Journal / Technology

Technology

Shadow AI: The Tools Your Team Already Uses

Most people using AI at work brought it themselves, on a personal account, into a product that trains on what they paste. The policy question is not whether to allow it. It is whether you can see it.

11 min readResolution

AI adoption inverted the pattern of every previous enterprise technology. It did not arrive from above, bought by management and deployed by IT. It arrived from below, brought in by each person, on their own account, without asking anyone.

Microsoft and LinkedIn's 2024 Work Trend Index — 31,000 respondents across 31 countries — measured it: 75% of knowledge workers use generative AI at work, and 78% of them bring their own tool. At small and medium businesses that figure rises to 80%.1

The same survey contains the detail that explains why owners cannot see it: 52% of people using AI at work are reluctant to admit they used it on their most important tasks, and 53% worry it makes them look replaceable. The practice is majority behaviour and it is deliberately invisible.

the approved path IT evaluation personalpersonalpersonalpersonal... the path actually taken
fig. 01 — the approved path, and the path actually taken

The size of what leaves

Verizon's Data Breach Investigations Report is the largest incident dataset in the industry. In the 2025 edition, 15% of employees regularly accessed generative AI on corporate devices — and only 11% of that access went through a properly governed corporate channel. The rest used personal email or corporate email without single sign-on.2

In the 2026 edition, regular users rose to 45%, 67% of them on non-corporate accounts. Analysing 858,440 data-loss events, the report found that source code was the most frequently submitted data type to external models.

Cyberhaven, which measures this through product telemetry — and sells a product for the problem, which should be said — tracks the share of pasted content that is sensitive: 10.7% in 2023, 27.4% in 2024, 34.8% in 2025, and 39.7% in the following edition, with the average employee entering sensitive data roughly once every three days.3

The case that became the reference

On 11 March 2023, Samsung's semiconductor division officially permitted ChatGPT. Within about twenty days there were three separate leaks, reported by The Economist of South Korea on 30 March and subsequently confirmed by Bloomberg:

  • an engineer pasted proprietary source code from a fabrication measurement program to fix a bug;
  • another pasted code for identifying defective equipment;
  • a third fed an internal meeting transcript in to generate minutes.

By May, Samsung had banned generative AI on company devices and networks.4

Nothing in that sequence required bad faith. Three people trying to work better, in a newly authorised tool, with nobody having explained what could not go into it.

What the terms of service actually say

This is the part almost nobody reads, and it is where the decision lives. Verified against the official pages in August 2026:

  • ChatGPT free, Plus and Pro — trains by default, with an opt-out; roughly 30 days of abuse retention even when opted out. Business, Enterprise and API — does not train.
  • Gemini consumer — used to improve services including model training, with human review, and Google's own notice tells you not to enter anything confidential. Conversations reviewed by a human are retained for up to three years and are not deleted when you delete your activity. Gemini for Workspace — governed by the enterprise agreement.
  • Claude free, Pro and Max — since 28 August 2025, trains by default unless you opt out, with five-year retention if you allow it and 30 days if you do not. Claude for Work, API, Government and Education — excluded, under commercial terms.

Two things stand out. The boundary is not between tools — it is between the free account and the business account of the same tool. And Google's retention of human-reviewed conversations survives the delete button.

the same tool free / personal account business account trains by defaultretention measured in years does not traincontractual retention
fig. 02 — same tool, two accounts, two destinations for your data

What it costs when it goes wrong

IBM's 2025 Cost of a Data Breach report with the Ponemon Institute — 3,470 interviews across 600 organisations — found shadow AI a contributing factor in 20% of breaches, at an average $4.63M against $3.96M for the rest: about $670,000 more per incident. In 97% of those cases there were no proper access controls on AI tools, and 63% of breached organisations had no AI governance policy at all.5

Those are enterprise figures and they do not transfer to a ten-person operation. What transfers is the structure of the problem: the cost does not come from the tool, it comes from the absence of any rule about it.

Banning does not work, and there is data on that

The reflex is to ban. The available numbers say banning changes visibility, not behaviour.

Software AG's "Chasing Shadows" survey of 6,000 knowledge workers across the US, UK and Germany found that 46% would refuse to give these tools up even if their organisation banned them completely.

A TrustedTech survey with Censuswide, of 2,001 employees, carries the more uncomfortable finding: unapproved AI use rises with seniority — 73% at C-suite level against 36% at entry level. The problem is not the reckless junior. It is the leadership.

A policy that only says "do not use generative AI" is not a strategy. It pushes the usage further underground, where you can see even less of it.

What to do in a small company

  1. A one-page acceptable-use policy. What can go in, what cannot, which tools are accepted. Without it, your actual policy is whatever each person's personal account defaults to.
  2. Pay for the business accounts. Highest-return item on the list, and counter-intuitive: a team plan costs less than the alternative of your team continuing on the free tier, where the same vendors do train on your data.
  3. Three classification levels, not thirty. Public, internal, and never-paste. Client data, contracts, proprietary code and financials go in the third.
  4. Turn on single sign-on. Without it you cannot know who is using what — which is exactly what the governed 11% in the Verizon data had and the other 89% did not.
  5. Ask before you prohibit. Finding out which tools your team already uses, and why, is more useful than any ban — and it is the only way an approved-tools list will actually cover the work people do.

The rule that summarises all of it: govern and enable, do not ban. Successful prohibition does not exist on this subject. Prohibition you cannot see does.

Further reading

Books that shaped this article, including the ones we disagree with. Where a work is popular rather than peer-reviewed, we say so.

Shoshana Zuboff — 2019
On how default data collection becomes normal without anyone agreeing to it. Long and polemical; read it critically, but the mechanism is the one at work here.
Bruce Schneier — 2018
Security treated as a problem of incentives rather than of technology. The reason your policy matters more than your tooling.

Resolution is a participant in the Amazon Services LLC Associates Program. As an Amazon Associate we earn from qualifying purchases — at no additional cost to you. Affiliate links never determine what appears on these lists: several of these books are here specifically because we think they are wrong in an instructive way.

References & notes

  1. Microsoft and LinkedIn (2024). Work Trend Index Annual Report, 8 May 2024 — 31,000 respondents across 31 countries.
  2. Verizon, Data Breach Investigations Report, 2025 and 2026 editions.
  3. Cyberhaven, AI adoption and risk reports, 2023–2026. Product telemetry from a vendor with a commercial interest in the subject; directional rather than independent.
  4. The Economist of South Korea, 30 March 2023; confirmed by Bloomberg; Forbes coverage, 2 May 2023.
  5. IBM and Ponemon Institute (2025). Cost of a Data Breach Report — 3,470 interviews across 600 organisations.
  6. Software AG, Chasing Shadows (6,000 respondents); TrustedTech with Censuswide (2,001 respondents). Both commercial surveys.
  7. Terms of service of OpenAI, Google and Anthropic, consulted August 2026. These change; verify against the current pages before acting.

Corrections are published inline and dated. Write to us if something here is wrong.

// weekly dispatch

One email. Every Tuesday.

The week's analysis, one tool we actually tested, and one behavioural pattern worth practising. Unsubscribe in one click.

// no spam · no resale · ~4 emails a month