STUDY
Use of AI in HR and Corporate Training
GUIDE
Prepare your organization to comply with the new AI regulations
Stay up to date with all our latest news
Subscribe to our newsletter Stay up to date with all our latest news
September 30, 2026
CONTENT CREATED BY:

Table of contents
Artificial intelligence (AI) is part of the daily work of thousands of professionals. It is used to summarize documents, prepare presentations, analyze data, translate information, generate content, or answer questions in a matter of seconds. In fact, 1 in 3 workers who use generative AI at work do so without their company knowing, according to Deloitte’s What we do in the AI shadows study of 25,000 workers. Against this backdrop, the rapid adoption of these tools is giving rise to a phenomenon that many companies still do not have under control—or have not even identified yet: Shadow AI.
Shadow AI is the use of artificial intelligence tools or applications by employees without the organization’s approval, oversight, or knowledge. Also known as AI in the shadows, it can occur when a professional uses a personal account for an AI tool, enters corporate information into an unauthorized application, or incorporates artificial intelligence solutions into their workflows without prior approval from IT, security, or compliance teams.
The issue is not just which tool is being used. The organization may lose visibility into what information is entered into it, where that information is processed, what responses it generates, and which decisions are being made based on those outputs. The data is beginning to show the scale of the challenge: IBM’s Cost of a Data Breach 2025 report, based on security breaches experienced by 600 organizations, found that 63% still did not have AI governance policies in place or were still developing them. Among organizations that experienced AI-related security incidents, 97% lacked proper access controls.
The term Shadow AI describes any unauthorized use of artificial intelligence within a company. It is an evolution of the well-known concept of Shadow IT, but it introduces new risks because interacting with an AI tool goes beyond simply installing an application: every prompt can contain data, every response can introduce inaccurate or biased information, and every automation can end up influencing a business process.
Shadow AI can emerge even when an employee has legitimate intentions. Typically, professionals are simply trying to solve a specific need faster: summarizing a report, interpreting complex information, writing an email, preparing a sales proposal, or analyzing a document.
The risk arises when they turn to unauthorized AI tools to do so and the company does not know what data is leaving its controlled environments or how the generated responses are being used.
The ease of access to generative AI has changed the way technology is adopted in the workplace. Employees no longer need to wait for their organization to implement a new solution: they can access free or freemium tools in seconds and start using them on their own.
That is why Shadow AI in companies should not be understood solely as an employee compliance issue. In many cases, it also reveals a gap between professionals’ needs and the tools, knowledge, or answers that the organization itself makes available to them.
Some of the factors that can drive the unauthorized use of AI include:
The use of AI by employees can become Shadow AI in seemingly everyday situations:
| Situation | Example of Shadow AI | Associated risk |
|---|---|---|
| Documentation | Upload a contract or internal report to a public AI to have it summarized | Disclosure of Confidential Information |
| Marketing and Sales | Enter customer information to prepare a proposal | Loss of control over sensitive data |
| Human Resources | Using unvalidated AI to analyze information about candidates or employees | Privacy and Compliance |
| Development | Pasting corporate code into an external wizard | Intellectual Property Exhibition |
| Customer Service | View real-life cases in a personal tool | Unauthorized processing of data |
| Customer Service | View real-life cases in a personal tool | Unauthorized processing of data |
| Day-to-Day Management | Install AI extensions or assistants without IT approval | Lack of traceability and new access points |
The key, therefore, is that the same task may be legitimate, while the way it is carried out can still introduce a risk that the organization is unaware of.
The corporate impact of unauthorized AI goes far beyond losing control over which applications employees use.
One of the main risks arises when sensitive data is entered into external tools: customer information, financial documentation, intellectual property, strategies, code, internal processes, or employee information.
IBM found that one in five organizations surveyed had experienced a breach related to Shadow AI. In addition, organizations with high levels of Shadow AI recorded average breach costs that were $670,000 higher than those with low or no levels of Shadow AI.
If a company does not know which tool was used, it also becomes more difficult to determine what information was entered, what output was generated, and whether that response ultimately influenced a decision.
This lack of traceability makes oversight, audits, and the investigation of potential incidents more difficult.
Artificial intelligence tools can generate incorrect, incomplete, or out-of-context responses. When an employee uses an unauthorized solution and relies on its outputs without verifying them, the risk goes beyond data and can directly affect decision-making.
Entering documents, code, strategies, or product information into external tools can put assets that form part of the company’s proprietary knowledge at risk.
The adoption of AI also requires companies to pay attention to the responsibilities associated with its use. For this reason, technology, security, compliance, and HR teams need to coordinate to define how artificial intelligence is integrated across the organization.
Although the two concepts are related, they do not mean exactly the same thing.
| Questions | Shadow IT | Shadow AI |
|---|---|---|
| What is | Use of Unapproved Software or Technology Services | Unauthorized or unsupervised use or integration of AI |
| Main risk | Applications and data outside the control of IT | Data, prompts, responses, decisions, and automations spiraling out of control |
| Example | Using an unauthorized SaaS tool | Importing Internal Documentation into a Personal Generative AI |
The distinction is important because Shadow AI involves constant interaction between the user, the data, and the model. Therefore, it is not enough to know which applications are installed: companies also need to understand how they are being used.
