Saltar al contenido

negocio · 4 min read

Shadow AI: why 64% of your staff already use AI unchecked

Unauthorized AI use by employees is surging in 2026, exposing client data and IP. What the law says and how to govern AI use without banning it outright.

Published on · Evicron

Shadow AI — employees using ChatGPT, Copilot or any other AI tool without IT or security knowing or approving it — has stopped being a workforce quirk and become the fastest-growing data risk of 2026. A Microsoft study covered by DirectorTIC on July 20 found that 64% of employees admit to using unauthorized AI tools for work, and 78% of those who use AI do so with their own personal accounts and apps, not ones the company has vetted. At Evicron, an AI and custom software studio based in Barcelona, we see this on nearly every consulting engagement: AI is already inside the company — nobody just invited it in formally.

What shadow AI actually is

The term mirrors “shadow IT”: tools teams adopt on their own to solve an immediate problem — summarizing a contract, generating code, drafting a proposal — without going through the security review that corporate software requires. What makes shadow AI different is the nature of the risk: every time someone pastes a code snippet, a client’s data or a financial figure into a public chatbot, that information leaves the company and can be stored, reused or exposed on third-party servers nobody controls.

The scale of the problem, in numbers

The 2026 figures are consistent across independent studies, which rules out a one-off spike:

  • 64% of employees admit to using unauthorized AI at work, and 60% of IT leaders believe their leadership has no clear plan to regulate it, per the Microsoft study reported by DirectorTIC.
  • WatchGuard’s global survey, published July 14, 2026, names shadow AI and unsafe work habits among the top drivers of rising cybersecurity risk this year, according to its press release.
  • Other industry research puts regular, ungoverned AI use on corporate devices at around 45% of employees, with engineering and product teams among the heaviest adopters.

This isn’t a story about careless employees. It’s the predictable result of generative AI being free, immediately useful, and far faster to adopt than any corporate software procurement process.

What your company is actually risking

The exposure isn’t just reputational. It stacks three legal fronts that already have real teeth in 2026:

  • GDPR: if an employee pastes client or coworker data into a public AI tool, the company may be transferring personal data to a third party without a legal basis, with fines reaching €20 million or 4% of global turnover.
  • The EU AI Act: the most serious violations — including prohibited uses and practices — carry fines of up to €35 million or 7% of annual worldwide turnover.
  • Trade secrets law: proprietary code or a commercial proposal pasted into a chatbot can lose its legal status as a trade secret if it wasn’t protected with reasonable safeguards beforehand, which weakens any later claim if that secret leaks or a competitor uses it.

On top of that sits the simplest risk of all: not knowing what company information has already left, or where it went.

How to regain control without banning AI

Banning it doesn’t work — the studies confirm it: people keep using AI regardless, just without anyone knowing. What does work is offering a better, governed alternative:

  1. Audit what’s already in use. Before writing a policy, find out which tools are actually circulating in the company and with what data — not what people are supposed to be using.
  2. Define an approved AI list with corporate accounts, data processing agreements and access control, instead of letting everyone rely on personal accounts.
  3. Offer alternatives that are just as fast. If the corporate AI tool is slower or more limited than free ChatGPT, shadow AI comes right back.
  4. Train teams on what can and can’t be pasted into a chatbot: most leaks aren’t malicious, they’re due to not knowing better.
  5. Review regularly, because tools and teams change faster than any policy written once and forgotten.

When it’s worth bringing in outside help

Doing this in-house is possible, but it usually runs into two problems: nobody internally has time to audit every tool already in use, and choosing and rolling out a corporate AI that genuinely replaces the scattered tools requires technical judgment that isn’t always available in-house. Our AI consulting for businesses starts exactly there: we audit what AI is already in use, what real risk it carries, and what your company would need for governed AI that doesn’t sacrifice the speed employees were after in the first place. When the fix means deploying specific tools — an internal assistant, an integration with your own data — we build it with applied AI; if the blocker is that teams don’t know what’s allowed, we solve that with AI training tailored to each department.

Bottom line

Shadow AI isn’t a passing trend: it’s the result of generative AI being faster to adopt than any company policy, and by 2026 it’s moving client data, code and commercial proposals outside company control every single day. Ignoring it won’t stop it — the data shows people keep using AI regardless. The only thing that works is auditing, offering governed alternatives, and training teams before a client, a competitor or an inspector discovers the leak first.

Want to find out what AI is already being used inside your company and how to govern it without slowing teams down? Get in touch: the first consultation is free, and we reply within 24 hours.

Let's talk.

Tell us about your project, challenge or opportunity. We reply within 24 hours with a concrete action plan and indicative budget.