All Posts
No items found.
1
min read

Shadow AI in the Enterprise: Why Unapproved AI Tool Adoption Is Becoming a Systemic Data Governance Crisis

Published on
September 9, 2026
Table of Contents

As geopolitical tension across multiple regions continues to push threat actors toward opportunistic data collection, enterprise security teams are simultaneously losing visibility into one of the fastest-growing data exposure vectors they face: their own employees' use of unapproved artificial intelligence tools. Shadow AI has crossed from productivity nuisance into a structurally significant governance failure, and the evidence now makes the case clearly.

The Scale of the Problem: Shadow AI Is Already Everywhere

The average organization runs 10 AI applications per month, many operating outside formal approval processes. [1] That figure alone reframes the problem: this is not a fringe behavior by a few technical employees. It is a baseline condition for most enterprises.

Broader survey data reinforces the point. According to the Microsoft/LinkedIn 2024 Work Trend Index, 78% of employees bring their own AI tools to work rather than waiting for corporate-sanctioned alternatives. [2] Among Gen Z employees, that figure reaches 85%. [2] Unsanctioned AI tool usage tripled over 12 months, rising from 15% to 45% of the workforce, according to the Verizon 2026 Data Breach Investigations Report as cited in vendor research. [2] A 2025 survey of 302 cybersecurity leaders by Gartner found that 69% of organizations either suspect or have direct evidence that employees are using prohibited public generative AI tools. [2]

The critical qualifier: 98% of organizations have unverified applications in use, with unsanctioned AI tools representing the fastest-growing segment, and the average company has 1,200 unofficial apps operating entirely outside IT visibility. [2] Shadow AI does not exist at the margins of the enterprise. It is the default state.

What Employees Are Actually Doing With These Tools

The exposure behaviors documented across recent research are specific and consequential.

Nearly 50% of enterprise employees use generative AI at work, and of those interactions, 77% involve real company data. [3] Over 4% of AI prompts and 20% of file uploads contained sensitive corporate data in Q2 2025, with consumer AI assistants being the biggest source of these exposures. [3] More precisely, 22% of generative AI users pasted payment-card or personal identity data into AI tools. [3] Figure 1 maps the full range of these exposure behaviors, showing the proportion of enterprise AI users engaging in each category of data-exposure activity as documented across LayerX and Cyera research compiled by IntuitionLabs.

The concealment dimension compounds the governance failure. According to Teramind data, 68% of employees intentionally hide their AI tool usage from employers. [2] A KPMG Trust in AI study of more than 48,000 workers across 47 countries found that 57% hide AI use from employers globally, presenting AI-generated content as their own. [2] When employees actively conceal their tool usage, behavioral monitoring, policy communication, and after-the-fact investigation all become significantly harder.

Samsung's 2023 experience remains instructive as a documented incident. Engineers accidentally leaked internal source code by uploading it to a public AI assistant, prompting the company to ban generative AI tools on company-owned devices. [4] An internal Samsung survey found that 65% of respondents believed generative AI services pose a security risk, yet the behavior occurred anyway. [4] The gap between employee risk awareness and employee behavior is not closing.

The Threat Surface Shadow AI Creates

Shadow AI does not only create passive data exposure risk. It generates active threat surface that adversaries are already exploiting.

A 2026 AI security assessment documented a credential theft campaign called Bissa Scanner, which stole AI credentials from more than 30,000 exposed .env files, with AI platform accounts representing the most stolen credential type in the campaign. [1] The same assessment found that high-risk generative AI prompts doubled over the past year within enterprise environments. [1] These are not theoretical risks. AI account credentials are now a tradeable commodity in criminal markets, with stolen access resold to obscure attacker identity in what researchers have termed LLMjacking. [1]

The financial consequences of unsanctioned AI exposure are documented. Organizations with high levels of unsanctioned AI tools incurred breach costs averaging $4.63 million, compared to $3.96 million for organizations with low or no unsanctioned AI tool usage, representing a $670,000 premium per incident. [2] Unsanctioned AI tool breaches also compromise intellectual property at 40%, versus a global average of 33%, and customer personally identifiable information (PII) at 65% versus a global average of 53%. [2]

The supply chain dimension adds another layer. As CISA and the UK National Cyber Security Centre (NCSC) stated jointly in their guidelines for secure AI system development: "Where system compromise could lead to tangible or widespread physical or reputational damage, significant loss of business operations, leakage of sensitive or confidential information and/or legal implications, AI cyber security risks should be treated as critical." [5] For financial services firms, healthcare organizations, and critical infrastructure operators, that threshold is routinely met.

Why Governance Frameworks Are Failing to Keep Pace

The structural gap between regulatory expectations and enterprise reality is now well-defined, if not yet well-closed.

