Skip to content
Entagl

industry · product

Shadow AI: The Ungoverned Risk Hiding in Your Business

Staff are already pasting customer data into consumer AI tools. Here is what shadow AI is, why it costs so much, and how governed AI shrinks the risk.

Entagl Research9 min read
Shadow AI: The Ungoverned Risk Hiding in Your Business

Shadow AI is the unsanctioned use of AI tools by employees, without approval, oversight, or security controls, and it is now one of the fastest-growing sources of data risk in business. It is not hypothetical: 77% of employees paste data into generative AI prompts, and 82% of those pastes come from personal accounts outside company control, according to LayerX's Enterprise AI and SaaS Data Security Report 2025. The bill is already arriving. IBM's 2025 Cost of a Data Breach Report found that 1 in 5 breached organizations were compromised through shadow AI, and those breaches cost about $670,000 more than average. The fix is not a ban that everyone ignores. It is governed AI: giving people a sanctioned, controlled tool for the work they are already using AI to do.

What is shadow AI?

Shadow AI is the AI equivalent of shadow IT: software and services adopted by staff without the knowledge or approval of IT, security, or leadership. In practice it looks like a receptionist pasting a patient's message into a free chatbot to draft a reply, a sales rep uploading a customer list to summarize it, or a marketer feeding an unreleased campaign brief into a consumer image tool.

Most of it is well-intentioned. People reach for AI to move faster, not to leak data. But consumer AI tools were built for individuals, not for regulated customer data. When sensitive information leaves your systems for a personal account, you lose the three things that keep data safe: visibility into where it went, control over how it is stored, and an audit trail if something goes wrong.

The scale is what makes shadow AI different from ordinary shadow IT. LayerX found that 45% of enterprise employees already use generative AI, reaching that level of adoption in under three years, and that 67% of AI usage happens through unmanaged personal accounts. Traditional data-loss tools, built to watch files and email, do not even register a copy-paste into a browser tab.

How big is the shadow AI problem in 2026?

Big, and growing on two fronts at once: more people using AI, and more sensitive data flowing through it. Employees now feed AI sensitive data constantly: 39.7% of all AI interactions involve sensitive information, and the average worker inputs sensitive data into an AI tool once every three days, per Cyberhaven's 2026 AI Adoption and Risk Report. Meanwhile, attackers have industrialized AI too: IBM's 2026 Cost of a Data Breach Report found that 1 in 4 malicious breaches were AI-enabled, a 56% jump over the prior year, costing an average of $6 million, roughly $1 million above the $4.99 million global average.

Here is the evidence base in one place.

Finding Figure Source
Breached organizations compromised through shadow AI 1 in 5 (20%) IBM Cost of a Data Breach 2025
Extra cost of a shadow AI breach vs. average ~$670,000 IBM Cost of a Data Breach 2025
Employees who paste data into GenAI prompts 77% LayerX 2025
Those pastes coming from personal accounts 82% LayerX 2025
Files uploaded to GenAI tools containing PII or payment data 40% LayerX 2025
AI interactions that involve sensitive data 39.7% Cyberhaven 2026
Malicious breaches that were AI-enabled 1 in 4 (25%) IBM Cost of a Data Breach 2026

The through-line: AI use is outrunning AI oversight, and the gap is exactly where breaches happen.

Why does shadow AI cost so much?

Because the data that leaks tends to be the data that matters, and because almost nobody has controls around it. Among organizations that reported an AI-related breach, 97% lacked proper AI access controls, and 63% of breached organizations had no AI governance policy at all, according to IBM's own analysis of the 2025 report. Only 37% had any approval process or oversight mechanism in place.

Customer data is usually what is exposed. When a shadow AI tool is involved in a breach, the record that leaks is frequently personally identifiable information, the category that triggers regulatory notification, fines, and reputational damage. That is why the shadow AI premium is so steep: it is not just a leak, it is a leak of the exact data that regulators and customers care about most.

Policy alone does not close the gap. One study found that only 17% of organizations have technical controls that can actually prevent employees from uploading confidential data to public AI tools. The other 83% rely on training, warning emails, and hope. As anyone who has run security awareness training knows, hope is not a control.

Why banning AI does not work

The instinct is to block it. Ban ChatGPT, blacklist the domains, tell everyone to stop. It fails for a simple reason: the productivity gains are real, so people route around the ban. When the sanctioned path is "do not use AI," the unsanctioned path wins, and it moves further into the shadows where you have even less visibility.

This mirrors a lesson businesses already learned with software sprawl. We wrote about that pattern in AI tool sprawl and why consolidation wins: stitching together single-purpose tools fragments your data and your control. Shadow AI is the ungoverned end of the same problem. Banning tools does not consolidate anything. It just pushes the fragmentation off your books.

The workable strategy is the opposite of a ban. Give people a governed AI that does the high-risk work inside guardrails, so the sanctioned path is also the fast path. When the approved tool is genuinely better and safer for the job, shadow AI loses its reason to exist.

