Here's a question worth asking honestly: if you haven't formally rolled out AI tools at your business, does that mean AI isn't being used with your company's data? A business may not know the answer, because employees may already be pasting customer details, contracts, or internal documents into whatever AI tool they've picked for themselves, on personal accounts, through browser extensions, inside free tiers of tools nobody in IT or management approved. This is what the industry calls shadow AI, and the evidence on it points to a genuinely useful, business-friendly conclusion: the fix isn't less AI. It's giving people a properly governed version of what they're already reaching for.
How big this actually is
According to Okta's 2026 "AI Agents at Work" research, 52% of knowledge workers surveyed globally had used AI tools without their employer's approval, with usage varying considerably by country: 67% in the US, 55% in the UK, roughly 60% in Australia, against notably lower rates of 31% in France and 32% in Germany. Separately, research associated with IBM's Cost of a Data Breach work found organizations with high levels of shadow AI incurred an average of $670,000 in additional breach costs compared with those without it. IBM's 2026 Cost of a Data Breach Report itself, covering 602 breached organizations, found the average total cost of a breach reached $4.99 million, that AI-driven attacks rose 56% year over year, and that roughly one in four malicious breaches involved AI in some form.
None of this is a reason to avoid AI. It's a reason to notice that the decision to adopt AI was, in a real sense, already made, by your own employees, without the data handling, contracts, or oversight a proper rollout would have included.
There's a genuinely encouraging pattern inside this same data, though. Netskope's 2026 Cloud and Threat Report tracked a real shift over time: the share of generative AI users accessing tools through personal, unmanaged accounts fell from 78% to 47%, while use of managed, company-provided accounts rose from 25% to 62% over the same period. That's a direct, measured signal that when businesses actually provide a managed alternative, employees move toward it, which is the evidence base the rest of this article builds on.
Why banning it doesn't actually work
This is the part worth taking seriously rather than reaching for the obvious-seeming response. Multiple 2026 analyses converge on the same finding: a policy that simply prohibits AI tools without giving employees an approved alternative doesn't reduce how much AI gets used. It reduces how much of it you can see. Employees under real work pressure tend to keep using whatever gets the job done faster, banned or not; the ban mainly removes your visibility into it.
The European Data Protection Supervisor, the EU's own data protection regulator for its institutions, put this plainly in guidance published in 2026: the most effective way to discourage unapproved AI use is providing approved AI platforms that are secure, compliant, and actually capable of meeting the work people need to do, backed by ongoing staff awareness rather than a one-time policy memo. The EDPS's own framing is worth quoting directly on the core point: securing data does not mean stifling progress. Separately, research cited by the Cloud Security Alliance suggests that providing employees with approved, functional AI alternatives can reduce unauthorized use by up to roughly 89%, though that figure should be treated as evidence from the cited research rather than a universal effect every organization should expect. The direction of the evidence is consistent: the businesses that reduce shadow AI risk aren't the ones that said no to AI, they're the ones that got ahead of it with something people actually want to use.
The compliance case for getting this right
For a European business, there's a specific legal reason this matters beyond general security hygiene, worth stating precisely rather than as a blanket rule. Where an AI provider processes personal data on your business's behalf, GDPR Article 28 requires a written agreement governing that processor relationship; using a tool without one in place is a compliance gap, though it's a separate question from whether a lawful basis for the underlying processing exists at all, and the two shouldn't be conflated. Whether a specific instance of pasting personal data into an unapproved tool amounts to a reportable personal data breach under Article 4(12), triggering the 72-hour notification obligation under Article 33, depends on an assessment of whether a breach actually occurred and whether it's likely to result in a risk to the rights and freedoms of the people whose data it is, not an automatic classification. What is true regardless of that case-by-case assessment: fines under GDPR Articles 83 and 84 can reach €20 million or 4% of global annual revenue, whichever is greater, for serious violations, and using ungoverned AI tools with personal data materially increases the chance of a genuine violation occurring, even where any single instance might not itself qualify as a reportable breach. This article is not legal advice, and a specific instance is worth assessing with your data protection officer or counsel rather than treated as automatically reportable or automatically compliant. We cover the broader compliance picture, including the controller-processor relationship a proper AI vendor agreement establishes, in Is Your Business Data Safe with AI?.
What a governed alternative actually looks like
The practical fix isn't complicated, and it isn't a ban. It's giving your team a sanctioned set of AI tools, with a proper data processing agreement under GDPR Article 28 in place with the provider, scoped access appropriate to each role, and a clear, short policy stating what can and can't be entered into which tool. This is close to what we walk through when onboarding a team to a new AI tool, covered in more depth in How to Onboard Your Team to AI Automation: people who already want to use AI to do their jobs faster generally adopt a good, sanctioned option readily, once it's actually available and not slower or more restrictive than what they were using on their own.
For context: how this looks in the US market
Since much of the available data on shadow AI prevalence comes from US-focused surveys, it's worth being explicit about that rather than assuming the specific figures transfer directly to Europe. US enterprises report some of the highest unsanctioned-tool usage rates currently measured, and a wave of governance tooling launched in the US market in August 2026 alone, including Okta Agent SSO, IBM AgentOps, and Broadcom AgentMinder, aimed specifically at giving IT teams visibility into which AI tools and agents are actually running inside their organizations.
