Shadow AI: What Employees Actually Paste Into AI Tools
Shadow AI is the use of AI tools for work that the organisation has not sanctioned, usually through personal accounts on consumer tiers, outside any administrative control and invisible to the people accountable for the data. It is not primarily a story about rule-breaking. It is what happens when the work arrives before the decision does, and the fastest way to get the work done is a browser tab that nobody had to approve. The measurable consequence, in IBM’s breach data, is that one in five studied organisations experienced a breach linked to it, and those incidents added as much as USD 670,000 to the average breach cost.
Published 5 September 2026. Last updated 5 September 2026, the date on which every source cited below was fetched and read at source.
A note on whose data this is
Shadow AI statistics circulate in a badly degraded state, and a large family of widely quoted percentages could not be traced to any original publication during the research for this page. They are therefore absent from it. What follows separates three kinds of evidence and labels each one: breach data from IBM with the Ponemon Institute as the named research partner, nationally representative survey data from the University of Melbourne and KPMG, and browser telemetry from security vendors whose product is the remedy. The third kind is useful for behaviour and unreliable for magnitude. Where it is used here, the method is stated in the sentence.
Those four figures come from IBM’s Cost of a Data Breach research covering 600 organisations studied by the independent Ponemon Institute. They describe one failure rather than four. The tools arrived, nobody attached an identity to them, and there was no policy saying which surface was for which kind of content. IBM adds one more detail that sharpens it: customer personal data was compromised in 53 percent of breaches generally, and in the breaches involving shadow AI that figure rose to nearly two thirds, at 65 percent. Shadow AI is not leaking drafts. It is leaking the records with the most regulatory weight attached.
What do employees actually paste, and why?
The best evidence here is the University of Melbourne and KPMG global study, because it is nationally representative rather than drawn from a vendor’s customer base: 48,340 respondents across 47 countries, sampled to be representative by age, gender and region. Its headline finding on this behaviour, quoted directly, is that 48 percent of employees report that they have uploaded company information, such as financial, sales, or customer information, into public AI tools.
Read the base of that number carefully, because it is routinely misquoted. In the underlying figure, 52 percent answered never, 14 percent rarely and 34 percent sometimes to very often. So 48 percent is the share who have ever done it, and 34 percent is the share doing it with any regularity. Both are worth knowing and they are not interchangeable.
The same study puts the motive in view, and it is not malice. Forty-eight percent of employees report feeling concerned about being left behind if they do not use AI at work, and the report finds a positive association between how much strain employees feel and how complacently they use AI. Fifty-six percent say they have used AI tools at work without knowing whether it was allowed. That is the sentence to sit with. In more than half of cases the employee was not defying a rule. They could not find one.
On what the pasting looks like mechanically, the most detailed public numbers come from LayerX, and the method has to travel with them: the figures are browser telemetry collected by a security extension deployed inside its own enterprise customer base, with no sample size disclosed, published by a vendor that sells the control. Directionally, the report finds that 45 percent of enterprise users are actively using AI platforms, that 77 percent of users paste data into generative AI tools and 82 percent of that activity comes from unmanaged accounts, that 22 percent of the users who paste are pasting personal or payment card data, and that 40 percent of files uploaded into generative AI tools contain the same. It reports an average of 14 pastes per day through non-corporate accounts, at least three of which contain sensitive data.
Cyberhaven’s 2026 report, also vendor telemetry from its own customer base and also without a disclosed sample size, lands in the same region from a different angle: 39.7 percent of all data movements into AI tools involve sensitive data, and 32.3 percent of ChatGPT usage occurs through personal accounts. Two vendors with different products and different customers agree that roughly a third of usage sits outside organisational identity. That convergence is worth something even if neither number should be quoted to the decimal place.
What gets pasted, then, is not exotic. It is the contract someone needs summarised, the customer email that needs a polite reply, the spreadsheet that needs explaining, the meeting notes that need turning into actions. The content is ordinary. The surface is the problem.
Does blocking AI tools reduce shadow use?
The available evidence says no, and one finding is unusually direct about it. In the Melbourne and KPMG study, behaviours that contravene organisational rules were most common among employees who report that their organisation has banned generative AI, at 67 percent, and among those with a policy guiding its use, at 56 percent, compared with 33 percent in organisations without such policies and 38 percent among those unsure whether a policy exists. The report’s own reading is that outright bans may be ineffective, and that simply having a policy does not guarantee compliance.
