Understanding the Rise of Unauthorized AI Usage in Workplaces
The study highlights a significant trend as corporate trust dwindles.
UpGuard, a recognized leader in cybersecurity and risk management, has recently released a study titled "State of Shadow AI". This report uncovers the troubling prevalence of unapproved generative AI tools being employed within various organizations. According to the data, a staggering 80% of employees are engaging with unauthorized AI tools in their work environments, raising serious security concerns and highlighting a significant gap in compliance across all employee levels.
What's even more alarming is that 68% of security leaders, including their Chief Information Security Officers (CISOs), are also admitting to using unapproved AI technologies daily. This situation indicates that not only are employees disregarding established corporate guidelines, but even those in charge of security are participating in this behavior. Consequently, organizations are finding themselves exposed to heightened security risks due to these unauthorized practices.
The Paradox of AI Training and Usage
The report unearths a perplexing AI security paradox. Although 40% of employees claim to have completed AI safety training and gained a better understanding of associated risks, these very individuals are more likely to be the ones using unapproved tools on a frequent basis. This contradiction suggests that traditional compliance and security training may not effectively curb the growing inclination to utilize unauthorized AI technologies.
Greg Pollock, the head of Research and Insights at UpGuard, emphasized this dilemma, stating, "Shadow AI has triggered a challenge in maintaining trust between employer and employee. Our data indicates that rather than reducing shadow AI usage, increased security training seems to correlate with its rise. Organizations need to engage more effectively with their employees about AI and appropriately channel their curiosity."
Who Is Embracing Shadow AI?
Research from UpGuard points out that typical security awareness initiatives are failing to mitigate unauthorized AI usage, inadvertently creating an environment for what can be termed "AI power users." The phenomenon is particularly evident among senior leadership, with employees in managerial positions showing a 50% higher likelihood of using Shadow AI compared to their peers.
The survey finds the following concerning trends:
- An astonishing 90% of security leaders report utilizing unapproved AI tools, and 69% of CISOs incorporate these technologies into their daily routines.
- A significant 27% of employees express more trust in AI for reliable information than in their managers or colleagues, highlighting the widening divide between employees’ perceptions and corporate authority.
- Approximately 23% of CISOs are aware that passwords and other sensitive credentials are being shared with AI tools at their organizations, which poses a tremendous risk.
- Despite 52% of employees being informed about their company’s AI usage policy, a troubling 70% are aware of sensitive data being shared with AI tools in their workload.
Creating a Secure Environment for the Future
The trend of unauthorized AI usage in workplaces is set to rise unless companies adopt stricter governance and approaches. It's becoming increasingly clear that simply blocking applications is ineffective, as 41% of employees will find workarounds regardless.
To foster a transparent and secure environment, businesses need to shift from restrictive fear-based approaches towards guided enablement strategies. This transition is essential for addressing the next steps necessary for improving security: ensuring visibility, establishing intelligent safeguards, and offering vetted tools. It is vital to make secure practices the most straightforward choice for all employees.
Methodology of the Study
This insightful report’s data was gathered through two primary methods. Firstly, the survey targeting security leaders was carried out by Dynata, covering a timeline that led into late summer 2025, with a participant pool of 542 security professionals from companies employing over 200 members across various global regions. Secondly, the employee-focused survey utilized the Prolific platform, capturing responses from 1020 currently employed individuals in the US and UK, contributing valuable insights about the work environment.
About UpGuard
Founded in 2012, UpGuard stands as an industry leader in cybersecurity and risk management. The company delivers an AI-powered platform for cyber risk posture management (CRPM), offering a comprehensive and actionable viewpoint of cyber risk across an organization's vendors, attack surfaces, and workforce. UpGuard's platform is trusted by many organizations to help manage cyber risk effectively and efficiently.
Frequently Asked Questions
1. What is "Shadow AI"?
Shadow AI refers to the use of unauthorized artificial intelligence tools within an organization that bypasses established protocols.
2. Why is unauthorized AI usage a concern?
Unauthorized AI usage can expose organizations to increased security risks and potential data breaches, which can undermine trust and compliance.
3. What percentage of employees use unauthorized AI tools?
According to the report, about 80% of employees are using unauthorized AI tools in their workplaces.
4. How do security leaders view this trend?
The report indicates that 68% of security leaders, including CISOs, have admitted to using unapproved AI tools themselves.
5. What can companies do to address unauthorized AI usage?
Companies should implement guided enablement strategies, improve visibility, set intelligent guardrails, and provide vetted AI tools to encourage secure practices.