What does governed AI actually look like?

Governed AI is not one feature. It is a set of controls that keep sensitive data inside a system you can see, audit, and prove. Here is the practical contrast.

Dimension Shadow AI (consumer tools) Governed AI (sanctioned platform)
Data location Personal accounts, outside company control Encrypted, inside a controlled system
Access control None; anyone with the link Roles and permissions per user
Audit trail No record of what was shared Logged, exportable, reviewable
Compliance posture No BAA, no DPA, unclear retention Signed agreements, defined retention
Human oversight None Review, override, and handover built in
Visibility Invisible to security tooling Monitored and reportable

The pattern that reduces risk, per the research, is a combination: discover which AI tools people actually use, classify the data those tools touch, route approved use through a sanctioned system, and keep a human in the loop. That last piece matters more than it sounds. As we covered in human-in-the-loop AI, the controls that make AI safe to deploy are review, override, and handover, not blind automation. The same logic applies to compliance-grade AI generally, which we broke down in compliant AI for regulated businesses.

Governed AI for customer conversations

The single highest-risk shadow AI workflow for most businesses is customer communication, because it is where sensitive data and speed collide. A team member wants to answer a patient, a shopper, or a lead quickly, so they paste the message into whatever tool is open. That is precisely the moment governed AI should replace the consumer tab.

This is the problem Entagl's four agents, one brain is built to solve for conversations. Instead of staff pasting customer messages into a personal chatbot, the AI agent for Instagram, WhatsApp, and web chat handles the reply inside a governed system: sensitive conversations stay encrypted at rest with AES-256-GCM, access is scoped by team roles and permissions, every conversation carries output guardrails and human handover, and regulated workspaces run under signed BAAs with HIPAA-grade audit logging. For teams that need it, there is self-service GDPR data export and deletion, and the option to bring your own model key. In other words, the work that would otherwise happen in an ungoverned tab happens in a system you can audit and prove.

It does not make shadow AI disappear across every department, and it should not pretend to. What it does is remove the reason people reach for consumer AI in the one workflow where the customer data is most sensitive and the temptation to move fast is highest.

A shadow AI checklist for SMBs

You do not need an enterprise security team to start. Work through this in order.

  1. Assume it is already happening. With 77% of employees pasting data into AI, the question is not whether, but where. Ask your team what they use, without blame.
  2. Name the high-risk workflows. Customer messages, patient records, contracts, and payment data are the ones that turn a leak into a breach. Prioritize those.
  3. Give people a sanctioned alternative. A ban with no replacement fails. Route the risky work through a governed tool that is genuinely faster.
  4. Insist on the controls. Encryption at rest, access roles, audit logs, human review, and a signed data agreement (BAA or DPA) for regulated data. If a tool cannot show you these, it is not ready for customer data.
  5. Keep a human in the loop. Approval and override are what make AI safe to deploy in a business that cannot afford mistakes.

Shadow AI is not an AI problem. It is a governance gap, and the businesses closing it are the ones that give their teams a sanctioned, controlled AI for the work they are already doing. If customer conversations are your highest-risk workflow, book a 30-minute demo and see what governed AI looks like in practice.

FAQ

What is shadow AI in simple terms?

Shadow AI is when employees use AI tools that their company has not approved or secured, often by pasting company or customer data into consumer chatbots from personal accounts. It is well-intentioned but ungoverned, which means the business loses visibility, control, and any audit trail over where sensitive data went.

How common is shadow AI?

Very common. LayerX found that 45% of enterprise employees already use generative AI and that 77% of employees paste data into AI prompts, with 82% of those pastes coming from personal accounts. IBM found that 1 in 5 breached organizations were compromised through shadow AI in 2025.

Why is shadow AI a security and compliance risk?

Because the data involved is often sensitive. IBM's 2025 report found shadow AI breaches cost about $670,000 more than average, and 97% of organizations with an AI-related breach lacked proper access controls. When personal or payment data leaks into an ungoverned tool, it can trigger regulatory notification, fines, and reputational harm.

Should we just ban AI tools at work?

Banning rarely works, because the productivity gains push people to route around the ban, moving usage further into the shadows. A better approach is to provide a governed, sanctioned AI for the high-risk work, so the approved path is also the fast path. Pair that with basic controls: encryption, access roles, audit logs, and human oversight.

How does governed AI reduce shadow AI risk?

Governed AI keeps sensitive data inside a system you can see and audit. For customer conversations specifically, a governed agent handles replies with encryption at rest, role-based access, audit logging, human handover, and signed compliance agreements, removing the reason staff would otherwise paste customer messages into a personal chatbot.

Sources: IBM Cost of a Data Breach Report 2025 and its data-leader analysis; IBM Cost of a Data Breach Report 2026; LayerX Enterprise AI and SaaS Data Security Report 2025; Cyberhaven 2026 AI Adoption and Risk Report; Kiteworks analysis of IBM's 2025 findings. Figures reflect the most recent reports available as of August 2026.

Published by Entagl Research on