Quick question: have you ever pasted work stuff into ChatGPT? Not sensitive stuff. Just an email that needed a better reply, or a spreadsheet formula you couldn’t figure out. If you nodded, you’re part of the 45%. That’s how many professionals used an AI tool at work last month without their company’s official blessing. It even has a name: shadow AI.
What is shadow AI, exactly?
Shadow AI is any AI tool you use at work that your employer hasn’t formally approved. The chatbot your teammate uses for summaries. That writing assistant that’s technically free. Even the AI meeting notetaker recording everything. If IT didn’t bless it, it’s shadow AI. The ZDNET report on shadow AI frames it as one of the biggest workplace AI issues right now.
Here’s the part that surprises people: it’s not rare, and it’s not going away. A global survey from WalkMe, covering 3,750 professionals, found that 45% used unsanctioned AI tools in the previous 30 days. Even more striking, 36% used confidential data alongside those tools. Not on purpose, usually. It just happens.
The deeper problem is confusion. The same research found that 34% of professionals didn’t even know which AI tools their employer had approved. Only 21% had been warned about their company’s AI policies. So a lot of shadow AI isn’t sneaky employees breaking rules. It’s people who never got told what the rules were.
Why so many people use shadow AI
The obvious villain theory is lazy employees looking for shortcuts. The reality is much more boring, and honestly, much more sympathetic.
CIOs who study this say most people aren’t using unsanctioned tools maliciously. They found a tool that does the job better than whatever the company provides. The company’s official AI might be clunky, or buried in a portal nobody can find, or just plain worse at the task. So people go where the work gets done.
Think about it from the employee’s side. You have a deadline. Your boss wants a summary by noon. The approved tool spins for ten minutes and gives you a wall of text. The free chatbot gives you exactly what you need in seconds. Which one are you using?
That’s the real engine of shadow AI. It’s not rebellion. It’s friction. When sanctioned tools are hard to use or don’t fit the workflow, people improvise.
The real risks (beyond getting in trouble)
This is where shadow AI gets serious, and it’s why companies care so much.
The biggest risk is data leaking out. You paste a customer list into a free AI tool, and that data now sits on someone else’s server. Maybe it’s training the model. It might get breached. Or it could sit in a country with weaker privacy laws. The company’s security team can’t protect what they don’t know exists.
There’s also a regulatory side that’s getting teeth. The EU AI Act, for example, introduces transparency rules under Article 50, and businesses that don’t comply can face fines up to 15 million euros or 3% of global annual turnover. Your one innocent ChatGPT session could, in theory, be part of a compliance failure that costs your employer millions.
And the personal risk? If your company has an AI policy and you break it, that’s a disciplinary issue. People have been talked to, written up, and in extreme cases let go over it. The stakes aren’t imaginary.
What smart companies do about it
Here’s the interesting twist: the companies handling this best aren’t the ones that banned everything.
Thomson Reuters, for example, took a track-don’t-block approach early on. Their COO told ZDNET that when people are curious about new AI tools, blocking them just pushes the behavior underground. People would move company data to personal devices instead. So they watched what employees were using, learned what was valuable, and then gave people the same tools in an approved, sandboxed environment where data stays protected.
Chase did something similar. Their CIO built an internal AI platform called LLM Suite, so employees can use AI features in a secure pipeline without going around the system. The idea is simple: if the good tools are available inside the walls, nobody needs to go outside them.
That’s the pattern that works, and it’s worth knowing even if you’re not the one making policy. The companies that win with AI give people sanctioned tools that are actually good. The ones that lose make the official tools painful and then wonder why everyone’s using something else.
How to use AI at work without crossing the line
You don’t need to be a policy expert to keep yourself safe. A few habits cover most situations.
First, know your company’s actual policy. It’s usually in the employee handbook or on the intranet. Five minutes of reading beats five months of guessing. If you genuinely don’t know what’s approved, ask your manager or IT. Not knowing the rules doesn’t protect you, and it’s the exact trap the WalkMe data shows people falling into.
Second, apply the confidential-data test before every prompt. Would you email this document to a random person outside the company? If not, don’t paste it into an AI tool either. Security firm Palo Alto Networks has a plain-language explainer of shadow AI that spells out why the data angle matters so much. When you need AI help with something sensitive, use the approved enterprise tool, since that’s the one with the data protection baked in.
Third, lean on the approved tools first. Give them a real chance before you dismiss them. A lot of enterprise AI suffers from bad first impressions more than bad performance. If the approved tool genuinely can’t do the job, that’s worth telling your manager, because companies often don’t know their own tools are falling short.
And finally, if you’re using an unapproved tool for work anyway, keep it mundane. No customer data, no financials, no internal strategy. Rewrite the prompt so it doesn’t contain anything identifying. It’s not a perfect solution, but it dramatically shrinks the downside while you figure out the official route.
The shadow AI you probably don’t think about
When most people hear “shadow AI,” they picture someone secretly running a hacky script. The reality is much more ordinary, and chances are you’ve seen these tools in action. Free ChatGPT accounts doing meeting summaries. Grammarly correcting emails in the background. An AI recorder capturing every call. A writing assistant that finishes your half-written report.
None of those feel like shadow AI. They all are. That’s exactly why it’s so hard to govern: the tools don’t look dangerous, and nobody stops to ask whether they’ve been approved.
The uncomfortable truth from the WalkMe data is that the tool itself matters less than the data flowing through it. A harmless-looking grammar checker that silently analyzes your confidential contract drafts is still sending that text somewhere. The question worth asking before you use any AI tool at work isn’t “is this approved?” but “where does this data go, and would my company be okay with it?”
The bottom line
Shadow AI isn’t going anywhere, and that’s not automatically a bad thing. Curious employees playing with new tools is how companies discover what actually helps them work.
The line you have to walk is simple in theory: be curious, but keep company data inside the tent. Use the approved tools when they work, ask for better ones when they don’t, and never let a convenient chatbot become a compliance catastrophe.
If you want to go deeper on the AI-at-work world, we’ve covered how to build safe and trustworthy AI agents with Zapier, why AI agents are everywhere but nobody uses them, and how to prepare for AI job interviews. The theme across all of them: AI at work is a skill now, and the people who learn the rules early are the ones who benefit most.