That result deserves a caution rather than a victory lap. Organisations that impose a ban are not a random sample. They are more likely to handle sensitive data, more likely to have noticed a problem already, and their staff are more likely to know what the rule is and therefore to recognise breaking it in a survey question. The finding does not prove that banning causes leakage. What it does establish is that a ban is not observably associated with less of the behaviour, which is the claim the ban is usually bought on.
The mechanism is easier to see from the supply side. BCG’s survey of 10,635 employees found that 37 percent say their company is not supplying the right tools, and that when corporate solutions fall short, 54 percent say they would use unauthorised AI tools. A ban does not remove the demand that created the behaviour. It removes the sanctioned channel and leaves the demand, which is a definition of shadow IT that predates AI by two decades.
The governance numbers put the starting point in view. ISACA’s 2026 poll of more than 3,400 digital trust professionals found only 38 percent of organisations have a formal, comprehensive AI policy, 25 percent have none, 90 percent believe employees are using AI in their organisation, and 33 percent train all employees on AI. Ninety percent usage against thirty-eight percent policy is the gap this page is about.
What one documented incident looked like
The most useful concrete case is Samsung’s, because it is on the public record from multiple independent accounts rather than in a vendor’s marketing.
Employees in Samsung’s device solutions division shared sensitive company information with ChatGPT while using it to help with work. The AI Incident Database records the leak as covering source code and internal meeting notes, with at least three separate instances identified. The accounts differ on timing, with the incident database placing the events in March 2023 and contemporaneous reporting describing an April leak, so the honest statement is spring 2023 rather than a specific week.
Samsung’s response is the part worth studying. On 1 May 2023 it temporarily restricted the use of generative AI tools on company-owned devices, covering computers, tablets and phones, and on non-company-owned devices running on internal networks. An internal memo said the restriction would hold until the company built, in its words, security measures to create a secure environment for safely using generative AI to enhance employees’ productivity and efficiency.
What the Samsung case actually demonstrates
Three things, and none of them is that AI is dangerous. First, the leak came from competent engineers doing their jobs, not from anyone careless. Second, nobody had told them which surface was appropriate for source code, and the tool did not ask. Third, the company itself framed the restriction as temporary and conditional on building a safe internal environment, which is the correct shape of the answer: the fix is a sanctioned surface, not a permanent prohibition on a capability the organisation clearly wanted.
What does an approved-tool list actually change?
It changes which side of the vendor’s terms your data lands on, and it changes whether anyone can see what happened.
The technical substance is that most major assistants treat consumer accounts and organisational accounts under different terms, with different training defaults, different retention and different administrative control. Which tier a person is signed into, rather than what the tool is called or what it costs, is what decides the answer. That is a factual question with product-specific answers, and it is the subject of a separate page kept under quarterly re-verification: does your AI vendor train on your data. Lithuanian readers will find the same table in ar DI tiekėjas mokosi iš jūsų duomenų.
The governance substance is IBM’s 97 percent. Access control is precisely the thing an organisational account provides and a personal account does not. Without it there is no record of who used what, no ability to revoke access when someone leaves, no route to answer a data subject request about material that was pasted, and no way to establish after an incident what actually left the building. A list of approved tools, bought on organisational identity with the administrative settings configured, converts an invisible risk into a governed one. It does not eliminate the risk. It makes it a risk somebody owns.
An approved list is only half the instrument, though. The other half is a stated rule about content: which categories of material may go into a sanctioned tool at all, who approves an exception, and, critically, who to tell when something confidential went in by mistake. That last line is the one most policies omit, and its absence guarantees that the first person to make the mistake will handle it by saying nothing.
Personal account against organisational account
| What you need after an incident | Personal account | Organisational account |
|---|---|---|
| A record of who had accessSource: IBM X-Force, 2025 | None available to the employer | Administrative visibility, subject to the vendor’s controls |
| Any view of what was submittedSource: LayerX, 2025 | None. In vendor telemetry, 82 percent of pasting into AI tools comes from unmanaged accounts | Governable at the browser or platform layer |
| Contractual terms that bind the vendor to youSource: Cyberhaven Labs, 2026 | Consumer terms, agreed by the individual | Business or enterprise terms, agreed by the organisation |
| Ability to revoke access when someone leaves | None. The account belongs to the person | Deprovisioning through the organisation’s identity system |
| Ability to answer a regulator or a data subjectSource: IBM, Cost of a Data Breach 2025 | Nothing to answer from | A basis to answer from, if the settings were configured |
| Cost when it goes wrong | As much as USD 670,000 added to the average breach, per IBM | The same incident, with the evidence to bound it |
A voice or customer-facing system raises the same questions with higher stakes, because the material passing through it is somebody else’s personal data rather than your own internal notes. The equivalent supplier questions are set out in our AI vendor security assessment template, in the voice AI security and compliance checklist, and, for the residency question specifically, in EU data residency compared.
