Shadow AI
From Hidden Habit to Deliberate Strategy
Most companies’ employees are already pasting sensitive data into unapproved chatbots. This briefing turns that hidden habit into a deliberate strategy — diagnosing shadow AI, working through tolerate vs. build vs. buy, and setting the guardrails for AI that acts.

- 50–90%
- of employees already use unapproved AI at work
- $670K
- in extra breach costs for organizations with high shadow AI
- 20%
- of breached organizations were compromised through shadow AI
- 95%
- of enterprise generative-AI pilots show no measurable P&L impact
Foreword
If your people are already using AI without approval, then “doing nothing” is not a neutral choice: it’s a choice to keep the risk and forgo the upside.
What's inside
Three parts, twenty-one chapters, plus a preface and forty-five numbered sources.
Part One · Chapters 01—06
The Diagnosis
What shadow AI is, how widespread it has become, and what it puts at risk.
- 01What Shadow AI Actually Is
- 02How Prevalent It Is
- 03What Employees Put Into These Tools
- 04Why It Happens
- 05What It Puts at Risk
- 06The Canonical Cautionary Tale
Part Two · Chapters 07—14
The Response
The economics of tolerate, build, or buy: a staged path for moving deliberately, and how to measure the result.
- 07From Bans to “Sanction-and-Steer”
- 08Option 1: Tolerate
- 09Option 2: Build
- 10Option 3: Buy
- 11The Case That Captures Both Promise and Limit: Klarna
- 12The Decision Framework
- 13On Measuring ROI
- 14Regulatory and Compliance Economics
Part Three · Chapters 15—21
AI That Acts
Agents, systems that don’t just advise but act, where the same discipline applies in sharper form.
- 15Why Acting Changes the Risk
- 16The Productivity Case, Kept Honest
- 17Why Agents Are Still a Specialist’s Tool
- 18What Broad Autonomy Actually Costs
- 19Accountability When an Agent Errs
- 20The Shape of a Disciplined First Move
- 21The Bottom Line
Written for four desks
The same research, read four ways. Each section answers a different set of decisions.
- 01
Security, IT & Compliance
Shadow AI on personal accounts is a data-governance and breach problem. Covers visibility, sanction-and-steer, the enterprise-vs-consumer tier distinction, and EU AI Act exposure.
- 02
Executives & Strategy
“Doing nothing” isn’t neutral. Covers the tolerate-build-buy decision, the opportunity and competitive costs of waiting, and a staged framework for moving deliberately.
- 03
Customer Service & Operations
The highest-volume, best-evidenced place to start. Covers hybrid human+AI models, the Klarna lesson, and measuring ROI against metrics your CFO already tracks.
- 04
AI & Automation Leads
The frontier is AI that acts. Covers why acting changes the risk, bounded-scope agent design, architectural guardrails, and accountability when an agent errs.

Free · Web, PDF, EPUB
Read the full briefing
Leave your work email and the report opens right here in the browser. Free, and yours in every format.
Read it in the browser, and download the PDF and EPUB to keep.
Frequently asked
What is shadow AI?
Shadow AI is employees’ use of AI tools — public chatbots, personal accounts, “bring your own AI” — outside the visibility or control of the IT organization. It’s the AI-era descendant of shadow IT, with a sharper edge: company data typed into systems that may store, learn from, or expose it.
How common is it?
Depending on how you measure it, between roughly 50% and 90% of employees already use unapproved AI at work, while only a minority of organizations have a policy, a sanctioned alternative, or any visibility.
Should we just ban it?
Bans consistently backfire — 46% of workers say they’d ignore an outright ban, and most bans are bypassed via personal accounts. The mainstream posture is “sanction-and-steer”: provide vetted tools, set data boundaries, and coach rather than block.
Who is this report for?
Leaders deciding where AI belongs in their stack — security, IT and compliance, executives and strategy, and customer-service and operations owners weighing tolerate vs. build vs. buy.
Is this report free?
Yes. Leave your work email to read the full briefing right here, and to download the PDF and EPUB — free.
Every Tidio Labs report is free to read online.
All reports