August 26, 2026
Shadow AI Detection
82% of sensitive pastes into AI tools come from personal accounts

By Marco Kotrotsos
7 min read
Three key takeaways:
- You cannot detect your way out of this. Microsoft's own shadow AI detection covers only managed Windows devices enrolled in Intune, while roughly 82% of sensitive pastes into AI tools come from personal accounts. The detection stack maps the managed minority of the surface.
- An amnesty with an enforcement date collects nothing honest. The standard vendor rollout runs 30/60/90, discover then amnesty then enforce, and publishing that enforcement date turns the amnesty into a confession booth with a sentencing date on the door.
- The root cause is intake, not policy. 63% of organizations have no formal AI governance policy, and among those that do, fewer than half have an approval process. There is nowhere to say yes, so people stop asking.
Two numbers, the same people, the same survey
The Purple Book Community's 2026 State of AI Risk Management report found that 90% of security leaders believe they have visibility into where AI is being used across their organization. In the same survey, 59% confirmed or suspected shadow AI they could not govern.
Those are not two separate groups. That is largely the same people holding both positions at once, which is what happens when your instruments cover part of the building and your reporting covers all of it.
Let me be straight about my standing here. I have not run an amnesty program. What I have done is walk into enough companies to see the distance between what the policy says and what is actually running, and to watch what that distance does to people. So this is the design I would run, and more usefully, the reasoning behind each rule. Most published versions of this get one specific thing wrong, and it happens to be the thing that decides whether anyone tells you the truth.
Detection is the wrong instrument
Start with what the tooling can actually see, because the answer is narrower than the category's marketing suggests.
Microsoft's shadow AI detection in Agent 365 applies to managed Windows devices enrolled in Intune. Personal laptops, phones, contractor machines, and anything not Windows sit outside the detection scope. That is not a criticism of Microsoft, it is stated plainly in their own documentation, and every endpoint-based approach has the same boundary. Network monitoring needs the traffic to cross your network. Endpoint agents need the endpoint to be enrolled. A personal hotspot routes around both.
Browser extensions are worse. An AI extension runs inside the browser session with access to page content, text inputs, clipboard contents, and often cookies and identity information. It requires no approval from anyone and is not covered by current shadow AI detection at all.
Now the number that settles it. Around 77% of employees paste data into generative AI prompts, and roughly 82% of those pastes come from personal accounts outside company oversight.
Put those together and the position is uncomfortable. The detection stack covers the managed surface well, and the managed surface is not where most of the risk is. You are buying a very good map of the wrong territory.
This is not an argument against buying the tooling. Buy it. It does real work on the part it reaches. It is an argument against detection being your only instrument, because a large share of the behaviour you care about happens somewhere it cannot reach by design, and no budget increase changes that.
What the ban bought Samsung
In May 2023, three Samsung semiconductor engineers put proprietary material into ChatGPT inside a single month. Source code, meeting transcripts, chip yield test sequences. Samsung banned generative AI for staff.
In 2026, Samsung reversed it. The DX Division now officially provides ChatGPT, Gemini, and Claude to employees.
I want to be fair to the ban, because it is easy to be smug about this in retrospect. Given what had just happened, a ban was a defensible panic response and I might have advised something similar in the room that week. The question is what it bought. Three years, during which the same people had the same underlying problem, the same tools remained one browser tab away on a device nobody controlled, and the company's view of its own exposure was a policy document rather than a measurement.
Apple, Goldman Sachs, JPMorgan Chase, Deutsche Bank, Bank of America, and Citigroup all ran versions of the same play. Several said at the time they would permit the tools once properly vetted, which is the same arc caught earlier in its run.
Yes, this is shadow IT again
The objection is correct, so concede it early and take the free lesson.
Cloud storage went Dropbox first, sanctioned drives second. Messaging went WhatsApp groups first, Slack and Teams second. Devices went ignored corporate laptop first, BYOD with mobile device management second. In every case the unofficial tool won enough ground that the only rational move left was to provide a sanctioned version of it.
What worked then transfers directly. Find out what problem the unapproved tool was solving, because most shadow IT is a real gap between what people need and what they were given. Shorten the approval path, because when approval takes weeks people stop asking. Control the blast radius rather than the tool, through single sign-on, multi-factor authentication, and device compliance, so that an unsanctioned tool reaches less even when someone starts using it before anyone approved it.
One thing genuinely differs. Dropbox held your file, but it did not read your document and retain your reasoning about it. The data surface is wider now and the paste leaves no trace on your side, which is why approval latency matters more today than it did in 2013.
