Your employees are using AI at work. Some of it you approved. Most of it you did not.
That is shadow AI, and in 2026 it stopped being a policy footnote and became a line item. This page covers what the measured data says, why the obvious response makes things worse, and what actually closes the gap.
What is shadow AI?
Shadow AI is the use of AI tools inside a business without approval or oversight from IT or security.
It is the AI version of shadow IT, with one difference that matters. When someone signed up for Dropbox without telling IT, the risk was where a file sat. When someone pastes a client contract into a free chatbot, the risk is what happens to the contents, one prompt at a time, with no record that it happened.
It is also harder to find. AI now sits inside tools you already sanctioned, as a feature rather than an app, so an inventory of installed software will not surface it.
How common is shadow AI?
Common enough that it is closer to the default than the exception.
One survey of employees and security leaders found 81% of employees and 88% of security leaders using unapproved AI tools. Cisco's readiness research found 60% of business leaders were not confident they could even identify unapproved AI tools in their own environment.
The seniority pattern is the uncomfortable part. Unapproved use is not concentrated among junior staff working around policy. Executives show some of the highest rates of regular use, and in earlier Cisco research nearly half of privacy and security professionals admitted entering non-public company information into generative AI tools themselves.
What does shadow AI actually cost?
The clearest figure comes from IBM's 2026 Cost of a Data Breach Report, produced by the Ponemon Institute across 602 breached organisations in 16 countries.
Shadow AI featured in 43% of AI-related security incidents, up from 20% the year before, at an average cost of 5.39 million USD per breach. Roughly one in five of those breaches also drew a regulatory fine.
The governance numbers in the same report explain why. 68% of breached organisations had no policy governing AI use or managing shadow AI. 92% of those that suffered an AI-related breach lacked adequate AI access controls. The share of organisations requiring IT approval before an AI tool is deployed fell from 45% to 38%, and only 19% said their AI governance and security teams coordinate with each other.
Read those together. Usage more than doubled while approval requirements shrank. Nobody decided unapproved AI was acceptable. The approval process simply stopped being load-bearing, because it was built for software you purchase and deploy, not software an employee opens in a browser tab.
20% to 43% in a single year.
Over the same period, the share of organisations requiring IT approval before deploying an AI tool fell from 45% to 38%.
Why does banning AI tools fail?
Because it removes visibility rather than usage.
Research into blocked applications found 45% of workers simply find a workaround. Usage moves to personal devices, personal accounts and personal phones, where nothing is logged and nothing can be reviewed.
There is a second cost. Employees are not being reckless. They are solving a real problem: a task that took two hours takes ten minutes. When the sanctioned option does not exist or is visibly worse than the free one, policy loses to the deadline. Ban the tool and you keep the risk, lose the record, and lose the productivity as well.
For regulated firms this is the worst of the three outcomes. You cannot tell a regulator what data left the business if you had no way of seeing it go.
Why is shadow AI a bigger problem for regulated businesses?
Because the exposure is continuous rather than a single event, and because the evidence you need afterwards does not exist.
Three specific problems:
What actually reduces shadow AI?
Giving people a sanctioned tool that is genuinely better than the one they are using without permission.
That is the whole mechanism. Shadow AI is a demand signal. Employees have already told you which capability they want and how much they value it, by going around you to get it. The question is only whether that demand gets served inside your controls or outside them.
In practice that means four things:
How does Moterra close the gap?
Private Claude Cowork by Moterra makes the tool your team already uses into the one your security team approves.
ISO 27001 and ISO 42001 certified across both the AWS and Anthropic layers, so the deployment stack is certified end to end. AWS and Anthropic hold SOC 2 Type II reports, and Moterra's setup has been independently validated by cyber security specialists. Your deployment is defensible under UK GDPR, EU GDPR, EU DORA and UK operational resilience requirements.
Moterra is an official Anthropic partner and an AWS Partner with GenAI Competency.
Frequently asked questions
What is shadow AI?
Shadow AI is the use of AI tools inside a business without approval or oversight from IT or security. It includes free consumer chatbots, browser extensions, AI features inside sanctioned SaaS tools, and personal accounts used for work tasks.
How common is shadow AI in businesses?
Surveys consistently put employee use of unapproved AI tools above two thirds, with some finding more than 80%. Most organisations cannot measure it directly, which is part of the problem.
What does shadow AI cost?
IBM's 2026 Cost of a Data Breach Report found shadow AI featured in 43% of AI-related security incidents, up from 20% the previous year, with an average breach cost of 5.39 million USD and a regulatory fine in roughly one in five cases.
Can you stop shadow AI by blocking AI tools?
Not effectively. Research on blocked applications found around 45% of workers find a workaround. Blocking usually moves usage onto personal devices and accounts, which removes visibility without removing risk.
How do you reduce shadow AI?
By providing a sanctioned tool with the same capability people are seeking, inside your own environment, with permissions inherited from your existing identity provider. Policy works when the approved path is also the easier path.
Is a private AI deployment enough on its own?
It resolves data residency, logging and access control, which are the parts a regulator asks about. Governance of what the tool is allowed to read and which actions require approval is configured on top of that.
Moterra
Official Anthropic partner. Deploys Claude inside regulated companies' own AWS and Azure tenants.