The duty that survives every policy: checking the output
Every control described above governs what goes into the tool. None of them governs what comes out, and that is the half where the damage is quieter and more frequent.
In the Melbourne and KPMG study, 66 percent of employees report having relied on AI output at work without critically evaluating the information it provides, 72 percent report putting less effort into their work because of AI, and 56 percent report having made mistakes in their work from AI use. Over half, 57 percent, admit to using AI in non-transparent ways, including presenting AI-generated content as their own or avoiding revealing that they used it. The study’s own conclusion is that this complacent use may be fuelled by inadequate training, guidance and governance of responsible AI use at work.
That last set of numbers is the reason a shadow AI programme cannot stop at procurement. If people conceal that they used a tool, no reviewer knows which claims to check. If nobody checks, the error rate the survey reports goes straight into client-facing work.
Europe has a view on this, and it is more modest than the compliance marketing suggests. Asked whether a company whose employees use ChatGPT for, say, writing advertisement text or translating must comply with the AI Act’s literacy obligation, the European Commission answers: “Yes, they should be informed about the specific risks, for example hallucination.” Asked how compliance should be documented, it answers: “There is no need for a certificate. Organisations can keep an internal record of trainings and/or other guiding initiatives.” The obligation is to make sure people know what can go wrong, not to buy anyone a qualification. The exact wording, what changed in the July 2026 rewrite, and why no EU fine attaches to that article are set out in what EU AI Act Article 4 actually requires.
Six steps that reduce the exposure
Find out what is already being used, without punishing the answer
An inventory taken under threat of sanction returns a fiction. Ask what people use and what they use it for, say in advance that nobody is in trouble, and expect the list to be longer than the licence register. Ninety percent of digital trust professionals believe employees in their organisation are using AI, while only 38 percent report a formal comprehensive policy.
Source: ISACA, AI Pulse Poll 2026Sanction a small number of tools on organisational identity
Choose a short list, buy it on business or enterprise terms, and configure the administrative settings before announcing it. The absence of access control is the single most consistent feature of AI-related incidents in the breach data, present in 97 percent of the organisations that reported one.
Source: IBM X-Force, Cost of a Data Breach 2025Write the content rule in three lines, not thirty pages
What may go in, what may not, and who to tell when something confidential went in by mistake. A policy nobody can recall under time pressure is not a control. More than half of employees say they have used AI at work without knowing whether it was allowed, which is a discoverability failure rather than a defiance problem.
Source: University of Melbourne & KPMG, 2025 (n=48,340)Close the gap that created the workaround
If people reach for an unsanctioned tool, the sanctioned one is missing, slower or worse. Thirty-seven percent of employees say their company is not supplying the right tools, and 54 percent say they would use unauthorised AI tools when corporate solutions fall short. Fixing the supply removes more shadow use than any prohibition.
Source: BCG, AI at Work 2025 (n=10,635)Teach the risks by name, starting with plausible-sounding errors
The European Commission’s answer for ordinary chatbot use at work is that staff should be informed about the specific risks, giving hallucination as its example. That is a short, concrete briefing, not a course, and it is the single highest-value thing to say to people who already use these tools daily.
Source: European Commission, AI literacy Q&AKeep an internal record, and refresh it
What was delivered, to whom, when, and the materials themselves, versioned. No certificate is required. Vendor terms and product behaviour change without notice, so the record needs a review date rather than a completion date.
Source: European Commission, AI literacy Q&ANone of that is expensive, and none of it is a technology project. It is a decision about which tools are sanctioned, a short written rule about content, a briefing that names the failure modes, and a record that someone reviews. The reason it so often does not happen is the same reason larger AI programmes do not deliver, which we set out with the evidence in why AI rollouts stall: the organisational half of the work is where the difficulty sits and where the budget usually is not. If you want the version that starts from what a team should be taught and how a programme is assembled around the roles people hold, that is on our AI training for companies page. And if the immediate question is simply what a team should be doing with the assistants it already has, ten practical business uses of ChatGPT is the concrete starting point.
One closing observation from the data. Shadow AI is usually described as a discipline problem, and the numbers do not support that reading. Half of employees who did it were unsure whether it was allowed, half feel they will be left behind if they do not use these tools, and the behaviour is most common precisely where a rule exists. This is a signal about missing infrastructure, not about character. The organisations that reduce it are the ones that give people somewhere sanctioned to go and tell them plainly what to watch for.