The design, and the choice
The published playbooks converge on a 30/60/90 rollout: establish a baseline, announce the policy with an amnesty window, then move to active enforcement once people have had time to comply. That pattern is the current standard advice, and it is worth noting that most of it is written by companies selling detection tooling.
That sequencing is where it breaks. If enforcement is the announced destination, nobody discloses the part that matters. You collect the defensible half of people's usage and end up with a number that is both wrong and reassuring, which is worse than having no number, because now leadership believes something specific and false.
There is also a structural reason the vendor version can afford the sunset. In their design, the amnesty only has to work once, to bootstrap a detection deployment that takes over afterwards. If detection cannot reach personal devices, and it cannot, then the amnesty is not a bootstrap. It is your permanent visibility channel, and a channel has to keep working.
Four rules follow from that.
No sunset. The amnesty is a standing channel, not a phase. Nothing takes over from it later.
No retroactive consequences, stated in exactly those words. Vague good-faith language reads as a trap to anyone who has been through a restructure, and correctly so. The promise has to name what will not happen.
Disclosure is decoupled from approval. Telling us you use something is not a request to keep using it, and it does not open a review of you. If those are the same form, the form is an application, and people do not apply for permission they expect to be refused.
Name the specific risk instead of prohibiting broadly. People comply with a reason that applies to their work. They route around a general one, and they feel justified doing it.
The wording of the promise is where the whole program lives. It should be short enough to quote back at you, and specific enough that breaking it would be obvious to everyone who read it.
What kills it
These are the failure modes worth designing against, because each one ends the program permanently rather than temporarily.
A manager references a disclosure in a performance conversation. That is the fatal one. It travels through an organization in about a week and it poisons every future request for honesty, not only the ones about AI.
Security quietly blocks a disclosed tool right after the window closes. You have now taught everybody that disclosure is targeting, and you have confirmed the suspicion they had when they hesitated.
Disclosures go into a system the discloser cannot see. Anything opaque gets read as a file being built.
Nothing visibly changes. People disclosed, the list went somewhere, and no sanctioned option appeared. The next time you ask for anything, you get silence and you will not know why.
The half nobody builds
The amnesty produces a list. The list is worth nothing unless the sanctioned path is genuinely faster than the shadow path, and this is the part that tends to get dropped when budget gets tight.
63% of organizations have no formal AI governance policy. Among those that do, fewer than half have an actual approval process for AI deployments. Most companies in this situation do not have a policy problem. They have an intake problem. A policy without an approval path is a sign on a door with no handle.
What that means concretely: a short intake form, a published decision turnaround measured in days rather than quarters, a default-yes tier for low-risk categories so most requests never need a committee, and one named person with authority to approve. Then work the disclosure list from the top by volume, because the tool forty people are already using is both the highest exposure and the cheapest thing to sanction.
Reading the number you get back
Set expectations before you run it, because the result will embarrass somebody.
Around 38% of employees admit to sharing sensitive work information with AI tools without permission, while the paste data suggests considerably more actually do it. That gap is exactly what the amnesty is built to close, so the disclosure count should come in well above what leadership currently believes.
If it comes back low, you did not achieve compliance. You got a quieter version of the same problem. The tell is a number that lands close to what the security team already estimated. Candid answers rarely agree with the guess that preceded them.
Get agreement in advance that a high number is a successful measurement rather than a failure of the security function. Without that agreement, the person who has to present the result has an incentive to suppress it, and you have rebuilt the original problem one level up.
The trade
IBM's breach cost research puts shadow AI in roughly one in five breaches, at about $670,000 more per incident than the average. Customer personal data shows up in a higher share of those breaches than in breaches generally. Meanwhile roughly 40% of companies hold official large language model subscriptions while about 90% of workers use personal AI tools daily for work tasks.
That gap is not going to close through policy, because the policy is what created the hiding. It closes when the sanctioned path is faster than the alternative and when telling the truth costs nothing.
An amnesty is just the mechanism for making that trade explicit. It works exactly as well as your willingness to keep the promise on the day keeping it becomes inconvenient, which is usually about six weeks in, when the first genuinely awkward disclosure lands on someone's desk.
Marco Kotrotsos, specializing in practical AI implementation for organizations ready to close the gap between AI hype and AI value. With 30 years of IT experience now focused purely on AI deployment, he works hands-on with companies to turn AI potential into measurable business outcomes.
This article is published in Autocomplete, a Medium publication about real-world AI for practitioners and decision-makers. We're always looking for writers. If you're building with AI and have something worth sharing, reach out.
My free Substack newsletter, also called Autocomplete, can be found here: https://acdigest.substack.com.
My books on Amazon: Claude Code for Everyone Else and From Vibe to Production.
I also take on a small number of mentees one-on-one on MentorCruise.