SecurityTechInsider AI security & governance
EN/ NL
Governance

Exposing shadow AI before you can control it: what 2026 figures demand of your organisation

Shadow AI is a measurable governance gap in 2026: IBM and Netskope show the scale. Here is how to map and control unauthorised AI use in your organisation.

9 September 2026 4 min
Illustration for this article: Exposing shadow AI before you can control it. Rows of dark unbranded rack equipment receding down a narrow aisle, lit only by their own indicator glow.
Organisations must establish formal processes to detect, approve and monitor AI tool use before shadow AI becomes a breach vector. Image: SecurityTechInsider — original editorial illustration

You must now map which AI tools your workforce actually uses, connect those tools to the data they touch, and establish a formal process to approve, track and revoke access. Without detection, shadow AI remains an invisible layer of governance failure.

An analysis of 9 September 2026 of shadow AI as a measurable governance gap argues that many organisations lack any formal process to approve, track or revoke employees' unauthorised AI tools. The analysis bundles incident data from major security vendors to show that shadow AI involvement in security incidents is now quantifiable. In our assessment, the scale of uncontrolled AI use means that visibility is no longer optional: you cannot manage what you cannot see, and the figures now show that most organisations cannot see their own AI activity.

How widespread is shadow AI in your sector?

The figures are consistent across vendors and geographies. Shadow AI is involved in approximately 43 per cent of the security incidents examined in recent analysis, whilst 44 per cent of workplace AI users deploy personal, unmanaged AI applications. This means almost half of all AI activity falls partly or entirely outside organisational control. Broader research suggests that 60 to 70 per cent of organisations have some shadow AI exposure, and that exposure can increase the impact of data breaches by around 15 per cent because investigation becomes harder.

A common misreading is that low visible AI use means low actual use. Research across mid-market companies shows that four in ten suspect employees use generative AI via personal accounts, yet only eight per cent regard this as widespread. The gap between perception and measurement reveals a visibility problem, not a use problem. Shadow AI occurs as readily in mid-sized European firms as in large enterprises.

What forms does unauthorised AI take?

  • Personal generative AI accounts — employees using ChatGPT, Claude or similar services with work email or work data.
  • Unvetted browser extensions and plugins — AI tools integrated into email, document and messaging platforms without procurement approval.
  • Unauthorised AI agents and service accounts — automated workflows using AI models to process data without formal identity and access controls.
  • Shadow integrations — connections between business applications and external AI services set up by individual teams rather than through central infrastructure.

Which concrete controls do you need to demonstrate?

  1. Detect and inventory AI tools touching your data — scan network traffic, email, document platforms and messaging systems to identify which AI services process your data and which employees use them.
  2. Link tools to data flows and identities — record which datasets each tool accesses, which employees or teams use it, and what business purpose it serves.
  3. Establish a formal approval process — require security review and governance sign-off before any new AI tool can process business data, with clear criteria for approval or rejection.
  4. Document the lawful basis for each workflow — record which model each approved workflow uses, what data it touches, and the legal basis for that data processing under your applicable regulations.
  5. Implement revocation and monitoring — maintain the ability to disable access to any tool and to audit ongoing use, with alerts when unapproved tools reappear.

What should you do first?

Begin with detection rather than prohibition. A ban without visibility simply drives shadow AI deeper. Map your current state: which AI tools are already in use, which data they touch, and which workflows could be formalised rather than blocked. Turn the patterns you find into controlled, approved workflows or restrict them. This requires coordination between security, data governance and the teams that actually use AI in their work.

The Cloud Security Alliance defines shadow AI as generative AI tools, models, services and agents that process business data without security review, procurement approval or governance. That definition is broad enough to cover everything from a contractor using a free chatbot to a department integrating an AI service into a business process. Your task is to make each instance visible and then decide whether to approve it, restrict it or block it.

What tooling can and cannot do

Detection platforms can show you which AI services your network carries and which employees use them. Workflow platforms can enforce approval gates and record which model and which verification steps went into each decision. Privacy layers can anonymise sensitive data before it reaches external AI services. None of these tools solves shadow AI on their own, and none of them removes your professional obligation to judge whether a particular AI use is lawful, appropriate and aligned with your organisation's risk appetite. The tooling creates visibility and enforces process; the governance decision remains yours.

Sources: This article draws on reporting and guidance from Seimless, TechnologyRadius, Netwrix, Cloud Security Alliance Labs and MyBusinessFuture.

Marit Halversen

Written by

Marit Halversen

Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.