Skip to main content
Kirk
Community Manager
July 16, 2026

Shadow AI: Is it Already on Your Network? 👀

  • July 16, 2026
  • 2 replies
  • 139 views

Hi everyone,

 

Something came across my radar this week that I thought was worth bringing here, because honestly it's the kind of thing that'll either make you nod along or give you a mild headache. Possibly both.

 

A new survey from BlackFog of over 2,000 workers at large companies found that nearly half of employees are using AI tools their employer hasn't approved. And it's not just people on the shop floor doing it either. 69% of C-suite leaders and presidents said they're fine with it, basically prioritising speed over security concerns.

 

That in itself is a lot. But the bit that really stood out to me was what people are actually putting into these tools. A third admitted to sharing internal research or datasets. 27%* have entered employee data like salaries or performance info. 23%* have fed in company financial information. Often into free tools, where that data is highly likely being used to train the model.

 

A separate Lenovo study published recently, surveying 6,000 enterprise employees globally, found that between a fifth and a third of workers are using AI completely outside the visibility of their IT teams. And 61%** of IT leaders said AI is increasing their cybersecurity risk, but only 31%** feel confident they can actually address it.

 

For this community specifically, I'd imagine this lands a bit differently than it does for the average person reading a news article. You're the ones who'd have to deal with the fallout.

 

So I'm curious where you stand on it:

  1. Is shadow AI something you're already seeing in your organisations, and if so how are you handling it?
  2. Is the answer better policy, better tooling, approved alternatives, or some combination of all three?

 

And genuinely, is this a problem that can actually be solved, or is it something we as tech professionals must simply acknowledge and adapt to?

 

Would love to hear how people are approaching it, especially those of you working in security or compliance heavy environments.

 

🔗* Shadow AI risks deepen as 31% of users get no employer training — Help Net Security

🔗** Roughly half of employees are using unsanctioned AI tools, and enterprise leaders are major culprits — CIO

 

Cheers,
Kirk

 

    2 replies

    Alex_Muc
    Level 3.0: Honeycomb
    July 20, 2026

    I don't have any statistics from our organization. But I'd guess that people are using tools that haven't been approved. I mean, it already starts with a simple Google search. If tools are easy to use and free, the barrier for employees is very low. This comes at the expense of data protection, because you never know whether the data will be used for training. When in doubt, you have to assume that it will.

    For connections to AI tools using our proxy, users are notified of approved tools before the connection is established. The frontend we use is a house development (MUCGPT) that allows us to integrate different LLMs. However, the LLMs run in the cloud, and therefore even sensitive data shall not be used. 

     

    I think this is a good solution. You offer a tool and keep reminding people about it. Other tools aren't strictly blocked. Otherwise, if people really want to use other tools, they'll just continue using them on unmanaged hardware. That doesn't prevent people from using it. You just lose visibility.

    Michel
    Level: 4.1: Jelly bean
    July 20, 2026

    Its a big issue everywhere i think but I believe people don't really see the dangers of shadow AI yet. Shadow IT is a problem everywhere, AI is just part of that bigger problem. 

    IT always needs to balance between secure and workable. You can't block it all because people will find a way around it. Block ChatGPT? I'll use Gemini for example. Same for blocking functions on a work phone and people will use their private phone to install Whatsapp. 

     

    But its getting better, more and more IT departments are embracing AI and making it available within the company, giving people a safe way to use AI hoping that they are not moving to alternatives. The biggest issue is still that the quality is often a lot better than what the internal AI tools offer.Â