Frequently Asked Questions
Shadow AI is the use of AI tools for work that the organisation has not sanctioned, typically through personal accounts on consumer tiers that sit outside administrative control. It is the AI-era form of shadow IT. IBM’s breach research found that one in five studied organisations experienced breaches linked to shadow AI, and that these incidents added as much as USD 670,000 to the average breach cost.Source: IBM, Cost of a Data Breach 2025
In a nationally representative study of 48,340 people across 47 countries, 48 percent of employees reported that they have uploaded company information such as financial, sales or customer information into public AI tools. Read the base carefully: 52 percent answered never, 14 percent rarely and 34 percent sometimes to very often, so 48 percent is the share who have ever done it and 34 percent is the share doing it with any regularity.Source: University of Melbourne & KPMG, 2025 (n=48,340)
The available evidence does not support that. In the Melbourne and KPMG study, behaviours contravening organisational rules were most common among employees whose organisation had banned generative AI, at 67 percent, against 33 percent in organisations with no such policy, and the report concludes that outright bans may be ineffective. Organisations that ban are not a random sample, so this does not prove that banning causes leakage. It does show that a ban is not associated with less of the behaviour.Source: University of Melbourne & KPMG, 2025 (n=48,340)
Employees in Samsung’s device solutions division shared sensitive company information with ChatGPT while using it for work, with the AI Incident Database recording source code and internal meeting notes across at least three separate instances. Accounts differ on whether the events fell in March or April 2023. On 1 May 2023 Samsung temporarily restricted generative AI tools on company-owned computers, tablets and phones, and on non-company devices running on internal networks, until it could build a secure environment for their use.Source: AI Incident Database, incident 768
Because it changes the contractual and technical position rather than only the stated expectation. Buying on organisational identity brings business terms, administrative settings, deprovisioning when someone leaves, and a record of access. IBM found that 97 percent of organisations reporting an AI-related security incident said they lacked proper AI access controls, and that 63 percent had no AI governance policy at all. Which account tier a person is signed into, rather than which tool they use, is what decides how the vendor treats the data.Source: IBM X-Force, Cost of a Data Breach 2025
Treat them as directional. Reports such as LayerX and Cyberhaven are built on telemetry collected inside the vendor’s own customer base, usually with no sample size disclosed, and the vendor sells the control that the finding argues for. Their behavioural patterns are informative, and two vendors with different products converging on roughly a third of AI usage running through personal accounts is worth noting. For magnitude, prefer IBM’s breach research with the Ponemon Institute as the named partner, or nationally representative survey work.Source: LayerX, Enterprise AI and SaaS Data Security Report 2025
Article 4 requires providers and deployers to take measures to support the development of AI literacy of their staff and of others acting on their behalf, and since the July 2026 rewrite the same article states that it does not require any specific level to be guaranteed for any individual. Asked about ordinary workplace use of a chatbot, the European Commission answers that staff should be informed about the specific risks, giving hallucination as its example, and states separately that there is no need for a certificate and that an internal record of trainings is sufficient.Source: European Commission, AI literacy Q&A
Not checking it. In the Melbourne and KPMG study, 66 percent of employees report having relied on AI output at work without critically evaluating the information it provides, 56 percent report having made mistakes in their work from AI use, and 57 percent admit to using AI in non-transparent ways including presenting AI-generated content as their own. Concealed use is what makes the error rate hard to catch, because a reviewer does not know which claims to verify.Source: University of Melbourne & KPMG, 2025 (n=48,340)
Founder & CEO, AInora
Building AI digital administrators that replace front-desk overhead for service businesses across Europe. Previously built voice AI systems for dental clinics, hotels, and restaurants.
View all articlesReady to try AI for your business?
Hear how AInora sounds handling a real business call. Try the live voice demo or book a consultation.
Related Articles
Does Your AI Vendor Train on Your Data?
Training defaults, EU residency, retention and admin controls tier by tier, each cell sourced to the vendor doc it came from.
EU AI Act Article 4: What the AI Literacy Rule Actually Requires
The 27 July 2026 rewrite, why no EU fine attaches to it, and what an evidence file contains.
Why Do AI Rollouts Stall?
What the adoption research actually says, including the reading of the famous 95 percent figure that almost nobody checks.
AI Vendor Security Assessment Template
The questions to put in writing before an AI supplier touches customer data.