Most staff are already using AI tools at work, policy or not. Research from Gartner puts the number at 69% of organisations that suspect or have evidence that employees are using prohibited public generative AI, and predicts more than 40% of enterprises will face a security or compliance incident linked to unauthorised shadow AI by 2030. In short, the meaning of shadow AI refers to AI use your IT and security team can’t see.
While it’s tempting to treat this as a discipline problem, it isn’t. Shadow AI exists in every organisation. It’s not new, and it started before the AI days. Even a business with a clear AI policy and a properly sanctioned tool isn’t exempt. Inde is one of them.
What Is Shadow AI?
Shadow AI refers to the unsanctioned, untracked use of AI tools by employees, without IT or security knowing. While ChatGPT is the most widely discussed, Claude, Gemini, and dozens of AI features built into everyday business software also count.
It isn’t a new problem wearing a new name. Before, it was called shadow IT, where business teams found their own tools when IT couldn’t support what they needed. The difference now is in the accessibility. Shadow IT needed someone with the skills to maintain an unsanctioned tool. Shadow AI needs nothing more than a personal subscription and a login.
The risk sits in what gets typed into a prompt, not just what software gets installed. It’s how the well-known 2023 Samsung leak happened: an engineer summarised internal product meeting notes using a public AI tool, and confidential product details ended up outside the company. It’s the moment that put shadow AI on the industry’s radar, and a mistake that’s easy to repeat without meaning any harm.
Why Shadow AI Happens, Even With a Policy in Place
Our own numbers at Inde make the case better than any survey. We’re open about AI tools; we have Copilot and others, and I'd say almost 70 to 80% of our organisation uses these tools day to day. It’s the reverse when you ban them: maybe 20 to 25%, usually within IT, have the liberty to use those tools. The other 75 to 80% becomes shadow AI.
Restriction doesn’t reduce AI use. It just pushes most of it out of sight. Banning doesn’t solve it; it just hides it.
Our sanctioned tool at Inde is Microsoft Copilot, including Inde Chat, an internal tool we built on Copilot that staff use for everyday work like drafting client proposals. But even with Copilot adopted, our own technical team recently flagged real limits for development work: restrictions on writing configuration into files that Claude's enterprise offering doesn't share. Rather than letting people quietly switch on their own, we formed a cross-divisional working group across security, network, data, and AI to compare the two properly and take a recommendation to leadership.
I wouldn't say we don't have shadow AI within Inde. There are small pockets of it. The difference is what happens next: a structured evaluation instead of a quiet workaround.
The Real Shadow AI Risks
Not all shadow AI risks are created equal. They scale from quiet to severe, and I see the same handful repeat across nearly every client engagement.
Data Exposure
Most of what leaks isn’t financial; it’s technical and incidental. Especially in development teams, people paste an error message into ChatGPT or Claude to fix it. While they copy and paste, relevant corporate information (employee or customer details) often gets included and starts spreading onto the public internet.
Financial information carries the same risk in a different shape: an accountant comparing annual reports across years by pasting them into a public tool exposes those reports before the board has even seen them.
No Audit Trail
Once information goes into a personal subscription, it’s gone. There’s no log inside the business, no way to prove what was shared and when, and nothing to work backwards from if something goes wrong.
No Accountability
Without a policy or a record, nobody owns the decision to share something. When people ask me whether the fault sits with the organisation or the employee, I'd say it’s both.
Organisations shouldn’t ban tools; they should identify the right ones and give people the opportunity to use them. Equally, employees need to be made aware, through an AI policy and regular refreshers, of what they can and can’t use.
Malware from Fake Tools
The worst outcome isn’t a data leak at all. Because AI adoption is increasing, that gives hackers the opportunity to build fake tools to replace the real ones. A link promising a free 10-day trial of Claude or ChatGPT is a real, current way ransomware ends up on a company device.
What This Means for Your Organisation
The shadow AI risks that matter to IT and technical leaders often look different from the ones that matter to the board. For IT and technical leaders, the governance gap is often bigger than it looks. It's not just ChatGPT, Claude, or Gemini. Business applications like Salesforce or ServiceNow come with built-in AI features. They're usually switched off, but at some point the organisation wants to turn them on, and that's still something to govern. Shadow AI isn't one rogue app to block. It's every AI feature quietly waiting inside the tools you already use.
For executive leaders, the exposure is about cost and accountability more than technology. Unpublished accounts, pasted into a public tool for a quick comparison, are outside the business before the board has seen them. A client's details, copied in alongside a bug report, sit in someone else's logs with no way to prove what left the building. Neither shows up as a line item until something goes wrong, and by then there's no audit trail to work backwards from.
How to Bring Shadow AI Under Control
Shadow AI cannot be eliminated by banning tools. Nobody can stop the five or ten most curious people in any business from finding a new tool before anyone else has heard of it. What works is giving everyone else a faster, sanctioned way to do the same thing.
That starts with understanding the meaning of shadow AI and gaining visibility into its use, not restricting it. Inde recently worked with an international logistics client using AI in silos across its branches, with no visibility into what tools were in use or why. Instead of shutting it down, Inde helped build a governance framework and brought the early adopters on board as champions, people who could show the rest of the business how to use AI properly rather than around the rules.
The fix is two-pronged: tool governance and data governance together. Sanctioning the right tools solves half the problem. The other half is the data feeding them. If you give an AI model junk data, the output you get back is junk too. That's where you see hallucinations, not because the AI has gone rogue, but because it was never taught with the right data.
The fast path matters as much as the guardrails. When our own team found a real gap between Copilot and Claude Enterprise, nobody had to work around policy to solve it. They already had a process to raise it, evaluate it, and change the policy if the case stacked up.
What You Can Do About Shadow AI
If any of this sounds familiar, the starting point isn’t a ban; it’s a conversation. We start with an audit, a discovery, and a risk assessment to understand how much shadow AI is actually happening. From there, we help write the AI policy and governance framework, recommend the right tools for the work at hand, whether that's Copilot, Claude Enterprise, or otherwise, and support the change management and training that makes it stick.
It isn't a lengthy commitment. It's a short engagement, one to two months, and then we make sure they're self-equipped to do it on their own, with ongoing support whenever a new tool needs assessing. While businesses with the right skills in-house can do this themselves, most don't have the spare capacity to build it from scratch while running the business at the same time.
Shadow AI isn't a sign your staff can't be trusted. It's a sign your sanctioned tools haven't caught up with the work yet. Book a security assessment or AI governance consult with Inde, and see what’s actually happening in your business before it becomes a problem.