The New York Department of Financial Services (NYDFS) issued an industry letter in October 2025 reinforcing that managing third-party service providers "remains a crucial element of a Covered Entity's cybersecurity program" and explicitly recommended that contracts include provisions on acceptable use of AI products. [6] NYDFS has stated it will factor deficiencies in third-party risk management into examinations and enforcement actions. [6] The guidance is prescriptive enough to function as a de facto compliance benchmark for regulated financial entities.

Yet regulatory expectations and enterprise capability are not converging fast enough. Legacy data loss prevention (DLP) programs were designed for predictable channels: email, endpoint, defined cloud applications. Browser-based AI tools, AI features embedded in productivity suites, and third-party large language model (LLM) integrations represent data pathways those architectures were never built to cover. [7] As one vendor analysis frames it, traditional DLP breaks down in AI-driven environments because it fails on three dimensions simultaneously: channel coverage, unstructured data classification, and user intent modeling. [7]

The CISA/UK NCSC joint guidelines are unambiguous on what secure AI development requires: security must be treated as a core requirement throughout the entire AI system lifecycle, not merely during development. [5] That principle is foundational, but it addresses AI system builders more than it addresses enterprises grappling with employees using external consumer AI products. The governance vacuum in between is where most enterprises currently sit.

Only 17% of organizations have a comprehensive AI security and governance framework in place, while 23% have no governance plans at all. [8] When fewer than 1 in 5 organizations has a functioning framework, regulatory guidance operates largely without a recipient.

The Workforce Dimension: Skills Gaps Compound the Risk

Governance frameworks require people to implement and operate them. That resource does not currently exist at the required scale.

The 2026 SANS/GIAC Cybersecurity Workforce Research Survey, drawn from 947 global respondents, found that 74% of cybersecurity teams are changing team size and role structures due to AI. [8] The skills gap now dominates as the primary workforce concern at 60%, up from 52% in 2025, creating a 20-percentage-point differential over headcount shortages. [8] Expert and senior roles are the most difficult to fill, with 55% of senior hires requiring 6 months or longer to fill. [8] Only 38% of organizations provide comprehensive AI security training, despite 54% reporting that governance policies exist. [8]

The practical implication is direct: organizations are attempting to govern a fast-moving, employee-driven AI adoption phenomenon using teams that are structurally understaffed in the expertise required to do so. Writing a policy is not equivalent to enforcing it, and enforcement requires both tooling and trained personnel.

What Effective Governance Actually Requires

The evidence supports a specific set of responses, not a general call for "better governance."

First, DLP programs must be extended to cover AI-specific data pathways. The 82% of sensitive AI pastes that come from unmanaged personal accounts represent a channel that sits entirely outside most corporate DLP architectures. [3] AI-aware DLP capabilities that can monitor browser-based interactions, classify unstructured data in real time, and model user intent at the point of action are a technical prerequisite for any meaningful control. [7] Blocking alone is counterproductive; employees find workarounds and the behavior goes underground. [7] Contextual coaching at the point of action produces more durable behavior change.

Second, AI tool inventories must be treated as a live asset management problem. The NIST Artificial Intelligence Risk Management Framework's GOVERN function explicitly calls for AI inventory and supply chain accountability. [9] An AI registry that catalogs sanctioned models, data connectors, and owners converts governance into an operational process rather than a periodic audit exercise.

Third, NYDFS Part 500 compliance work should be extended to cover AI tool vendors as a class of third-party service providers, with contracts specifying:

  • acceptable AI use
  • data handling terms
  • breach notification obligations [6]

Vendor due diligence questionnaires that do not address AI data handling are structurally incomplete against the current risk profile.

Fourth, the workforce gap cannot be papered over with policy alone. Only 38% of organizations provide comprehensive AI security training despite the majority claiming governance policies exist. [8] Training that addresses the specific behaviors documented in Figure 1, including inadvertent PII exposure, prompt content risks, and the risks of unmanaged personal accounts, must reach employees before the governance gap widens further.

Shadow AI is not an emerging risk being tracked on a future-state roadmap. It is a present-tense data governance failure operating at scale, with documented financial consequences, active threat actor interest in the credentials it generates, and a workforce that currently lacks the tools or training to close it.

Figure 1: Percentage of enterprise GenAI users or employees engaging in each data-exposure behavior, as reported across LayerX and Cyera research compiled by IntuitionLabs (2023–2026) [9].

