September 30, 2026

Shadow AI: Why HR Should Lead the Adoption of AI

Cristina Martos

CONTENT CREATED BY:

Cristina Martos

Table of contents

Artificial intelligence (AI) is part of the daily work of thousands of professionals. It is used to summarize documents, prepare presentations, analyze data, translate information, generate content, or answer questions in a matter of seconds. In fact, 1 in 3 workers who use generative AI at work do so without their company knowing, according to Deloitte’s What we do in the AI shadows study of 25,000 workers. Against this backdrop, the rapid adoption of these tools is giving rise to a phenomenon that many companies still do not have under control—or have not even identified yet: Shadow AI.

Shadow AI is the use of artificial intelligence tools or applications by employees without the organization’s approval, oversight, or knowledge. Also known as AI in the shadows, it can occur when a professional uses a personal account for an AI tool, enters corporate information into an unauthorized application, or incorporates artificial intelligence solutions into their workflows without prior approval from IT, security, or compliance teams.

The issue is not just which tool is being used. The organization may lose visibility into what information is entered into it, where that information is processed, what responses it generates, and which decisions are being made based on those outputs. The data is beginning to show the scale of the challenge: IBM’s Cost of a Data Breach 2025 report, based on security breaches experienced by 600 organizations, found that 63% still did not have AI governance policies in place or were still developing them. Among organizations that experienced AI-related security incidents, 97% lacked proper access controls.

STUDY

Use of AI in HR and Corporate Training

How AI is being used, what’s working, and what’s really holding back its adoption.

Download the study

What is Shadow AI?

The term Shadow AI describes any unauthorized use of artificial intelligence within a company. It is an evolution of the well-known concept of Shadow IT, but it introduces new risks because interacting with an AI tool goes beyond simply installing an application: every prompt can contain data, every response can introduce inaccurate or biased information, and every automation can end up influencing a business process.

Shadow AI can emerge even when an employee has legitimate intentions. Typically, professionals are simply trying to solve a specific need faster: summarizing a report, interpreting complex information, writing an email, preparing a sales proposal, or analyzing a document.

The risk arises when they turn to unauthorized AI tools to do so and the company does not know what data is leaving its controlled environments or how the generated responses are being used.

Why is Shadow AI growing in companies?

The ease of access to generative AI has changed the way technology is adopted in the workplace. Employees no longer need to wait for their organization to implement a new solution: they can access free or freemium tools in seconds and start using them on their own.

That is why Shadow AI in companies should not be understood solely as an employee compliance issue. In many cases, it also reveals a gap between professionals’ needs and the tools, knowledge, or answers that the organization itself makes available to them.

Some of the factors that can drive the unauthorized use of AI include:

  1. The drive for productivity: professionals discover tools that allow them to complete certain tasks faster.
  2. A lack of corporate alternatives: when there is no approved solution that meets a specific need, employees look for alternatives outside the company.
  3. A lack of clear guidelines: it is not always clearly defined which tools can be used, what data can be entered into them, and for which tasks.
  4. A lack of awareness of the risks: professionals may know how to use an AI tool without understanding what happens to the information they enter into it.
  5. Training that is too generic: knowing what AI is does not necessarily mean knowing how to act in specific real-world situations.

Examples of Shadow AI in an organization

The use of AI by employees can become Shadow AI in seemingly everyday situations:

SituationExample of Shadow AIAssociated risk
DocumentationUpload a contract or internal report to a public AI to have it summarizedDisclosure of Confidential Information
Marketing and SalesEnter customer information to prepare a proposalLoss of control over sensitive data
Human ResourcesUsing unvalidated AI to analyze information about candidates or employeesPrivacy and Compliance
DevelopmentPasting corporate code into an external wizardIntellectual Property Exhibition
Customer ServiceView real-life cases in a personal tool Unauthorized processing of data
Customer ServiceView real-life cases in a personal toolUnauthorized processing of data
Day-to-Day ManagementInstall AI extensions or assistants without IT approvalLack of traceability and new access points

The key, therefore, is that the same task may be legitimate, while the way it is carried out can still introduce a risk that the organization is unaware of.

