Shadow AI, the use of artificial intelligence tools by employees without approval from their organization, is becoming a growing challenge for companies. Recent studies show that nearly half of employees—45%—have used unauthorized AI tools in the past month, and almost a third of them have used confidential company data with these tools. According to the "State of Digital Adoption 2026" report by WalkMe, a technology firm, many professionals are unclear about which AI tools are approved by their employer, with 34% unaware of the approved list and only 21% having been informed about their company's AI policies.
Tal Carmi, Chief Information Officer at WalkMe, explained that Shadow AI often reflects a larger issue: employees may turn to unapproved tools if the official ones are hard to use, don't integrate well with their work, or don't help them perform their tasks effectively. Carmi emphasized that employees aren't necessarily trying to cause harm; they often find the unauthorized tools more efficient. However, this trend poses risks that require leaders to carefully balance encouraging innovation with maintaining control over emerging technologies.
Kirsty Roth, operations director at Thomson Reuters, acknowledged the importance of allowing employees some flexibility to explore AI. According to the "2026 Future of Professionals" report, a third of professionals in fields like law, accounting, and compliance use unauthorized AI tools, with the rate increasing to 41% among those who feel their firms are lagging in AI adoption. Roth's approach involves monitoring AI use closely while offering similar features through an approved, secure environment known as a "sandbox," which helps prevent sensitive company data from being exposed.
Carmi stressed the need for business leaders to understand which AI tools employees are using, what data they are sharing, and how they rely on AI in their daily tasks. He argued that knowing the reasons behind employees' choices is key to creating effective policies that are both responsible and practical.
Gill Haus, CIO at Chase, described how his organization has taken a proactive approach by integrating AI controls into LLM Suite, Chase's internal platform for accessing large language models. Launched in 2024, LLM Suite allows employees to test new AI features in a secure environment without violating company rules. Haus noted that all AI activity goes through a secure pipeline, effectively preventing Shadow AI. He recommended that other organizations adopt similar strategies to ensure AI is used responsibly and under control.
Managing Shadow AI in Enterprises: Balancing Innovation and Risk
AI-rewritten from original reportingHow it works
shadow-aiai-securityemployee-adoptiondata-protectionai-policiesworkspace-tools



