Do not start with a ban or another policy document, but with visibility: inventory which AI tools, agents, extensions and personal accounts actually touch your work data, link those to identities and data flows, and turn useful patterns into controlled workflows or block them. Without detection, shadow AI remains an invisible layer of risk.
The occasion for this piece is a governance analysis that Seimless published on 28 August 2026. It brings together incident figures from IBM and Netskope with a concrete observation: many organisations have no formal process to approve, track or revoke employees' unauthorised AI tools. That makes the core question a practical one: not whether shadow AI occurs, but how you make it visible and manageable.
How big is the shadow AI problem according to the 2026 figures?
The scale is now measurable. According to the Seimless analysis, which bundles IBM and Netskope data, shadow AI is involved in 43% of the security incidents examined, and 44% of workplace AI users use personal, unmanaged AI apps. Almost half of AI activity therefore falls partly or entirely outside organisational control, while more than two thirds of organisations have no process to limit unauthorised AI deployment.
The TechnologyRadius statistics overview places a broader picture alongside this: according to its bundling of research series, an estimated 60 to 70% of organisations have shadow AI exposure, and such exposure can raise the impact of data breaches by around 15% because investigations become harder. Netwrix reports in addition that only around 20% of organisations fully monitor employees' AI use, and that 76% do not fully manage non-human identities such as AI agents and service accounts.
What exactly counts as shadow AI and which forms should I recognise?
The Cloud Security Alliance defines shadow AI in its research note as generative AI tools, models, services and agents that process business data within an organisation without security review, procurement approval or governance. Netwrix explicitly calls shadow AI a subset of shadow IT. To make it recognisable, we distinguish four practical forms in our analysis:
- Personal generative AI accounts — for example a private account used to have a contract or memo rewritten.
- Unauthorised SaaS tools with AI features — services in use without procurement approval, whose AI function was added later.
- Embedded agents in existing applications — AI functions within tools that were never centrally registered, such as note-takers in confidential meetings.
- Shadow agents with their own action rights — automated processes that carry out actions independently via service accounts.
That last category in particular connects to identity and access management for AI agents under NIST, in which agents are treated as separate digital identities.
Why does 'we see little AI use' usually mean no visibility rather than no use?
A recurring misconception is that little visible AI use equates to little use. MyBusinessFuture describes a Bitkom study of more than 600 companies which shows that around four in ten mid-market companies suspect that employees use generative AI at work via private accounts, while only eight per cent regard this as widespread. That shows managers usually see their own assessment, not an actual measurement.
Our assessment: as long as detection is absent, the sentence "we see little AI use" says more about the lack of visibility than about actual use. This aligns with the Seimless picture that almost half of AI activity falls outside control. Shadow AI is therefore not an exclusive problem of large enterprises, but, according to the figures cited by MyBusinessFuture, occurs just as much in the European Mittelstand.
Which steps turn shadow AI into demonstrably controlled use?
The Cloud Security Alliance links shadow AI to a set of control measures aligned with NIST-style security principles. Based on those recommendations and the Netwrix risk list, we sketch a practical framework:
- Inventory and detection — use network and CASB monitoring, browser-extension audits and SaaS discovery to map per department which AI tools, agents and extensions are actually in use.
- Identity and access — treat AI agents, tools and service accounts as fully-fledged principals with least-privilege rights, SSO and role-based access; link personal accounts to work identities or block them.
- Data minimisation and isolation — record which data must never go through public AI channels and design integrations so that sensitive data only travels via controlled paths.
- Logging and audit trail — log prompts, outputs, tools used, models and identities per workflow, so it remains traceable where shadow-like use still occurs.
- Formalise or block — turn useful patterns into approved workflows with policy, training and guardrails, and explicitly exclude high-risk patterns.
Anyone wanting to set up these steps coherently will find broader context in our topic hub on AI governance and workflow control. On the data side, recording GDPR responsibilities per phase of your AI workflow and controlling the risks of ChatGPT connectors to Gmail, Drive and Teams can help.
What role can a verification console play in gaining visibility into shadow AI?
Detection and governance call for a place where the choices per workflow become visible. Vera is a privacy-focused AI verification layer for professionals working with confidential or high-trust information; it is not a chatbot and not its own language model. Its function is not to solve shadow AI, but to support the visibility and workflow control described above: showing per task which models were used and which verification steps, corrections, disagreements and sources went with them, so that control becomes possible.
The privacy workflow is fail-closed: if the privacy verification fails, the document is not sent onward. The Semantic Privacy Shield is designed to replace sensitive document values with synthetic, session-only equivalents on EU infrastructure before AI processing, so that only anonymised content goes to the selected models; the original values can be restored locally. That is an architecture description, not a guarantee that anonymisation runs flawlessly or that the full GDPR is complied with. The professional final judgement always remains with the user.
Sources and references
Sources: The article draws on the shadow AI analysis by Seimless (with IBM and Netskope data), statistics from TechnologyRadius, the risk list from Netwrix, the Cloud Security Alliance research note and the Bitkom study cited by MyBusinessFuture.