Employees may already be using AI tools your organization hasn’t approved or may not know about. The Verizon 2026 Data Breach Investigations Report put a number on how widespread it is.
This is what shadow AI looks like at scale, and many organizations have little visibility into how much of it is happening internally.
Why It’s Happening
These tools are accessible in a way that most enterprise software isn’t. There’s no installation, no IT ticket, no budget approval. An employee who wants to summarize a long document or draft a client email can open a browser tab and be done in thirty seconds. When something makes your job easier and nothing says otherwise, you use it. Most employees have never thought of this as a decision that required anyone else’s input.
What Shadow AI Actually Looks Like in Practice
Shadow AI isn’t limited to standalone AI assistants. It shows up in several forms that are easy to miss:
Personal accounts used for work. An employee has a personal ChatGPT, Claude, or Google Gemini account they’ve been using since before the company had any formal AI tools. They use it at work the same way they use it at home. The account isn’t provisioned by IT, isn’t subject to organizational data handling terms, and doesn’t appear in any app audit.
Browser extensions. AI writing assistants, summarizers, and grammar tools integrated directly into Chrome or Edge are among the least visible forms of shadow AI. They don’t show up in software inventories. Verizon found that the average company had more than 15% of users with unauthorized AI extensions installed, and noted that some of these tools collect and retain browsing information for context. Many employees don’t think of them as “AI tools” at all. They think of them as productivity features.
AI inside tools that were already approved. Microsoft Word, Outlook, Edge, and a growing number of SaaS platforms now include AI features that may or may not be part of what IT originally approved. The tool is sanctioned. The AI layer built into it may not have been specifically reviewed, configured, or restricted.
Shared team accounts. Someone set up a paid personal AI subscription with a company card, shared the login with their team, and now five people are using the same unmanaged account for work involving client data. No one set it up with bad intentions. No one thought much about it at all.
What Many Organizations Still Can’t See
Most organizations don’t have a clear picture of which AI tools are in use, who’s using them, or what type of account is involved. A managed Microsoft 365 Copilot deployment has organizational controls, audit logging, and defined data handling. A personal AI account used for the same work sits outside those organization-managed controls. From the outside, both look like “using AI.” The difference in what happens to the data is significant.
Questions most organizations can’t answer right now
- Which AI tools are actively in use across the organization (including browser extensions)?
- Are employees using personal accounts, shared logins, or managed enterprise accounts?
- What categories of data are being entered as AI prompt context?
- Who is responsible for keeping AI use policy current and fielding employee questions?
When a Prompt Becomes a Data Decision
Most employees don’t think of writing a prompt as a data transfer.
How it plays out
An employee at a professional services firm needs to summarize a lengthy client contract before a deadline. They paste the document into a personal AI account, get a clean summary in under a minute, and move on. The task was routine. The document contained client names, deal terms, and confidential business information. The employee didn’t think twice, and had no reason to, because no one had told them otherwise.
If that organization later faces a dispute and counsel asks what systems touched client data, “the employee used a personal AI account” is a very uncomfortable answer. It may mean the organization has no reliable audit trail, no enterprise data processing agreement covering that use, and limited visibility into how the data was handled.
IBM’s 2026 Cost of a Data Breach Report found that 43% of breached organizations studied had incidents involving shadow AI, up from 20% the prior year. Breaches involving shadow AI averaged $5.39 million. The financial exposure isn’t hypothetical, and it’s growing.
Consumer AI products and managed enterprise AI products operate under meaningfully different terms. Consumer services may retain conversation history by default. Some use activity data to improve their models unless users opt out, a setting employees may never review. When employees use personal or unmanaged accounts for work, the organization may have no record of what was entered, which tools were used, or how the data was handled.
Managed enterprise AI products such as Microsoft 365 Copilot, ChatGPT Business and Enterprise, Claude for Enterprise, and comparable managed offerings can provide organizational controls, administrative visibility, and contractual data handling protections that personal accounts do not provide in the same way.
The exposure with shadow AI comes specifically from employees using personal or unmanaged accounts for work that involves organizational data, outside any of those controls.
Why Policy Alone Doesn’t Close the Gap
In EisnerAmper’s 2025 workplace AI survey, only 36% of respondents said their employer had a formal AI policy. Even among organizations that do have one, a policy distributed once and never tied to day-to-day workflows doesn’t change much. An employee summarizing a client document at 4pm on a Friday isn’t consulting the employee handbook.
“Don’t use AI for sensitive data” doesn’t work if the employee doesn’t know what counts as sensitive, doesn’t know whether their account type matters, and doesn’t have a clear alternative to reach for. Vague policies get interpreted loosely, especially under deadline pressure, which is usually exactly when employees are turning to AI in the first place.
Where to Start
Ask department heads and IT what AI tools they know about, then assume the real list is longer. Include browser extensions in the audit. The tools employees use most casually are often the ones no one has mapped.
An approved tool doesn’t mean an approved account configuration. Define which account types are acceptable for work use, and make that distinction specific enough that employees can act on it without having to ask.
Skip abstract categories. Tell employees specifically what can’t go into an external AI tool: client records, draft contracts, financial projections, personnel data. Give them a decision they can make in the moment, not a principle they have to interpret.
AI tools and their terms change regularly. Someone needs to own the policy, respond to employee questions, and update it when the environment shifts. Without a named owner, the policy ages out and nobody notices.
For Greater Sacramento organizations, the first step is getting visibility into what is already in use. From there, they can decide which tools are approved, set clear data boundaries, and assign responsibility for keeping those rules current. Doing that now is far easier than building the process after an incident, client request, or insurance review forces it.
Vision Quest Cyber works with Greater Sacramento organizations on AI policy, data handling, and security. If you want to understand what AI use actually looks like inside your organization, we can help you find out.
