Samsung engineers pasted proprietary source code into ChatGPT to help optimize it. Amazon employees fed internal meeting notes and confidential data into the same tool. In both cases, the AI was doing exactly what it was asked to do. The problem was that nobody with security authority asked it to do anything. The employees just did it on their own.
This is shadow AI. And 68% of workers are doing some version of it right now.
The average enterprise has 14 distinct AI tools running across its workforce. IT knows about four or five of them. Companies with over 1,000 employees are managing upward of 250 unauthorized AI tools. Engineering teams lead the charge at 79% adoption. Gen Z workers are twice as likely to use unauthorized AI as their older colleagues. And 38% of employees admit to sharing sensitive work information with AI tools without their employer knowing.
The numbers are bad. The trend line is worse. 76% of organizations now cite shadow AI as a definite or probable problem, up from 61% last year. That’s a 15-point jump in 12 months.
The Damage Is Already Measured
IBM’s 2025 Cost of Data Breach Report found that one in five organizations experienced a breach linked to shadow AI. Those breaches added $670,000 to the average cost of a data incident and took 247 days to detect. 97% of the organizations that got hit lacked AI access controls.
HiddenLayer’s 2026 AI Threat Landscape Report made it worse: 35% of AI-related breaches were traced to malware hidden in public model and code repositories. The same repositories that 93% of organizations rely on for AI development. One in eight reported AI breaches is now linked to agentic systems, autonomous AI tools that can take actions on their own.
And here’s the stat that should keep every CISO awake: 31% of organizations don’t know whether they experienced an AI security breach in the last 12 months. They’re not saying it didn’t happen. They’re saying they have no way to tell.
The Missing Layer
The enterprise security market has tools for this. CASBs monitor cloud application usage. DLP systems flag data leaving the network. Identity platforms control who accesses what. These tools cost six and seven figures per year. They’re built for Fortune 500 security teams with headcount and budget.
The startup with 15 employees using Claude for customer support, ChatGPT for code review, and Notion AI for internal docs has none of this. The school district where teachers discovered AI grading tools on their own has none of this. The local government office where an intern connected an AI agent to the shared drive has none of this.
Shadow AI is not an enterprise problem. It is an everyone problem. But the tools to detect and manage it are priced and designed exclusively for enterprises.
The security layer that catches unauthorized AI usage, monitors what data flows into which models, and gives administrators visibility into what’s actually happening needs to exist at a price point and complexity level that a 10-person company, a school, or a city council office can deploy. Right now it doesn’t. And every month it doesn’t exist, the gap between “AI tools employees are using” and “AI tools the organization knows about” gets wider.
The comparison to shadow IT in the 2000s is obvious but incomplete. Shadow IT was someone installing Dropbox. Shadow AI is someone feeding your client database into a model hosted by a company you’ve never heard of, running on servers in a jurisdiction you haven’t considered, with a privacy policy that changes quarterly. The stakes scaled with the technology.
What This Means for Everyday People
If you work anywhere that hasn’t explicitly told you which AI tools are approved, you’re probably part of this statistic. That doesn’t make you reckless. It makes you someone whose employer hasn’t caught up yet. The gap isn’t between careful and careless employees. It’s between organizations that have an AI governance policy (37%, per IBM) and the 63% that don’t. Until the tools to manage this are as accessible as the AI tools causing the problem, the gap stays open.