What risks does Shadow AI pose to companies?

The corporate impact of unauthorized AI goes far beyond losing control over which applications employees use.

Corporate data leakage

One of the main risks arises when sensitive data is entered into external tools: customer information, financial documentation, intellectual property, strategies, code, internal processes, or employee information.

IBM found that one in five organizations surveyed had experienced a breach related to Shadow AI. In addition, organizations with high levels of Shadow AI recorded average breach costs that were $670,000 higher than those with low or no levels of Shadow AI.

Lack of traceability

If a company does not know which tool was used, it also becomes more difficult to determine what information was entered, what output was generated, and whether that response ultimately influenced a decision.

This lack of traceability makes oversight, audits, and the investigation of potential incidents more difficult.

Errors and unverified outputs

Artificial intelligence tools can generate incorrect, incomplete, or out-of-context responses. When an employee uses an unauthorized solution and relies on its outputs without verifying them, the risk goes beyond data and can directly affect decision-making.

Intellectual property and confidentiality

Entering documents, code, strategies, or product information into external tools can put assets that form part of the company’s proprietary knowledge at risk.

Regulatory risk

The adoption of AI also requires companies to pay attention to the responsibilities associated with its use. For this reason, technology, security, compliance, and HR teams need to coordinate to define how artificial intelligence is integrated across the organization.

Shadow AI vs. Shadow IT: are they the same?

Although the two concepts are related, they do not mean exactly the same thing.

QuestionsShadow IT Shadow AI
What isUse of Unapproved Software or Technology ServicesUnauthorized or unsupervised use or integration of AI
Main riskApplications and data outside the control of ITData, prompts, responses, decisions, and automations spiraling out of control
ExampleUsing an unauthorized SaaS toolImporting Internal Documentation into a Personal Generative AI

The distinction is important because Shadow AI involves constant interaction between the user, the data, and the model. Therefore, it is not enough to know which applications are installed: companies also need to understand how they are being used.

How to detect Shadow AI in a company

Detecting Shadow AI requires looking beyond a traditional software inventory. The first step is to understand what employees are actually using AI for. Which tasks are they trying to speed up? Which tools do they need? Where are they encountering friction with corporate solutions?

From there, IT and security teams can analyze the applications and extensions being used, while HR and Learning teams can identify knowledge gaps: professionals who do not know which data they can enter into a tool, which outputs need to be reviewed, or which alternatives have been approved by the company.

This approach prevents Shadow AI detection from turning into a search for someone to blame. The goal is to identify which needs are driving employees outside the corporate framework and address them.

How to prevent Shadow AI without blocking the use of artificial intelligence

Trying to address Shadow AI solely by banning tools may shift the problem, but it does not necessarily eliminate the need that led professionals to use them in the first place. An effective strategy needs to combine governance, technology, and people.

Companies should establish clear, easy-to-understand policies on which tools are authorized, what they can be used for, and what types of information should not be entered into them. At the same time, they need to provide corporate alternatives that are useful enough so employees do not have to continually rely on external applications.

Technology controls are also necessary to provide visibility, access management, data protection, and traceability. But there is a third layer that is just as important: people need to know how to act.

From knowledge to skills: HR’s role in addressing Shadow AI

Knowing a corporate policy does not necessarily mean knowing how to apply it when a real situation arises. An employee may know that they should not share “confidential information” and still be unsure whether they can enter part of a report, data from a sales proposal, or part of a customer conversation into an AI tool.

This is where AI literacy needs to evolve into the development of skills that can be applied in everyday work: recognizing sensitive information, assessing the risk of a tool, verifying an AI-generated response, identifying when human oversight is required, or knowing which corporate alternative to use.

