest answer is no, this self-check is likely underestimating the real number.
Two or more honest "yes, this is a gap" answers is a strong sign shadow AI is already active on your team, whether or not anyone has said so out loud.
What to Do With What You Find
The instinct after finding shadow AI is often to ban it outright, which usually just pushes the same behavior further out of sight. A more effective response names the gap the shadow tool was filling and offers an approved alternative that covers it, then treats continued unapproved use as a training and policy conversation rather than purely a disciplinary one.
Building a Shadow AI Inventory Without Starting a Panic
The goal of a first audit is not to catch anyone. It is to find out, honestly, what tools are already in use so a rollout plan reflects reality instead of a policy document's assumptions. Framing the audit that way, explicitly, before it starts, changes how honestly people answer.
Start with an anonymous survey, not a named one. Anonymous answers about which AI tools someone has used for work in the last month tend to surface far more honest numbers than a survey tied to a name, given how many people are already reluctant to admit this kind of use.
Pull a list of browser extensions across managed devices. Free AI writing and summarizing extensions are commonly installed without IT ever approving them, and this list alone often surprises companies that assumed their device management was tight.
Check network logs for known AI tool domains over the last 90 days. This step catches usage the survey and extension review might miss, particularly from personal devices connecting through company Wi-Fi.
Compare the three sources against each other, not just individually. A tool that shows up in network logs but nobody admitted to using in the survey is the clearest sign the survey undercounted, and a useful number for calibrating future surveys.
Writing a Policy People Will Follow
A policy that only says AI tools require approval, with no fast path to get that approval, produces exactly the same shadow AI behavior as no policy at all, since the underlying time pressure that drove the workaround never went away. A policy that works names which tasks already have an approved tool, gives a specific person or team to contact for anything not yet covered, and commits to a turnaround time for that request, typically a few days rather than an open-ended review. Employees follow policies that are faster than the workaround. They route around ones that are not.
What a Realistic 60-Day Response Looks Like
Days 1-14: run the inventory above. Get an honest picture before deciding anything about policy or enforcement.
Days 15-30: identify the two or three most common unapproved use cases. These almost always cluster around writing, summarizing, and basic research, not exotic tasks.
Days 31-45: get an approved tool in front of the people doing those specific tasks. Speed here matters more than a perfect long-term platform choice.
Days 46-60: revisit the inventory. A meaningful drop in unapproved use is the clearest sign the approved alternative covers the gap; if the drop is small, the alternative missed the mark and needs another look.
Doing nothing does not freeze shadow AI in place. It grows quietly as more free AI tools become available and as more employees hear from a colleague that a particular tool saved them real time on a task. A company that revisits this question in a year having done nothing typically finds a larger, more entrenched version of the same gap, now spread across more tools and more departments than the version it could have addressed today with far less disruption.
How This Differs From a Standard Security Audit
A shadow AI audit is not the same exercise as a standard IT security audit, and treating it that way tends to produce a report full of technical findings that never gets acted on by the people who could fix the underlying gap. A standard security audit asks what could go wrong. A shadow AI audit needs to also ask why people reached for an unapproved tool in the first place, which is a question about workflow and time pressure as much as it is a question about access controls. Pairing a technical review with a handful of honest conversations with the people doing the work tends to produce a far more useful result than either one alone.
Companies running their first honest audit almost always find more shadow AI than expected, not less, given how consistently the survey research above points to the majority of AI users bringing their own tools regardless of company size or industry. Treating that discovery as confirmation the audit worked, rather than as a surprising failure of oversight, keeps the response focused on fixing the gap instead of assigning blame for something that was already happening industry-wide before anyone measured it locally.
Alphabyte helps companies find out what is being used before writing a policy that ignores it. Our data readiness work includes exactly this kind of audit, so a rollout plan is built around real behavior, not a guess. If you want an honest picture of what your team is already using before you write a policy around it, talk to our team.
Frequently Asked Questions
Is shadow AI always a security problem?
Not automatically, but the risk rises fast once company or customer data is involved. A free AI tool used for personal brainstorming carries far less risk than the same tool used to draft something referencing real client information.
Can we technically block all unapproved AI tools?
Partially, through network and device controls, but determined employees find workarounds, especially on personal devices. Blocking works better paired with an approved alternative than used alone.
Should we punish employees for using shadow AI?
Rarely as a first step. Most shadow AI use comes from a real gap in approved tools, not malicious intent. Punishment without a better alternative tends to just make the behavior harder to see.
How do we find out what AI tools are already in use?
A mix of an honest internal survey, a review of browser extensions and approved app lists, and network traffic review for known AI tool domains gives a realistic picture, more reliable than asking people to self-report alone.
Does a written AI policy reduce shadow AI?
Only if it is specific and paired with an approved tool that covers real tasks. A policy that only says "don't use unauthorized AI" without offering an alternative rarely changes behavior.
Is shadow AI more common in certain departments?
Departments with heavy writing or research workloads, like marketing, sales, and HR, tend to show the most shadow AI use, simply because those tasks map most directly onto what free AI chatbots do well.
Does company size change how much shadow AI exists?
Microsoft's research found it is more common at small and medium-sized companies, likely because smaller IT teams have less capacity to roll out and enforce approved alternatives quickly.
Adam Nameh
Co-Founder, AI Practice. Adam Nameh is the Co-Founder of Alphabyte Solutions Inc., a Toronto-based data and AI consulting firm that has helped over 100 clients across North America turn complex data environments into actionable business intelligence. With a decade of hands-on experience in data architecture and platform design, Adam works directly with leadership teams to deliver practical AI and data solutions that drive real business outcomes.
View full profile →More from the blog

BYOAI: When Employees Bring Their Own AI to Work
78% of AI users already bring their own AI tools to work. BYOAI is not a future trend. It is your team's current reality, whether IT has caught up or not.
Read more →

What Is Copilot Studio? What It Does and When to Use It
Copilot Studio is not Copilot. It is the tool that builds the custom agents Copilot alone cannot. Here is what that means in practice.
Read more →

Copilot vs ChatGPT: Which Fits Your Business?
Both connect to a chat window. Only one connects to your actual files. Here is how Microsoft 365 Copilot and ChatGPT for business really compare.
Read more →