AI

Shadow AI explained: The work shortcut that could leak your company’s secrets

| October 1, 2026
shadow AI

Using an AI chatbot, assistant, or browser to speed up your work is tempting, but doing it without your employer’s knowledge can put sensitive data at risk.

You’re swamped, so you paste a long email thread into a free chatbot and ask for a summary. It works, it saves an hour, and nobody notices. But the thread may contain customer details or confidential plans you’ve just shared with an outside service.

If your employer hasn’t approved that tool or how you’re using it, that’s shadow AI.

The UK’s National Cyber Security Centre (NCSC) defines shadow AI as:

“the use of AI technology which isn’t captured in an organisation’s approved systems and processes.”

A Microsoft study published in 2025 found that 71% of UK employees surveyed said they had used AI tools at work their employer hadn’t approved. Most people aren’t doing this to cause trouble. They want to get their work done faster, and the tools are right there.

Shadow AI isn’t limited to chatbots. It can also be:

  • A browser extension that “improves your writing.”
  • A meeting-notes bot that joins your calls.
  • An AI feature quietly switched on inside an app you already use.
  • A small automation you built yourself that sends data to an AI service.

AI features are appearing in search engines, email apps, and phones. Instead of a helpful list of links, Google now tries to answer your question. Microsoft’s Copilot drafts replies to your boss before you’ve had coffee. Your phone summarizes conversations you don’t even remember having. That makes it easy to start using one without checking whether it’s approved for work.

Why it worries IT and security teams

When you enter data into a public AI tool, it leaves your company’s control. The service may keep that data or use it to improve its models, unless specific privacy controls are in place. That can lead to data breaches, lost intellectual property, and regulatory problems.

There is also a security angle. AI assistants and agents—tools that can take actions on your behalf—are complex software and can have serious vulnerabilities. If an attacker exploits one, they may gain access to the data and services the tool has.

IBM’s 2025 Cost of a Data Breach research found that one in five organizations reported a breach linked to shadow AI. Only 37% had policies to manage AI or detect shadow AI. Organizations with a lot of shadow AI paid roughly $670,000 more per breach.

In a survey of our newsletter readers, 90% of respondents said they were worried about AI using their data without consent. Company data deserves the same care as your own.

How to use AI more safely at work

You don’t need to avoid AI altogether. Think carefully about which apps and services you use before you share data. Start by talking to your employer, then follow these steps:

  • Ask for an approved tool. Security leaders say the best way to reduce shadow AI is to offer something better and safer, such as an enterprise AI platform with guardrails.
  • Use your work account, not a personal one. Work accounts are the ones your IT team can protect and govern.
  • Find out what’s off-limits. Customer details, financial data, HR records, source code, and confidential meeting content may be restricted. Ask which kinds of data you may and may not use with AI.
  • Check the privacy settings. Look at whether the tool stores your inputs or uses them to train its models.
  • Register your use case. Many organizations keep a list of approved AI tools and uses. A quick approval process makes it easier to stay on the right side of the rules.
  • Be careful with agents and plug-ins. Tools that connect to your email, files, or calendar should be reviewed by your IT or security team first.
  • Speak up. If the approved tools aren’t meeting your needs, say so. The NCSC recommends open conversations about security to help reduce reliance on unapproved tools.

If you manage a team, remember that banning AI outright tends to push the use further out of sight. Find out why people are turning to unapproved tools. Providing useful, approved options and clear rules can help staff work faster while protecting company data.


Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

About the author

Pieter Arntz

Malware Intelligence Researcher

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.