Shadow AI: Gold in the Dark

Nick Erskine-Shaw|Founder|

Also published on LinkedIn

Everyone is using AI. At home, at work, and in the wide grey zone between. At most desks it arrived the same way: no approval, no rollout, no map. Someone opened a tab, got an hour back, and never mentioned it.

That's shadow AI: people using personal and outside tools to do company work, outside the governance, security and visibility of the org.

We see it in every transformation we run. When we map an organisation at task level, the work people actually do, the processes it flows through, the tools it touches, the same picture keeps surfacing. The official AI stack, bought top-down, sits half used. Meanwhile there's a second stack nobody procured: personal accounts, free tiers, browser tabs. And that's the one doing the work.

The research says the same thing at scale. Upwork found 55% of full-time employees admit to using AI without formal approval. MIT found 90% of workers use personal AI tools daily while only 40% of companies have official subscriptions. But you don't need a study. Ask your own people, with amnesty, and watch the hands go up.

What the shadow work actually is

Here's the pattern we find when we get to task level, and it changes how you should feel about all of this.

Shadow AI isn't concentrated in the risky, judgement-heavy work. It clusters on the menial, repeatable tasks: the status updates, the first drafts, the reformatting, the summarising, the meeting notes, the boilerplate. The exact tasks that score highest for automation in any honest analysis. The exact tasks a well-run AI rollout would target first.

In other words, your people have already found the right work to hand to AI. They did the task analysis themselves, informally, one desperate afternoon at a time. They're embracing AI, and mostly they're embracing it in the right places.

They're just doing it with no controls, no shared learning, and no way for the organisation to see it, fund it, or build on it. The instinct is right. The rollout is missing.

And that instinct is worth protecting. The people using AI in the shadows aren't a risk register entry. They're your early adopters, self-taught and already ahead of the rollout you haven't run. Squash the initiative and you lose the exact energy every transformation begs for. The move isn't to stop them. It's to own it.

What it costs you

Left in the dark, that instinct turns expensive, in four ways.

Your org chart is lying to you. Job descriptions, capacity plans, hiring decisions: all built on a picture of the work that stopped being true. More than half of employees hide their AI use and present the output as their own, per KPMG's global study, and Microsoft found the reason: 53% worry that using AI on important work makes them look replaceable. The JD says your analyst writes the report. A model drafts it, the analyst edits. You don't know how much of your output is human and how much is a model. Nobody in your organisation does.

The data walks out. Company context, customer records, source code, board thinking, pasted into personal accounts with no audit trail and terms that let it train someone else's model. Cyberhaven's telemetry shows the sensitive share of data flowing into AI tools has more than tripled in two years, to over a third of everything pasted. IBM prices the exposure: shadow AI adds an average of $670,000 to a breach, making it one of the costliest factors going.

The learning never lands. Every person quietly using AI is building real capability: prompts that work, workflows that save hours, judgement about where the model helps and where it lies. All of it lives in personal accounts. When they leave, it leaves. Ten people solve the same problem ten times and the org learns it nowhere. That's the compounding failure, and it's the cost nobody's writing about.

You fund the wrong stack. With AI spend under a microscope and MIT finding 95% of enterprise AI pilots deliver no measurable return, organisations keep buying tools by vendor pitch and executive instinct. Meanwhile the shadow stack, chosen bottom-up by people who know the work, gets used every day and appears in no budget line. You're paying for the stack nobody asked for and ignoring the one your teams already voted for.

How to engage with shadow AI

The instinct to ban is wrong. Samsung tried it and reversed course. Prohibition doesn't stop the usage, it just pushes it deeper into the dark, and the hiding numbers get worse. Shadow AI is not a discipline problem. It's a demand signal. Upwork found the same workforce using AI in the shadows also wants structure: 68% want more leadership support to experiment. The most honest tool-requirements document your organisation will ever produce, written task by task, by the people doing the work.

So engage with it, in order.

Start with amnesty, not audit. You need the truth more than you need compliance theatre. Make it safe to disclose. The goal of the first conversation is a real picture of who's using what, on which work, not a list of names for HR.

Understand the work, at task level. Roles are bundles of tasks. Map them, and score each task honestly: which work can be automated, which can be AI-assisted, which can be augmented, which stays human. Then lay the shadow usage over that map. Where they overlap, and they mostly will, your people have already validated the analysis for you. Where shadow AI is touching work it shouldn't, sensitive data, client-facing judgement, you now know exactly where the guardrails go.

Fund the stack the work needs. Tool and vendor decisions made from the map, not the pitch. Sanction the tools the shadow usage proves people want, on enterprise terms with real data protections. Cut what nobody touches. Every dollar traceable to the tasks it serves.

Bring the work into the light and keep score. Human, AI-assisted, automated: known per task, in the open, so the hidden half becomes a measured number. And put your shadow adopters to work in the open too: they're the ones who already know what works, so make them the people who keep feeding the company brain. Prompts, workflows and judgement that lived in personal accounts become shared assets, one baseline of how the organisation actually runs, in our world the Human Layer Graph, that gets sharper with every contribution. Then track what changes: adoption role by role, hours freed and where they went, capacity realised against capacity projected. Evidence a hawk-eyed CFO signs off on.

Turn the lights on

Your people already started your AI transformation. They started it on the right tasks, with the wrong controls, and they're running it every day without you. That's not a workforce problem. That's initiative, and it's the most valuable raw material you have.

The organisations that get this right won't be the ones with the strictest policies. They'll be the ones who could see: what the work is, who's doing it, what it needs, and what changed. Shadow AI isn't the disease. It's the symptom of an unmapped org, and it's telling you exactly where to start.

AI doesn't kill jobs. It frees time. Right now, half of it is happening in the dark. Turn the lights on.


Sources: Upwork Research Institute, Future Workforce Index 2026; MIT NANDA, The GenAI Divide 2025; Microsoft and LinkedIn, Work Trend Index; KPMG and University of Melbourne, Trust, Attitudes and Use of AI: A Global Study 2025; IBM and Ponemon Institute, Cost of a Data Breach Report 2025; Cyberhaven Labs, AI Adoption and Risk Report.

Related reading

Go deeper

We use cookies to improve your experience and analyze traffic.