ReportsAugust 2026

Shadow AI

From Hidden Habit to Deliberate Strategy

Most companies’ employees are already pasting sensitive data into unapproved chatbots. This briefing turns that hidden habit into a deliberate strategy — diagnosing shadow AI, working through tolerate vs. build vs. buy, and setting the guardrails for AI that acts.

See what's inside
Bart Turczynski45 sourcesWeb, PDF, EPUB
Shadow AI: From Hidden Habit to Deliberate Strategy
50–90%
of employees already use unapproved AI at work
$670K
in extra breach costs for organizations with high shadow AI
20%
of breached organizations were compromised through shadow AI
95%
of enterprise generative-AI pilots show no measurable P&L impact

Foreword

If your people are already using AI without approval, then “doing nothing” is not a neutral choice: it’s a choice to keep the risk and forgo the upside.
Tytus Gołas

What's inside

Three parts, twenty-one chapters, plus a preface and forty-five numbered sources.

Part One · Chapters 01—06

The Diagnosis

What shadow AI is, how widespread it has become, and what it puts at risk.

  1. 01What Shadow AI Actually Is
  2. 02How Prevalent It Is
  3. 03What Employees Put Into These Tools
  4. 04Why It Happens
  5. 05What It Puts at Risk
  6. 06The Canonical Cautionary Tale

Part Two · Chapters 07—14

The Response

The economics of tolerate, build, or buy: a staged path for moving deliberately, and how to measure the result.

  1. 07From Bans to “Sanction-and-Steer”
  2. 08Option 1: Tolerate
  3. 09Option 2: Build
  4. 10Option 3: Buy
  5. 11The Case That Captures Both Promise and Limit: Klarna
  6. 12The Decision Framework
  7. 13On Measuring ROI
  8. 14Regulatory and Compliance Economics

Part Three · Chapters 15—21

AI That Acts

Agents, systems that don’t just advise but act, where the same discipline applies in sharper form.

  1. 15Why Acting Changes the Risk
  2. 16The Productivity Case, Kept Honest
  3. 17Why Agents Are Still a Specialist’s Tool
  4. 18What Broad Autonomy Actually Costs
  5. 19Accountability When an Agent Errs
  6. 20The Shape of a Disciplined First Move
  7. 21The Bottom Line

Written for four desks

The same research, read four ways. Each section answers a different set of decisions.

  1. 01

    Security, IT & Compliance

    Shadow AI on personal accounts is a data-governance and breach problem. Covers visibility, sanction-and-steer, the enterprise-vs-consumer tier distinction, and EU AI Act exposure.

  2. 02

    Executives & Strategy

    “Doing nothing” isn’t neutral. Covers the tolerate-build-buy decision, the opportunity and competitive costs of waiting, and a staged framework for moving deliberately.

  3. 03

    Customer Service & Operations

    The highest-volume, best-evidenced place to start. Covers hybrid human+AI models, the Klarna lesson, and measuring ROI against metrics your CFO already tracks.

  4. 04

    AI & Automation Leads

    The frontier is AI that acts. Covers why acting changes the risk, bounded-scope agent design, architectural guardrails, and accountability when an agent errs.

Shadow AI: From Hidden Habit to Deliberate Strategy

Free · Web, PDF, EPUB

Read the full briefing

Leave your work email and the report opens right here in the browser. Free, and yours in every format.

Read it in the browser, and download the PDF and EPUB to keep.

By submitting this form you agree to our terms and conditions and privacy policy. You can opt out of our mailing list at any time.

Frequently asked

What is shadow AI?

Shadow AI is employees’ use of AI tools — public chatbots, personal accounts, “bring your own AI” — outside the visibility or control of the IT organization. It’s the AI-era descendant of shadow IT, with a sharper edge: company data typed into systems that may store, learn from, or expose it.

How common is it?

Depending on how you measure it, between roughly 50% and 90% of employees already use unapproved AI at work, while only a minority of organizations have a policy, a sanctioned alternative, or any visibility.

Should we just ban it?

Bans consistently backfire — 46% of workers say they’d ignore an outright ban, and most bans are bypassed via personal accounts. The mainstream posture is “sanction-and-steer”: provide vetted tools, set data boundaries, and coach rather than block.

Who is this report for?

Leaders deciding where AI belongs in their stack — security, IT and compliance, executives and strategy, and customer-service and operations owners weighing tolerate vs. build vs. buy.

Is this report free?

Yes. Leave your work email to read the full briefing right here, and to download the PDF and EPUB — free.

Every Tidio Labs report is free to read online.

All reports