EBOOK

Practical Guide to Boost your Company’s Cybersecurity from Within

Download ebook

Experience in other areas of cybersecurity shows the impact this approach can have. KnowBe4’s Phishing by Industry Benchmarking Report 2026 analyzed 42 million simulations involving 14.8 million users across 64,000 organizations and found that ongoing training reduced phishing susceptibility by 79% after one year. The study focuses specifically on phishing—not Shadow AI—but it demonstrates the value of sustained training in changing risk-related behaviors.

In this sense, the challenge is not simply to run a one-off awareness session on artificial intelligence. It is about turning knowledge into behaviors that can be applied when real situations arise.

Shadow AI and the AI Act: why AI literacy is becoming more important

Training also takes on a new dimension with the European Union Artificial Intelligence Act, or AI Act.

Article 4 establishes that providers and deployers of AI systems must take measures to support the development of AI literacy among their staff and other people who use these systems on their behalf, taking into account factors such as technical knowledge, experience, education, training, and the context in which the systems are used.

The European Commission states that this AI literacy obligation has applied since February 2025 and that supervision and enforcement began in August 2026. The regulation does not require organizations to guarantee a specific level of AI literacy for every employee, but it does reinforce the need for companies to take measures to develop the relevant knowledge and capabilities.

For HR and Learning teams, this changes the approach: it is no longer enough to teach employees what artificial intelligence is. Organizations need to consider who uses each system, what they use it for, what risks they encounter, and what knowledge they need to use it correctly.

Conclusion: Stopping Shadow AI? It’s a matter of skills

Many organizations are addressing Shadow AI from a technology perspective: which tools to block, which access points to restrict, or which solutions to authorize. However, the unauthorized use of AI also has a human dimension. Employees need to know how to recognize when information is sensitive, understand the risks associated with using certain tools, identify when an AI-generated response should be verified, and know which corporate alternatives are available to them.

That is why reducing Shadow AI is not just about putting more controls in place, but about developing the skills people need to make better decisions in real workplace situations. AI literacy needs to evolve from one-off awareness initiatives into continuous, practical, and up-to-date upskilling that can support professionals as tools, use cases, and associated risks continue to change.

That is precisely the approach behind isEazy Skills: a corporate training solution designed to develop the skills professionals need in their day-to-day work, with specialized content in areas such as artificial intelligence and cybersecurity. Because when it comes to Shadow AI, having informed employees is important, but having professionals who are prepared and know how to act is what can truly make the difference.

Frequently Asked Questions About Shadow AI

What is Shadow AI?

Shadow AI refers to the use of artificial intelligence tools, applications, or systems by employees without the organization’s approval, supervision, or knowledge. It can range from the use of a personal generative AI account to extensions, copilots, or automations that have not been validated by the company.

What are some common examples of unauthorized use of AI?

Some examples include uploading corporate documents to a public AI platform, using personal accounts to analyze work-related data, installing assistants or extensions without authorization, sharing code with external tools, or using AI-generated responses in decision-making without validating them.

What are the risks associated with unauthorized AI tools?

Pueden provocar exposición de información sensible, pérdida de trazabilidad, riesgos sobre propiedad intelectual, incumplimientos internos o regulatorios y decisiones basadas en respuestas incorrectas o no verificadas.

How can a company prevent Shadow AI?

La prevención requiere combinar políticas claras, herramientas corporativas adecuadas, controles tecnológicos, gobierno de la IA y formación. El objetivo no debe ser únicamente bloquear aplicaciones, sino proporcionar alternativas seguras y desarrollar las competencias necesarias para que los empleados sepan utilizarlas correctamente. 

What role does HR play in the face of Shadow AI?

Human Resources and Training can address the human aspect of the problem through AI literacy and upskilling programs. Their role is to help professionals recognize risks, understand internal policies, and apply appropriate criteria when faced with real-world situations involving the use of artificial intelligence.

Does the AI Act require companies to train employees on artificial intelligence?

Article 4 of the AI Act stipulates that providers and those responsible for deploying AI systems must take measures to support the development of AI literacy among individuals who operate or use these systems on their behalf, taking into account their knowledge, experience, training, and context of use.