Detecting Shadow AI requires looking beyond a traditional software inventory. The first step is to understand what employees are actually using AI for. Which tasks are they trying to speed up? Which tools do they need? Where are they encountering friction with corporate solutions?
From there, IT and security teams can analyze the applications and extensions being used, while HR and Learning teams can identify knowledge gaps: professionals who do not know which data they can enter into a tool, which outputs need to be reviewed, or which alternatives have been approved by the company.
This approach prevents Shadow AI detection from turning into a search for someone to blame. The goal is to identify which needs are driving employees outside the corporate framework and address them.
Trying to address Shadow AI solely by banning tools may shift the problem, but it does not necessarily eliminate the need that led professionals to use them in the first place. An effective strategy needs to combine governance, technology, and people.
Companies should establish clear, easy-to-understand policies on which tools are authorized, what they can be used for, and what types of information should not be entered into them. At the same time, they need to provide corporate alternatives that are useful enough so employees do not have to continually rely on external applications.
Technology controls are also necessary to provide visibility, access management, data protection, and traceability. But there is a third layer that is just as important: people need to know how to act.
Knowing a corporate policy does not necessarily mean knowing how to apply it when a real situation arises. An employee may know that they should not share “confidential information” and still be unsure whether they can enter part of a report, data from a sales proposal, or part of a customer conversation into an AI tool.
This is where AI literacy needs to evolve into the development of skills that can be applied in everyday work: recognizing sensitive information, assessing the risk of a tool, verifying an AI-generated response, identifying when human oversight is required, or knowing which corporate alternative to use.
Experience in other areas of cybersecurity shows the impact this approach can have. KnowBe4’s Phishing by Industry Benchmarking Report 2026 analyzed 42 million simulations involving 14.8 million users across 64,000 organizations and found that ongoing training reduced phishing susceptibility by 79% after one year. The study focuses specifically on phishing—not Shadow AI—but it demonstrates the value of sustained training in changing risk-related behaviors.
In this sense, the challenge is not simply to run a one-off awareness session on artificial intelligence. It is about turning knowledge into behaviors that can be applied when real situations arise.
Training also takes on a new dimension with the European Union Artificial Intelligence Act, or AI Act.
Article 4 establishes that providers and deployers of AI systems must take measures to support the development of AI literacy among their staff and other people who use these systems on their behalf, taking into account factors such as technical knowledge, experience, education, training, and the context in which the systems are used.
The European Commission states that this AI literacy obligation has applied since February 2025 and that supervision and enforcement began in August 2026. The regulation does not require organizations to guarantee a specific level of AI literacy for every employee, but it does reinforce the need for companies to take measures to develop the relevant knowledge and capabilities.
For HR and Learning teams, this changes the approach: it is no longer enough to teach employees what artificial intelligence is. Organizations need to consider who uses each system, what they use it for, what risks they encounter, and what knowledge they need to use it correctly.
Many organizations are addressing Shadow AI from a technology perspective: which tools to block, which access points to restrict, or which solutions to authorize. However, the unauthorized use of AI also has a human dimension. Employees need to know how to recognize when information is sensitive, understand the risks associated with using certain tools, identify when an AI-generated response should be verified, and know which corporate alternatives are available to them.
That is why reducing Shadow AI is not just about putting more controls in place, but about developing the skills people need to make better decisions in real workplace situations. AI literacy needs to evolve from one-off awareness initiatives into continuous, practical, and up-to-date upskilling that can support professionals as tools, use cases, and associated risks continue to change.
That is precisely the approach behind isEazy Skills: a corporate training solution designed to develop the skills professionals need in their day-to-day work, with specialized content in areas such as artificial intelligence and cybersecurity. Because when it comes to Shadow AI, having informed employees is important, but having professionals who are prepared and know how to act is what can truly make the difference.
Shadow AI refers to the use of artificial intelligence tools, applications, or systems by employees without the organization’s approval, supervision, or knowledge. It can range from the use of a personal generative AI account to extensions, copilots, or automations that have not been validated by the company.
Some examples include uploading corporate documents to a public AI platform, using personal accounts to analyze work-related data, installing assistants or extensions without authorization, sharing code with external tools, or using AI-generated responses in decision-making without validating them.
Pueden provocar exposición de información sensible, pérdida de trazabilidad, riesgos sobre propiedad intelectual, incumplimientos internos o regulatorios y decisiones basadas en respuestas incorrectas o no verificadas.
La prevención requiere combinar políticas claras, herramientas corporativas adecuadas, controles tecnológicos, gobierno de la IA y formación. El objetivo no debe ser únicamente bloquear aplicaciones, sino proporcionar alternativas seguras y desarrollar las competencias necesarias para que los empleados sepan utilizarlas correctamente.
Human Resources and Training can address the human aspect of the problem through AI literacy and upskilling programs. Their role is to help professionals recognize risks, understand internal policies, and apply appropriate criteria when faced with real-world situations involving the use of artificial intelligence.
Article 4 of the AI Act stipulates that providers and those responsible for deploying AI systems must take measures to support the development of AI literacy among individuals who operate or use these systems on their behalf, taking into account their knowledge, experience, training, and context of use.
GUIDE
Prepare your organization to comply with the new AI Regulations
Download guide