The regulatory stakes differ for a European business, though, since GDPR's data processing requirements and the EU AI Act's transparency obligations create direct legal exposure that a US-only compliance posture doesn't fully capture. We cover what the AI Act specifically requires in our EU AI Act guide. The underlying lesson, provide a sanctioned option rather than relying on a ban, holds regardless of which specific regulatory regime applies.
A framework for assessing your exposure
This is a Kubera AI planning heuristic, not a security audit, meant to help a business gauge its shadow AI exposure and make the case for a sanctioned rollout rather than treat the risk as abstract.
The Kubera Shadow AI Exposure Filter asks four questions:
- Do you currently have any approved, sanctioned AI tool for common tasks like drafting, summarizing, or answering routine questions? If the honest answer is no, the risk that employees have already filled that gap themselves, with a tool nobody vetted, is materially higher.
- What kind of data would a typical employee be tempted to paste into a convenient AI tool? Customer records, contract terms, and financial details are the categories that turn an individually reasonable shortcut into a GDPR-relevant event the moment they're entered somewhere ungoverned.
- If an employee used an unapproved tool today, would anyone know? Shadow AI activity often blends into ordinary browser and app traffic rather than tripping an obvious alarm, so for most businesses the honest answer is no, which is itself the strongest argument for visibility over prohibition.
- Would a sanctioned alternative actually be good enough that people would prefer it to what they're using now? A policy paired with a worse tool doesn't solve the problem; a policy paired with a genuinely usable, sanctioned option does.
If the honest answers here point to real exposure, that's the case for a proper rollout, not for stepping back from AI altogether.
Where this plays out in practice
Illustrative scenario, not a specific Kubera client: a mid-size professional services firm discovers, during a routine security review, that several staff members have been using personal AI accounts to draft client correspondence and summarize meeting notes, including notes containing client financial details. Rather than banning AI tools outright, the firm rolls out a sanctioned AI assistant with a proper data processing agreement in place, scoped so staff can do the same drafting and summarizing work they were already doing, faster and with the same convenience, but inside a system the firm actually controls and can account for. In this illustrative scenario, usage of the old, unapproved tools drops sharply within weeks, not because anyone was told to stop, but because the sanctioned option was genuinely as good to use and came with none of the personal risk of being the one who caused a data incident.
FAQ
Does this mean my business should ban AI tools until we have a formal policy? The evidence suggests that's the less effective option. A ban without a usable, sanctioned alternative tends to reduce visibility into AI use rather than reduce the use itself. Providing a good, approved option tends to work better than prohibition alone.
Is shadow AI really a risk if we haven't adopted AI as a business? Yes, and this is the part worth internalizing: not adopting AI formally doesn't mean AI isn't already touching your company's data. Okta's 2026 research alone found unsanctioned AI use ranging from roughly 31% to 67% of surveyed knowledge workers depending on the country, and other 2026 industry surveys report similarly high figures.
What's the actual GDPR exposure if an employee uses ChatGPT or a similar tool for work? It depends on the specifics, and this isn't an automatic classification. Where the provider processes personal data on the business's behalf, Article 28 requires a written agreement governing that relationship, and using a tool without one is a compliance gap. Whether a specific instance also amounts to a reportable breach under Article 33 depends on a case-by-case assessment of risk to the people whose data it is, not an automatic rule, and this is worth assessing with a data protection officer or counsel rather than treated as settled either way.
How long does it typically take a business to even notice unauthorized AI use? Longer than most businesses assume, in general, since shadow AI traffic often blends into ordinary browser and app activity rather than tripping an obvious alarm. That's itself a strong argument for building visibility in deliberately rather than assuming you'd notice if it became a problem.
What's the single most effective way to reduce shadow AI risk? Providing a sanctioned, genuinely usable AI tool with proper data handling in place is one of the strongest practical measures. Research cited by the Cloud Security Alliance suggests reductions in unauthorized tool use of up to roughly 89% when employees are given an approved, functional alternative, though the exact effect will vary by organization and should not be treated as a universal benchmark.
Does this apply only to large enterprises, or does it affect small and mid-size businesses too? It affects businesses of every size. Smaller businesses often have less formal IT oversight to begin with, which if anything makes unsanctioned AI use more likely to go unnoticed, not less.
What should a first, practical step look like? Start with the exposure questions in this article's framework: whether a sanctioned tool already exists, what kind of sensitive data employees might be tempted to paste elsewhere, and whether you'd actually know if that happened today. That assessment points directly to where a sanctioned rollout should start.
Is this different from the EU AI Act's requirements? Related but distinct. GDPR governs the personal-data exposure shadow AI creates regardless of which specific AI system is involved. The EU AI Act adds separate obligations depending on how a given AI system is used, covered in more depth in our EU AI Act guide; a business addressing shadow AI risk generally needs to account for both.
Won't giving employees an approved AI tool just increase how much AI is used overall? Likely yes, and that's a reasonable outcome rather than a problem. The goal isn't minimizing AI use, it's making sure the AI use that's already happening, and will likely grow, happens inside a system your business actually controls and can account for.
How does this connect to onboarding a team to a new AI tool? Directly. A sanctioned tool only reduces shadow AI risk if people actually adopt it in practice, which is the same adoption challenge we cover in How to Onboard Your Team to AI Automation.
If you're trying to work out how much shadow AI exposure your business already has, and what a properly governed rollout would actually look like, that's exactly the kind of assessment worth doing now rather than after an incident forces the question.
