A threefold rise in a single year is fast enough that any policy written before it is describing a different organization.
The number is best read as a measurement of governance lag rather than of employee behavior. Shadow AI is defined against what the employer has sanctioned, so the figure rises both when staff adopt something new and when the organization has simply not gotten around to classifying a tool that is already in use. Both are governance gaps and both are closed the same way, which is by producing an inventory.
That is why every AI governance framework, from NIST AI RMF to ISO 42001 to the EU AI Act, starts in the same place. Each assumes you can enumerate the AI systems in use and say what each one does with what data. An organization that writes an acceptable-use policy before it can produce that list has governed a population it cannot see.
Common questions
- How many employees use unapproved AI tools at work?
- Verizon's 2026 Data Breach Investigations Report recorded shadow AI use at 45% of employees, up from 15% the year before. The measure is taken against what each employer had formally sanctioned, so part of the rise reflects tools already in use that the organization had not yet classified either way.
- Where should AI governance start?
- With an inventory. NIST AI RMF, ISO 42001, and the EU AI Act all assume an organization can enumerate the AI systems in use and state what each does with what data. Writing an acceptable-use policy before that list exists governs a population nobody can see, which is why policy-first programs stall.
- Should companies block unsanctioned AI tools?
- Blocking without a supported alternative usually relocates the activity rather than ending it. Usage at 45% indicates the sanctioned toolset does not cover the work people are actually doing. The more effective sequence is to inventory what is in use, approve a capable option quickly, and then enforce against the remainder.