AI Integration · 2026-09-15 · 13 min

Shadow AI: two-thirds of the workforce work around the policy — the numbers, the legal position, and the way out for leadership

Michael Kaiser

Michael Kaiser

Co-Founder & Head of Systems, Vincency

When you next run a round on AI this quarter, nobody in the room will tell you what the numbers already say: your workforce is using AI. Not as an exception, as the norm. 78 percent of AI users bring their own tools rather than the sanctioned ones. 71 percent of connections to generative AI run through personal accounts. And two-thirds of office professionals admit to using AI while believing company policy forbids it. The question for 2026 is not whether your people use AI. It is whether you can see it, and what leaves the building while you cannot.

This piece collects what the 2025 and 2026 telemetry and survey data actually show, what that means legally for a German managing director since the AI Act, and the order of measures that work — which is not the order most companies instinctively reach for.

Is my workforce really using AI without approval?

Yes, with a probability that no longer needs a survey of your own. The measurements converge across five independent sources. Microsoft and LinkedIn's Work Trend Index puts 75 percent of knowledge workers on AI, with 78 percent of those bringing their own tools. LayerX's enterprise telemetry records 71 percent of all connections to generative AI tools via personal, non-corporate accounts, 58 percent of corporate-account connections bypassing single sign-on, and 89 percent of AI usage invisible to identity and access management. The PagerDuty survey of 2026, run by Wakefield Research among 1,250 office professionals, found 66 percent admitting AI use they believe violates policy, rising to 72 percent in organisations of 1,500 or more employees.

Two figures matter for the management floor specifically. Deloitte found 41 percent of senior executives had personally used an unsanctioned AI tool in the past 90 days, and Teramind's 2026 report puts executives using unapproved AI at 93 percent. The State of Shadow AI compilation adds Netskope's finding that 60 percent of the enterprise population used personal SaaS generative-AI apps in May 2025. Shadow AI is not a junior-employee problem that flows upward to your desk. It starts on your desk.

What actually leaves the building?

The short answer is: more than any file-based control sees. LayerX's Browser Security Report finds 77 percent of employees paste data into generative AI prompts, 82 percent of those paste events run through unmanaged personal accounts, and 40 percent of files uploaded to AI tools contain personal or payment data. Generative AI has overtaken every other channel for corporate-to-personal data movement and now accounts for 32 percent of it — the single largest exfiltration channel in the enterprise browser.

Harmonic Security's analysis of one million prompts and 20,000 uploaded files across more than 300 applications puts numbers on the sensitivity: nearly 22 percent of uploaded files and 4.37 percent of prompts contained sensitive content, and files — though only 13.9 percent of exposure events — carried 79.7 percent of stored credit card exposures, 75.3 percent of customer profile leaks and 68.8 percent of employee PII incidents. The same analysis found the average enterprise gaining 23 previously unknown generative AI tools in a single quarter. Netskope, cited in the Cloud Security Alliance research note of May 2026, counts 223 incidents per organisation per month of users sending sensitive data to AI applications — roughly 8.2 gigabytes monthly, and double the prior year.

PagerDuty adds the human layer: 43 percent have entered work-related correspondence into public AI tools, rising to 51 percent in the UK and 50 percent in Japan. That is contracts, personnel matters and customer complaints, pasted into systems your company has no agreement with.

Which duties land on me as managing director?

Three legal regimes attach, and none of them requires you to have approved anything. That is the point that surprises: the liability does not sit on approved usage, it sits on usage.

First, data protection. An employee pasting customer names, personnel data or correspondence into a public AI tool hands personal data to a provider with whom you have concluded no processing agreement. That is a processing under your responsibility without its contractual basis — a failure of the Article 32 security duty, with a possible notification duty under Article 33 if the exposure qualifies as a breach. The fine framework reaches 20 million euros or four percent of global annual turnover.

Second, the AI Act. Article 4 has obliged deployers since 2 February 2025 to ensure a sufficient level of AI literacy in the people using the systems. Deploying within the meaning of the regulation is use under your own responsibility, sanctioned or not — a company whose staff uses public tools untrained cannot satisfy it. Since 2 August 2026 the Article 50 transparency duties apply on top wherever AI output reaches your counterparties. The enforcement tier for these duties runs to 15 million euros or three percent of global turnover.

Third, trade-secret law. The German Trade Secrets Act protects information only while the holder took reasonable secrecy measures. Pasting confidential material into a public tool can forfeit the protection entirely — the information stops being a secret the moment your secrecy conduct no longer deserves the name. And the consequence is no longer theoretical: on 7 May 2026 CB Financial Services filed what the CSA documents as the first SEC Form 8-K triggered by unauthorised employee AI use rather than a cyberattack. IBM's breach report, cited there, prices the category at 670,000 US dollars of additional cost per incident and a median detection time of 247 days.

Why prohibition does not work

The instinctive answer — forbid it — is the one the data refutes most clearly. Of the people already using AI, 66 percent do so believing it is not permitted. Asked whether they would disclose their use, 39 percent say they would rather use AI without telling anyone — rising to 47 percent at billion-dollar organisations and 46 percent at firms of 1,500 or more employees. A third would hide it to avoid scrutiny, and 29 percent are not even sure whether use is permitted. A ban does not reduce usage. It removes visibility and adds concealment, which is strictly worse.

The positive number in the same data set is the one a managing director can act on: when organisations provision sanctioned tools, unauthorised use drops by 89 percent. Netskope's traffic data shows the mechanism live — the share of the enterprise population on personal AI accounts fell twelve points between February and May 2025, the first measured sign that sanctioned alternatives displace personal accounts rather than sit alongside them. Supply-side governance beats detection.

