Back to blog
Discover·Sep 7, 2026·5 min read

Shadow AI statistics 2026: the numbers every security leader should know

Shadow AI is any AI tool employees use for work without the knowledge or approval of IT or security — a personal ChatGPT account, an unvetted browser extension, or an AI feature quietly switched on inside a tool you already run. In 2026 it stopped being an edge case and became the default way most people use AI at work. Here are the numbers that matter, with their sources.

Key takeaways

  • Most workplace AI use is unsanctioned — bringing your own AI tool is now the majority behaviour, not the exception.
  • Shadow AI is now a factor in roughly 43% of data breaches (IBM, 2026), more than double the year before.
  • The problem is governance, not the tools: the organisations getting hurt are the ones with no visibility and no controls.

How widespread is shadow AI?

  • 78% of employees who use AI at work bring their own, unsanctioned tools — Microsoft Work Trend Index, 2025.
  • 75% of knowledge workers use AI at work, and 52% use tools their employer did not provide — Microsoft, 2024.
  • 55% of workers use AI tools their employer has not approved — Salesforce, 2024.
  • Around 80% of employee AI tools evade IT oversight — reported by SC Media, 2026.

What shadow AI costs

  • Shadow AI now factors into 43% of data breaches, more than doubling from 20% the year before — IBM Cost of a Data Breach 2026 (602 organisations across 17 countries).
  • The global average breach now costs around $5 million, a 12% increase year over year — IBM, 2026.
  • More than two-thirds of organisations lacked governance processes to limit shadow AI, and of those breached on their AI models, 92% had failed to control access — only 40% limit access at all — IBM, 2026.
  • Shadow AI incidents added as much as $670K to the average breach cost — IBM, 2025.

How sensitive data leaks out

  • 39.7% of data movements into AI tools involve sensitive data — the average employee feeds proprietary information into an AI tool roughly once every three days — Cyberhaven 2026 AI Adoption & Risk Report.
  • 1 in 3 employees access AI tools using personal accounts on corporate devices, bypassing any controls in place — Cyberhaven, 2024.

Where the risk concentrates

  • In financial services, 72% of employees use at least one unsanctioned AI tool — one of the most regulated sectors for unauthorised data processing — Salesforce, 2024.

What the numbers actually say

Read together, the picture is consistent: adoption is near-universal and mostly invisible, the cost lands hardest where there is no governance, and the failure point is not that people use AI — it is that security teams cannot see what is in use. The organisations that stay ahead make shadow AI visible before writing policy on top of it. That starts with discovering every AI tool in use and keeping a living AI inventory. Grasp's Discover surfaces the tools in use, including the hidden ones, so governance is built on the real picture rather than a survey — see it live.

Frequently asked questions

What percentage of employees use shadow AI?

Estimates range from 55% to 78% depending on the survey. Microsoft's 2025 Work Trend Index found 78% of workplace AI users bring their own unsanctioned tools; Salesforce (2024) found 55% use unapproved tools. Across studies, the consistent finding is that most workplace AI use is unsanctioned.

How much does shadow AI add to breach risk?

Per IBM's Cost of a Data Breach 2026, shadow AI now factors into 43% of breaches, more than double the 20% seen a year earlier. IBM's 2025 report put the shadow-AI premium at up to $670K per breach.

Is shadow AI a security risk?

Yes — mainly because of what it hides. Cyberhaven (2026) found 39.7% of data sent to AI tools is sensitive, and IBM (2026) found more than two-thirds of organisations lacked processes to limit shadow AI. The risk is the lack of visibility and control, not AI use itself.

How do you manage shadow AI?

Start by discovering every AI tool in use, build an inventory, then apply governance. You cannot govern what you cannot see.

Sources

IBM Cost of a Data Breach Report 2026 and 2025 · Microsoft Work Trend Index 2024-2025 · Cyberhaven AI Adoption & Risk Report 2024-2026 · Salesforce 2024 · SC Media 2026.