Shadow AI use tripled to 45% of employees in one year, per Verizon's 2026 Data Breach Investigations Report, which recorded employee use of unsanctioned AI tools rising from 15% to 45%.
Now states
49% of employees use AI tools their employer has not sanctioned, from BlackFog and Sapio Research, fielded across 2,000 UK and US employees in November 2025.
Why it changed
The DBIR figure was real but measured a different question. Verizon's 15% to 45% series tracks frequency of AI use on corporate devices, not whether the employer had approved the tool. The report's separate shadow AI finding is a rank within data-loss events and carries no employee percentage, so the card had joined an adoption series to an approval claim that no source made. The replacement asks employees directly whether the tool was sanctioned, which is the question the card was always making. The new source is vendor-commissioned and is labeled as such on the card.
49%
of employees use AI tools their employer has not sanctioned
49% of Employees Use AI Tools Their Employer Has Not Sanctioned
Survey. Self-reported by a sample. Read it as what this population says it does, not as a measurement of what it does.
Roughly half is the number worth planning against, and it has been stable across several independent measurements rather than resting on one survey. Gartner found 69% of organizations suspected or confirmed staff use of prohibited public generative AI, and Harmonic Security's telemetry put close to three quarters of enterprise ChatGPT usage on personal rather than corporate-licensed accounts. Different questions, same conclusion: sanctioned tooling does not cover the work.
The number is best read as a measurement of governance lag rather than of employee behavior. Unsanctioned is defined against what the employer has approved, so the figure rises both when staff adopt something new and when the organization has not gotten around to classifying a tool already in use. Both are governance gaps and both close the same way, which is by producing an inventory.
That is why every AI governance framework starts in the same place. NIST AI RMF, ISO 42001, and the EU AI Act each assume you can enumerate the AI systems in use and say what each one does with what data. An organization that writes an acceptable-use policy before it can produce that list has governed a population it cannot see.
What this does not mean
This does not mean half of your staff are doing something dangerous. Unsanctioned covers a marketer running an unapproved transcription tool over a public webinar and an engineer pasting production data into a consumer chat interface, and those carry entirely different exposure. It also does not mean blocking is the answer. Usage at this level indicates the approved toolset does not cover real work, and a block without a supported alternative moves the activity rather than ending it. Nor is this a count of tools: one employee using four unapproved tools registers once.
Take this to your board
Forty-nine percent of employees use AI tools their employer has not sanctioned, from a survey of two thousand UK and US staff at organizations over five hundred people, published by BlackFog in January 2026.
Say the peer figure and your own in the same breath. A number without a comparison invites the board to supply one from memory.
Sources
Every external figure on this page, with its origin, sample, and the date it was last checked by hand.
49% of surveyed employees reported using AI tools that their employer had not sanctioned.
BlackFog and Sapio Research, Shadow AI researchVendor research · Published January 27, 2026 · Sample: 2,000 employees, 1,000 UK and 1,000 US, at organizations above 500 staff · Verified September 12, 2026
Fielded by Sapio Research in November 2025. Employees self-report against their own understanding of what the employer has approved, so the figure moves with how clearly a policy was communicated as well as with actual behavior. Commissioned by a vendor selling data exfiltration controls, which is an interest in the answer being high.
Common questions
How many employees use unapproved AI tools at work?
Research published by BlackFog in January 2026, fielded by Sapio across 2,000 UK and US employees, put the figure at 49%. Gartner reached a similar place from the organizational side, with 69% of surveyed organizations suspecting or confirming staff use of prohibited public generative AI tools.
Where should AI governance start?
With an inventory. NIST AI RMF, ISO 42001, and the EU AI Act all assume an organization can enumerate the AI systems in use and state what each does with what data. Writing an acceptable-use policy before that list exists governs a population nobody can see, which is why policy-first programs stall.
Should companies block unsanctioned AI tools?
Blocking without a supported alternative usually relocates the activity rather than ending it. Usage near half the workforce indicates the approved toolset does not cover the work people are actually doing. The more effective sequence is to inventory what is in use, approve a capable option quickly, and then enforce against the remainder.
Is unsanctioned AI use the same as shadow AI?
The terms are used interchangeably and the measurements underneath them differ, which is where confusion enters. Some studies count employees using unapproved tools, some count data-loss events involving AI, and some count AI traffic on corporate devices regardless of approval. Check which question a figure answers before putting it in a board pack.