Artificial Intelligence

Shadow AI in the Workplace: Your Employees Already Use AI Without Telling You

Shadow AI is the use of artificial intelligence tools by employees without the company's approval or oversight.
image of an innovation lab (for an AI developer tools business)
Key takeaways
  • According to a Gartner survey (2025) of 302 cybersecurity leaders, 69% of organizations suspect or have evidence that employees use prohibited public generative AI tools.
  • According to the Microsoft and LinkedIn Work Trend Index (2024), 75% of knowledge workers use AI at work and 78% of AI users bring their own tools.
  • According to KPMG and the University of Melbourne (2025), 66% of users rely on AI output without checking its accuracy and 56% have made mistakes at work because of AI.
  • Gartner predicts that by 2030, more than 40% of organizations will experience security or compliance incidents linked to shadow AI; PlanAxion recommends a four-step governance approach rather than a ban.

The quarterly report came out faster than usual. The summary is clean, the tone is right. What leadership does not know: the analyst had it reviewed by a public chatbot, margin figures included.

That scene is playing out right now in most Quebec businesses. Employees did not wait for an internal policy to adopt AI. The phenomenon has a name: shadow AI.

According to a Gartner survey of 302 cybersecurity leaders (2025), 69% of organizations suspect or have evidence that employees are using prohibited public generative AI tools.

What is shadow AI in the workplace?

Shadow AI is the use of artificial intelligence tools by employees without the company's approval or oversight. ChatGPT, Gemini, Claude or Perplexity, used from a personal account for work tasks, are its most common form.

Unlike classic shadow IT, it requires no installation. A browser is enough: paste a document, upload a spreadsheet, ask for a summary. The gesture feels harmless. The data, meanwhile, has just left your perimeter.

The distinction between traditional AI and generative AI matters here: shadow AI almost always involves the latter, accessible to anyone with no technical skill.

How big is shadow AI in 2026?

Individual AI use far exceeds what companies report: two thirds of people use AI regularly, while one fifth of Canadian businesses report using it. The gap between those two measures is the shadow zone.

The benchmarks worth remembering:

At PlanAxion, we see the same pattern in our ERP mandates and AI workshops: when leadership asks who already uses AI, half the hands go up, and almost none of those uses had been counted.

What risks does shadow AI create for your business?

Three risks dominate: confidential data leaks, unverified errors entering your deliverables, and regulatory non-compliance. None of the three shows up on a dashboard until an incident reveals it.

Leaks first. A customer contract pasted into a free consumer tool can be retained and reused by the provider. Gartner predicts that by 2030, more than 40% of organizations will experience security or compliance incidents linked to shadow AI.

Errors next. According to KPMG and the University of Melbourne (2025), 66% of users rely on AI answers without checking their accuracy, and 56% admit to making mistakes at work because of AI.

Compliance last. In Quebec, Law 25 governs the communication of personal information to third parties, which includes public AI tools. Our article on Law 25 and cloud computing details the required assessment process.

Five professionals sorting artificial intelligence use cases on a whiteboard in a Quebec meeting room
Governing shadow AI starts with an inventory: which tools, which tasks, which data.

Should you ban ChatGPT and public AI tools at work?

No. An outright ban pushes usage onto personal devices, where you see nothing at all. The numbers show it: 69% of organizations observe or suspect the use of tools that are already prohibited (Gartner, 2025). The ban already exists; it does not work.

The employee demand is legitimate. They are trying to absorb a workload that keeps growing, and AI helps them do it. Punishing that initiative means punishing productivity while keeping the risk.

The approach that holds: offer an approved tool as simple as the ones employees already use, plus clear rules on what can go into it. A well-equipped employee has no reason left to go through a personal account.

Shadow AI is first a business signal: your employees found value in AI before your official plan did.

How do you govern AI use without killing the momentum?

Four workstreams are enough to bring AI out of the shadows: an honest usage inventory, a short policy, approved tools and training tied to real tasks.

The inventory first, without a witch hunt. A declared amnesty (tell us what you use, nobody gets blamed) produces a truer map of usage in two weeks than any technical audit.

The policy next. One page, not thirty: the approved tools, the data categories that never leave (personal information, unpublished financial data, source code), and the human review rule before anything goes out externally.

Training last, wired to each team's real tasks. Only 39% of AI users have received any from their employer (Microsoft and LinkedIn, 2024). It is the cheapest and highest-return lever on this list.

Some of the uses you inventory deserve better than governance: they deserve a real project. That is the role of a structured AI workshop: turning individual initiatives into use cases prioritized by problem, expected value, available data and required effort. At PlanAxion, the exercise runs over 4 weeks and the investment varies with scope; it is confirmed during a short exploratory call.

Transparency note: the figures cited come from public surveys (Gartner, Microsoft and LinkedIn, KPMG and the University of Melbourne, Statistics Canada). Scopes and definitions vary from one study to another, and none of these numbers describes your specific situation.

What should you remember about shadow AI before your next executive meeting?

Your employees already use AI: the only decision still yours is whether that use will be visible, governed and profitable. The inventory costs two weeks. The policy fits on one page. Canada's 2026 numbers show that companies that structure this momentum pull ahead of those that ignore it.

Frequently asked questions about shadow AI

What is shadow AI?

Shadow AI is the use of artificial intelligence tools, most often public chatbots such as ChatGPT, Gemini or Claude, by employees without their company's approval or oversight. It differs from classic shadow IT in its simplicity: no software to install, a browser and a personal account are enough.

What share of employees use AI without authorization at work?

According to Gartner (2025), 69% of organizations suspect or have evidence that employees use prohibited generative AI tools. The 2024 Microsoft and LinkedIn Work Trend Index already measured that 78% of AI users were bringing their own tools to work rather than waiting for their employer.

Should ChatGPT be banned at work?

A total ban shifts usage onto personal devices and removes all visibility. The most effective approach combines an approved tool of comparable simplicity, a one-page policy on the data that must never leave, and training tied to real tasks. Bans belong on sensitive data categories, not on the tool itself.

What should a corporate AI usage policy contain?

Four elements: the list of approved tools with their business accounts, the data categories that must never be submitted to a public tool (personal information, unpublished financial data, source code), a human review requirement before any external release, and a contact point for proposing new use cases.

Is shadow AI covered by Law 25 in Quebec?

Law 25 governs the communication of personal information to third parties, which includes the providers of public AI tools. Submitting customer or employee personal information to a consumer tool without a prior assessment exposes the company to penalties. A privacy impact assessment is the expected process.