Skip to main content
AI Adoption8 min read

Shadow AI Is Not a Discipline Problem

In one April 2026 survey, two-thirds of office professionals had used AI at work believing it was not permitted. In a 47-country study, over half of employees hide their AI use. Whatever the rules are producing, it is not zero use. It is use you cannot see.

MK

Mathieu Kessler

Founder, Kesslernity

Share:

Your organisation may not have rolled out AI. It got adopted anyway.

The adoption just happened where you cannot see it: in public AI tools, on accounts your organisation does not control. The people doing it are not fringe cases, and they are not acting out. They are staff getting their work done with the best tool they can reach, minus the one property you actually need, which is visibility.

The numbers, with their scope attached

Two studies this cycle put figures on it, and both are worth reading in the original, methods included.

The largest is the KPMG and University of Melbourne global study, which surveyed over 48,000 people across 47 countries between November 2024 and January 2025. Among its employee findings: 57% say they hide their use of AI and present AI-generated work as their own. Almost half admit to using AI in ways that contravene company policy, including uploading sensitive company information into free public tools. Two-thirds (66%) rely on AI output without evaluating its accuracy. And only 40% say their workplace has any policy or guidance on generative AI at all.

The sharper corporate cut is PagerDuty's 2026 shadow AI survey, run by Wakefield Research in April 2026 across 1,250 office professionals in non-IT roles at companies with at least $500 million in revenue, in the US, UK, Japan and Australia. 66% have used AI tools at work despite believing they were not permitted. 43% have entered work-related correspondence into public AI tools. More than a third (34%) have entered customer data. 31% have input financial information or disclosed confidential company documents or strategies.

Read the two 66s separately, because they come from different populations. In one, two-thirds used AI believing it was not permitted. In the other, two-thirds rely on AI output without evaluating its accuracy. Either number alone is enough to make this a governance problem rather than a curiosity.

What a ban actually buys you

The instinctive response is to prohibit harder: block the domains, update the acceptable-use policy, send the memo. The surveys cannot say whether bans cause the hiding, but they can say what coexists with them: where people believe use is forbidden, use continues at scale and much of it is concealed. Prohibition is demonstrably not producing zero use. It is producing use the organisation cannot see, and hidden use is worse on the axes a governance owner cares most about: visibility, teaching, and the data boundary.

  • You lose the telemetry. Sanctioned tools produce logs, usage data, and a picture of where AI helps. Use outside them gives the organisation no application-level record at all.
  • You lose the teaching moment. The employee pasting a contract into a free chatbot is exactly the person who needs to hear about data boundaries, and a rule they are already breaking makes them far less likely to ask.
  • The data leaves anyway. Work-related correspondence, customer data, financial information: the survey shows respondents entering each into public AI tools, which by definition sit outside the enterprise agreements you negotiated.
  • Concealment compounds. In the global study, 57% of employees say they hide their AI use and present AI-generated work as their own. Whatever drives that, work is shipping under a description of how it was made that is not true, and governance cannot reach what people will not admit exists.

A rule that two-thirds of surveyed professionals believed applied to them and used AI anyway is not functioning as a control. It is the appearance of one, purchased at the cost of the real thing.

Read it as a demand signal

Here is the reframe that makes the problem tractable: shadow AI is one of the more honest adoption signals an organisation gets, because by definition nobody mandated it and no change programme produced it. People who use AI covertly are people you did not have to convince, and the simplest reading of the numbers is unmet demand for tools that help with the work. It is a reading, not a proven motive, and it does not make the leak figures above acceptable: the demand signal and the data problem are the same fact viewed twice, and both views are true.

A demand signal does not get disciplined. It gets met, with guardrails. Five moves, in the order that matters.

The five moves

1. Give the demand a sanctioned lane that is actually good

Shadow AI concentrates where the sanctioned tool loses to a free chatbot on capability. If the enterprise tool is slower, more restricted, or a generation behind, many people will route around it, policy or not. The first governance spend is not monitoring software; it is making the approved lane capable and low-friction inside your data boundary, so choosing it costs as close to nothing as you can manage.

2. Write the one-page guidance most employees say they lack

Only 40% of employees in the global study say their workplace has any generative AI guidance; for the rest, whatever policy exists is folklore to them. The fix is not a thirty-page document; it is one page that names three things: which tools are approved, which data classes stay inside per your own data-classification policy (customer data, financials and credentials are the usual core), and who is accountable for reviewing what ships. A page an employee can hold in their head is the only kind that competes with a paste shortcut.

3. Make disclosure safe

The global study says 57% hide their use; it does not say why. A plausible reading is that hiding is the rational move wherever admitting AI use invites doubt about competence, and if that is true anywhere in your organisation, the fix is incentives rather than exhortation. Write into the policy text that saying “AI drafted this, I verified it” is a normal disclosure and not misconduct, and have managers ask what tools people use as a curiosity question rather than an audit question. How to treat past incidents, especially anything involving sensitive data, is a decision for HR, legal and security together, not a line in a blog-shaped policy. You cannot govern what people will not admit exists.

4. Instrument the boundary, not the person

The monitoring conversation goes wrong when it becomes surveillance of employees. Point the controls at the data boundary instead: data-loss prevention on what leaves for public AI endpoints, sensitivity labels that travel with documents, and network-level visibility of which AI services are in use. Boundary controls need their own proportionality and privacy review, and access to what they collect should stay narrow. But the direction matters: watching the boundary aims at the incident, while watching the person mostly teaches better hiding.

5. Keep one rule that survives every tool change

Tools will churn every quarter. The rule that does not: AI prepares, humans decide. The person who ships work is accountable for that work, verified, whatever drafted it, inside the organisation's wider accountability model rather than instead of it. That duty aims at the 66% who rely on AI output without evaluating it, because it anchors verification to the clearest possible place: the named human on the deliverable.

The metric to watch

One indicator worth watching: the shadow number falling while total use rises, demand moving into a lane you can see. It is an indicator rather than a verdict, and it belongs next to harder measures: data-handling incidents, disclosure rates, and how often shipped work was actually verified. Two questions stay with named owners rather than with any blog post: what happens when sensitive data has already gone out, which is an incident and possibly a notification duty to run with counsel, and who owns the policy, the tool list and the exceptions. But the day an employee tells you unprompted which AI tool they used on a deliverable, you will have recovered the thing prohibition spends: the truth about how work gets done in your organisation.

Sources

Kesslernity is an independent practitioner publisher with no vendor sponsorship. Figures above are quoted from the named studies with their original scope; neither study was commissioned by or involves Kesslernity.