Skip to content

Executive Summary

The use of unapproved AI tools in the workplace, termed shadow AI, poses risks to sensitive data and security. Employees often utilize these tools to expedite tasks, such as summarizing email threads, without employer authorization, leading to potential exposure of confidential information. The UK’s National Cyber Security Centre defines shadow AI as AI technology not captured in organizational systems and processes. A Microsoft study from 2025 indicated that 71% of UK employees had used unapproved AI tools at work. Shadow AI extends beyond chatbots to include various applications like browser extensions, meeting bots, and integrated app features. Concerns for IT and security teams stem from the fact that inputting data into public AI tools leaves company control, potentially leading to data breaches or intellectual property loss. Furthermore, AI agents introduce security vulnerabilities, and research suggests shadow AI is linked to data breaches, with organizations using it facing higher breach costs.

Facts Only

* Shadow AI is defined as the use of AI technology not captured in an organization’s approved systems and processes.
* A Microsoft study published in 2025 found that 71% of UK employees surveyed had used unapproved AI tools at work.
* Shadow AI can manifest as chatbots, browser extensions, meeting-notes bots, or integrated app features.
* Entering data into public AI tools leaves the data outside of company control.
* AI assistants and agents present security vulnerabilities that can be exploited by attackers.
* IBM’s 2025 Cost of a Data Breach research linked one in five organizations to a breach involving shadow AI.
* Organizations with significant shadow AI paid approximately $670,000 more per breach.
* Ninety percent of survey respondents were worried about AI using their data without consent.
* Recommended safety steps include asking for approved tools, using work accounts, checking privacy settings, and registering use cases.

Full Take

The narrative frames the conflict as a tension between individual efficiency and organizational security governance, suggesting that shadow AI is a systemic failure enabled by the ubiquity of new technology rather than isolated employee misconduct. The pattern involves normalizing access to powerful tools (like search and email integration) where convenience overshadows explicit control mechanisms, leading to an environment ripe for unapproved behavior. The shift from viewing AI as a novelty to understanding it as a potential vector for data leakage demands a re-evaluation of what constitutes "safe" work practice. The implication is that security is not just about preventing external breaches but also managing internal, emergent risks created by adopting unvetted technologies. The cost analysis reinforces the idea that the lack of policy creates a significant, measurable liability for the organization. What is being navigated here is the friction between decentralized, rapid innovation and centralized, risk-averse control structures.
* Bridge Questions: If organizations focus on providing superior, approved enterprise solutions, how can they effectively incentivize employees to adopt those systems over shadow practices? What mechanisms can be implemented to ensure that the process of seeking approval for AI tools is as efficient and accessible as the act of using them? How should organizational cultures shift to prioritize proactive security education over reactive enforcement when dealing with emergent technologies?

From the original · Malwarebytes Labs

Using an AI chatbot, assistant, or browser to speed up your work is tempting, but doing it without your employer’s knowledge can put sensitive data at risk. You’re swamped, so you paste a long email thread into a free chatbot and ask for a summary.
Read the full story at malwarebytes.com

Sentinel — Human

Confidence

The text reads like legitimate, well-researched organizational advice on corporate AI risk, effectively blending factual data with practical security recommendations.

Signals Detected
low severity: Variable sentence length and natural flow interrupted by direct advice structure.
low severity: Logically structured progression from problem definition (Shadow AI) to impact (security/cost) to solution (safeguards).
low severity: Citations of specific bodies (NCSC, Microsoft, IBM) and specific statistics suggest research-based sourcing.
low severity: The structure mimics established cybersecurity advisory patterns rather than pure LLM narrative flow.
Human Indicators
Presence of specific, layered advice (e.g., 'Ask for an approved tool,' 'Use your work account') demonstrating insider/contextual knowledge.
The integration of multiple, distinct statistical claims from named organizations makes it less likely to be a pure LLM fabrication.
Shadow AI explained: The work shortcut that could leak your company’s secrets | Huntaegis