Shadow AI is nothing new. What is new is that in 2026 it can no longer be dismissed as a fringe phenomenon. A series of recent workforce and security publications shows that employees are using AI tools en masse without the approval of IT and security, and that in doing so confidential information regularly ends up in public models. The problem has thereby shifted: from a matter of policy and awareness to a concrete question about visibility, data flows and demonstrable control.
The immediate occasion for this article is the Shadow AI Report 2026 from Teramind Research. That report describes how much AI use within organisations falls outside formal governance, making data flows invisible and leaving little control over which information ends up in which tool. The report explicitly points to the need for user-level telemetry, classification of data types and contextual policies.
What the figures show
The Teramind findings do not stand alone. PagerDuty published a survey with the finding that two-thirds (66%) of office professionals have used unauthorised AI tools at work. The same publication reveals that employees share confidential company information with public AI tools, and that policy and training lag behind actual use.
Lenovo arrives at a comparable picture from a different angle. In a workforce survey, the company states that 70% of AI within enterprises is uncontrolled and that this brings hidden risks, costs and complexity. The core is always the same adoption gap: employees are ahead in their use, while IT and security lack an overview.
Why that overview matters becomes clear from the security context. In the 2026 Data Breach Investigations Report, Verizon links unapproved shadow AI to data breaches and places the topic within broader breach trends. Uncontrolled AI use is thereby not a theoretical risk, but a real route along which sensitive information can leave the organisation.
Why bans and awareness are not enough
The temptation is to respond with a ban or with an extra round of security awareness. But the studies show that policy already exists and that use continues nonetheless. A generic ban usually shifts the problem to private accounts and personal devices, where there is no visibility at all. Awareness alone changes little as long as employees experience a concrete productivity advantage.
The Artificial Intelligence Risk Management Framework (AI RMF 1.0) from NIST places this in a broader context. The framework notes that shadow AI arises when departments deploy AI without review by IT, and that organisations need governance, monitoring and structured risk assessment to use AI responsibly. The common thread from all sources points the same way: without a control layer around AI use, the organisation remains blind to its own data flows.
In practice, that control layer consists of a number of building blocks:
- Inventory: knowing which AI tools are actually being used, per user and per department.
- Access restriction: offering controlled, approved alternatives rather than merely banning.
- Logging: auditable recording of AI interactions, so that what was shared can be reconstructed afterwards.
- Data classification: determining in advance which data types may and may not go to an external model.
Where a verification console can help
For professionals who work with confidential information — lawyers, notaries, occupational physicians, journalists, researchers and compliance teams — this question is especially acute. This is not about arbitrary company data, but about case files, client information and source material subject to professional confidentiality or statutory secrecy.
Vera, in that context, is not a chatbot and not a language model of its own, but a verification layer designed to make AI use controllable. The Semantic Privacy Shield carries out preprocessing and anonymisation on EU infrastructure; the workflow is set up so that only anonymised content is sent to the selected AI models. If the privacy check does not pass, nothing is forwarded. This aligns with the finding from the studies that the greatest risk lies precisely in what goes out uncontrolled.
In addition, the multi-model verification can help avoid blindly adopting AI answers: the console makes verification steps visible, so that a professional can judge for themselves whether an answer is usable. Vera guarantees no correctness and eliminates no errors or hallucinations — the professional final judgement always remains with the user. What matters is that the steps become traceable and demonstrable. Anyone who wants to view and edit documents within the same secure environment can do so via Vera Office.
The message of the reports from Teramind, PagerDuty, Lenovo and Verizon can be summed up soberly: AI use happens anyway, whether the organisation has approved it or not. The question is no longer whether employees deploy AI, but whether the organisation can see, steer and afterwards account for that use. That is the shift that 2026 makes visible: from shadow AI as a quiet habit to shadow AI as a governance task that calls for verifiable control.