References

  1. Check Point Research, "AI Security Report 2026," Check Point Research, 2026. [Online]. Available: https://pages.checkpoint.com/ai-security-report-2026.html [Accessed 08 Sep. 2026].
  2. Adaptive Security, "Unsanctioned AI Tools: What They Are, the Hidden Risks They Create, and How to Govern Shadow AI Across the Enterprise," 2026-07-10. [Online]. Available: https://www.adaptivesecurity.com/blog/unsanctioned-ai-tools-what-they-are-the-hidden-risks-they-create-and-how-to-govern-shadow-ai-acr [Accessed 08 Sep. 2026].
  3. IntuitionLabs, "ChatGPT Data Security: Preventing Proprietary Data Leaks," IntuitionLabs, 2026. [Online]. Available: https://intuitionlabs.ai/articles/prevent-chatgpt-proprietary-data-leaks [Accessed 08 Sep. 2026].
  4. Bloomberg, "Samsung Bans ChatGPT and Other Generative AI Use by Staff After Leak," Bloomberg, 2023-05-02. [Online]. Available: https://www.bloomberg.com/news/articles/2023-05-02/samsung-bans-chatgpt-and-other-generative-ai-use-by-staff-after-leak [Accessed 2025].
  5. CISA / UK NCSC and 20+ international partner agencies, "Guidelines for Secure AI System Development," CISA / NCSC, 2023. [Online]. Available: https://www.cisa.gov/resources-tools/resources/guidelines-secure-ai-system-development [Accessed 2025].
  6. L. Taubin, C. Kuck, "NYDFS Issues Guidance on Managing Risks Related to Third-Party Service Providers," Alston & Bird, Of Interest Financial Services Blog, October 27, 2025. [Online]. Available: https://www.alstonconsumerfinance.com/nydfs-issues-guidance-on-managing-risks-related-to-third-party-service-providers/ [Accessed 2025].
  7. Forcepoint, "DLP for AI: Everything You Need to Know to Secure Your Data," Forcepoint, 2026. [Online]. Available: https://www.forcepoint.com/blog/insights/dlp-for-ai [Accessed 08 Sep. 2026].
  8. SANS | GIAC, "2026 Cybersecurity Workforce Research Report: The Evolving Cyber Workforce: AI, Compliance, and the Battle for Talent," SANS Institute / GIAC, 2026. [Online]. Available: https://www.sans.org/white-papers/2026-cybersecurity-workforce-research/ [Accessed 08 Sep. 2026].
  9. AI Governance Library (aigl.blog) — summarising NIST AI 100-1, "Artificial Intelligence Risk Management Framework (AI RMF 1.0)," National Institute of Standards and Technology, U.S. Department of Commerce, 2023. [Online]. Available: https://csrc.nist.gov/publications/detail/ai/100-1/final [Accessed 08 Sep. 2026].

How Anomali Can Help

Shadow AI adoption exposes credentials and sensitive data through unmonitored channels, requiring dark web monitoring, threat feeds, and unified data visibility to detect the fallout.

  • Anomali Credential Monitoring surfaces employee credentials from dark web dumps and infostealer logs, enabling forced password resets before the stolen credentials described in this article are weaponised for account takeover or ransomware.
  • Anomali's Unified Security Data Lake normalises telemetry across cloud, endpoint, network, and identity, providing the correlated visibility needed to detect the attack patterns described in this article without vendor lock-in.
  • Anomali's dark web and advanced threat intelligence provides coverage that commodity feeds do not reach, nation-state actor attribution including Iranian-nexus groups, pre-ransomware initial access broker detection with a 24–72 hour warning window, outside-in compromised host visibility, and dark web credential monitoring, all surfaced inside ThreatStream as enriched, actionable intelligence.

Does your current stack give you the visibility needed to detect shadow AI-driven data exposure?

Get in touch with Anomali to find out more.

FEATURED RESOURCES

September 9, 2026
No items found.

Shadow AI in the Enterprise: Why Unapproved AI Tool Adoption Is Becoming a Systemic Data Governance Crisis

Most employees already paste company data into AI tools they were never approved to use. See what shadow AI exposes and where DLP and policy fall short.
Read More
September 8, 2026
Anomali Cyber Watch

Privilege Escalation in CrowdStrike. TerminalFix, ClickFix Lure, Steganography, Reverse Tunnel. REVSTEALER Disable Windows Update and Defender.Langflow and Ruby on Rails Vulnerabilities. Microsoft Teams, Spring Ring Intrusion. Chrome Zero-Day.... and more

Researcher Releases FalconFlank Proof-of-Concept Demonstrating Privilege Escalation in CrowdStrike Falcon. TerminalFix Campaign Combines ClickFix Lure, Steganography, and Reverse Tunnel for Network Access. Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner. Critical Langflow and Ruby on Rails Vulnerabilities Under Active Exploitation. Fake Help Desk Calls on Microsoft Teams Fuel the Spring Ring Intrusion Campaign. Chrome Zero-Day Traced to Flawed Array-Sort Optimization in V8.
Read More
September 7, 2026
Agentic SOC

Pourquoi un SOC agentique commence par des données à haute fidélité

Pourquoi un SOC agentique commence par des données à haute fidélité. Les défis liés aux données. Les options pour les résoudre.
Read More
Explore All