The way out: make it visible, sanction it, enable it

Six measures in the order that works. The sequence matters more than the individual items, because each step depends on the previous one being real.

StepWhat it means concretelyWhat it answers
1. InventoryMeasure which AI services are actually reached and via which accounts — browser telemetry or identity logs, aggregated at tool level, no individual content surveillanceYou cannot govern the 90 percent you cannot see
2. Sanctioned toolsOne or two tools under an enterprise agreement, with the processing contract concluded and training on your data switched offCuts unauthorised use by 89 percent — the single largest lever
3. One-page policyThree data classes — public, internal, never — and three rules: which account, which data class, output checked before useTurns the prohibition instinct into a usable rule
4. Article 4 enablementRole-based literacy for the people actually using AI, documented, datedThe statutory duty running since February 2025
5. Technical controlsSSO enforcement on the sanctioned tools, DLP rules on paste and upload, review of browser extensions — over half of installed extensions carry high or critical permissions and 26 percent are sideloaded, a channel network filters never seeCloses the channel policy cannot reach
6. Works council and reviewBring the Betriebsrat in before any measurement starts; quarterly review, because the tool landscape grew from roughly 317 to more than 1,550 tracked applications in five monthsLegitimacy, and a governance that keeps pace

The cost arithmetic is the closing argument. The measured delta for a shadow-AI incident is 670,000 US dollars against a median detection time of 247 days — nearly eight months of exposure you did not know about. The setup described above is a project of weeks at five figures, not quarters at six. Governance is cheaper than invisibility; the numbers say it plainly enough that the remaining question is only who in your house owns the file.

Frequently asked questions about shadow AI

Is shadow AI really widespread in our company?

Very probably yes. Microsoft and LinkedIn put 75 percent of knowledge workers on AI, 78 percent of them on their own tools rather than sanctioned ones. LayerX sees 71 percent of all connections to generative AI tools going through personal accounts, and PagerDuty has two-thirds of office professionals confirming they use AI despite believing it violates policy. In organisations of 1,500 or more that rises to 72 percent. Leadership is no better: 41 percent of senior executives told a Deloitte survey they had used an unsanctioned AI tool in the past 90 days.

May we monitor employees’ AI use?

Yes, but in a differentiated and co-determined way. Permitted and sensible is measuring tool usage: which AI services are reached through which accounts, via browser telemetry or identity logs. Not permitted is blanket content-level surveillance of individuals without cause. Where a works council exists, introducing such measurement is subject to co-determination. The proportionate variant that comes first: aggregate visibility at tool level, not employee files.

Is a written AI policy enough?

No, and the data shows why: 66 percent of users know they are violating policy, and 39 percent say they would conceal their use rather than risk a ban. A policy without a sanctioned alternative does not produce abstention, it produces invisible usage. A policy becomes effective when it regulates three things: which tools are sanctioned, which data classes may go where, and that outputs are checked before use.

What does a shadow AI incident cost us?

Three figures are solidly documented. IBM’s breach report has carried shadow AI as its own damage category since 2025, at 670,000 US dollars of additional cost per incident and a median detection time of 247 days. Under data protection law, fines run to 20 million euros or four percent of global turnover when personal data flows into public tools without a processing agreement. And since May 2026 there is a first securities-law case: CB Financial Services had to disclose an incident via Form 8-K.

Does the AI literacy duty apply even if we have not approved any AI?

Yes. Article 4 of the AI Act has applied to deployers since 2 February 2025, and deploying in the sense of the regulation is what anyone does who uses AI within their area of responsibility, sanctioned or not. The duty requires that people working with the systems have a sufficient level of AI literacy. A company whose staff uses public tools untrained and unsteered factually cannot meet it. That is the legal core of the problem: not approving is no defence, it is part of the violation.

Which data must never go into public AI tools?

Three classes: personal data without a concluded processing agreement, meaning customer names, personnel records, health data; trade secrets under the German Trade Secrets Act, because sharing them without secrecy measures forfeits protection entirely; and anything under confidentiality agreements, professional secrecy or supervisory rules, such as quotes with customer pricing, M&A documents or source code containing credentials.

What is the first step if we want to start this week?

In this order: first, make actual usage visible through browser telemetry or identity logs, aggregated at tool level. Second, sanction one or two tools under an enterprise agreement with training disabled — that alone cuts unauthorised use by 89 percent. Third, a one-page policy with three data classes and three rules. Only then is the debate about technical blocks worth having.

Sources, status and note: All figures come from the linked surveys and telemetry reports, retrieved on 15 September 2026: the Microsoft/LinkedIn Work Trend Index for adoption and bring-your-own shares; the LayerX Enterprise GenAI Security Report and Browser Security Report for personal-account shares, paste behaviour, file sensitivity and the exfiltration share; the PagerDuty/Wakefield 2026 survey (n = 1,250) for policy violation and concealment figures; Harmonic Security for the one-million-prompt analysis and the file-weighted exposure shares; the Cloud Security Alliance research note of May 2026 for the IBM breach delta, the CB Financial Services 8-K, Netskope incident volumes and the 89 percent provisioning effect; the Teramind Shadow AI Report 2026 and the Aona statistics compilation for the executive figures (93 percent Teramind, 41 percent Deloitte); the State of Shadow AI compilation for the Gartner and Netskope figures; and the AI Act for Articles 4 and 50. This article is an analysis, not legal advice.