August 26, 2026
Shadow AI: The Thing I Can’t Stop Noticing About How People Actually Use AI
I use AI every single day. I love what it does for my work. So this piece isn’t me warning you away from it. It’s me being genuinely…

By Sonu Thakur
3 min read
I use AI every single day. I love what it does for my work. So this piece isn't me warning you away from it. It's me being genuinely curious about something I keep noticing: how much of our AI use is happening completely off the radar, and what that actually means.
Here's the thing I stumbled on. There's a name for it: shadow AI. It just means someone using an AI tool that their company never approved. A personal ChatGPT account instead of a company one. A browser extension with AI quietly built in. A coding assistant nobody in IT even knows exists. Nothing sneaky about it, most people doing this aren't trying to break any rules. They just found something that helped them get their work done faster, and used it.
But here's what made me pause. It's not a few people doing this occasionally. It's basically everyone, all the time, and most companies genuinely have no idea how much of it is happening.
So how much is actually happening?
I went looking for numbers, and honestly, they surprised me.
Most workers admit to pasting sensitive information, customer details, internal documents, even code, straight into AI tools. And most of that is happening through personal accounts, not anything the company set up or can see. Close to half of all AI usage at work happens this way. The average company is now logging over 200 AI-related data slip-ups a month, and when they finally go looking for the real number of AI tools employees are using, it usually turns out to be five to ten times higher than what IT thought.
That gap, between what companies think is happening and what's actually happening, is the part that got me. Not any one scary number, just how wide that blind spot is.
Why nobody's catching it
It's not that companies aren't trying. It's that the tools they have weren't built for this. The systems designed to stop data leaks were built for things like email attachments or USB drives, not for a chat window where someone's typing in a client's information to get help drafting an email.
And because a lot of this happens through a personal browser tab, it's basically invisible. On average, it takes companies over 200 days to even realize sensitive data went somewhere it shouldn't have. That's most of a year. And it's not because people are being careless on purpose, it's that hardly anyone has actually been told what's okay to type into these tools and what isn't.
Here's my actual take
Most people talk about this like it's purely a security problem. Lock it down, block the tools, watch people more closely.
I don't think that's the full picture. What I keep coming back to is this: people aren't using unapproved AI tools because they don't care about the rules. They're using them because the tool is faster and better than whatever their company officially gives them. That's not rebellion, that's just people trying to get their work done.
So if you only respond by blocking things, you catch some of it and push the rest further underground. People still need the speed. They'll just hide it better next time.
The more useful question isn't "how do we stop this." It's "what were people actually trying to get done, and can we give them a real, sanctioned way to do it just as fast." That's a product question as much as it's a security question, and I think that's exactly why so many companies are still stuck on this.
What I think actually helps
A few things seem to genuinely move the needle: actually checking sign-in logs for known AI tools instead of just guessing, giving people a fast way to get new AI tools approved instead of a months-long process, and real, specific training instead of a once-a-year policy email nobody reads.
Where I land on this
I don't think the answer is fewer people using AI. I think it's companies catching up to how their people are already working, instead of pretending it isn't happening.
Shadow AI isn't some future risk. It's already sitting in your browser tabs right now. The question is just whether your company finds out about it the hard way, or actually asks what you needed in the first place.