Research Report · May 2026

State of Shadow AI 2026

A synthesis of published shadow AI research from Gartner, Microsoft, Cyberhaven, Netskope, and IBM, with ShadowLock's analysis of what it means operationally. Adoption, leakage, detection methodology, and compliance pressure: the data IT leaders and MSPs need to size and respond to the shadow AI problem. Every figure links to its publisher; the interpretation is ours.

Last updated June 15, 2026

See running statistics

Key findings

Eight numbers every IT leader should have at hand

75%

of knowledge workers use AI at work

Microsoft & LinkedIn, 2024 ↗
69%

of organizations suspect or have evidence of prohibited public GenAI use

Gartner, 2025 ↗
11%

of what employees paste into ChatGPT is sensitive data

Cyberhaven Labs ↗
39.7%

of AI interactions involve sensitive data

Cyberhaven Labs, 2026 ↗
60%

of the enterprise population used personal SaaS genAI apps in May 2025

Netskope Threat Labs, 2025 ↗
40%

of enterprises predicted to hit a shadow-AI-linked incident by 2030

Gartner, 2025 ↗
$670K

added to average breach cost where shadow AI was involved

IBM, 2025 ↗
7

genAI apps at the average organization by May 2025, up from 5.6 in February

Netskope Threat Labs, 2025 ↗

Executive summary

Where the shadow AI story stands in 2026

Shadow AI — employee use of unsanctioned AI tools — is now a mainstream operating condition rather than an emerging one. The interesting questions have moved past scale to response: which organizations have closed the governance gap, what controls are working, and where the regulatory pressure is headed.

The 2025–2026 data tells a consistent story. Adoption is settled: Microsoft and LinkedIn put 75% of knowledge workers using AI at work, with 78% of those users bringing their own tools. Leakage is meaningful: Cyberhaven puts sensitive data in 11% of what employees paste into ChatGPT and in 39.7% of AI interactions overall. And much of it is unmanaged — Netskope found 60% of the enterprise population on personal SaaS genAI apps in May 2025, precisely the traffic a network-layer control cannot tell apart from the sanctioned kind. That figure is down 12 points since February, which is the first measured sign that sanctioned alternatives are displacing personal accounts rather than merely sitting alongside them.

Compliance and insurance pressure is the dominant emerging dynamic. SOC 2 auditors, HHS reviewers, EU data protection authorities, and cyber insurance underwriters are all increasingly asking AI-specific questions. The grace period during which "we have a policy" was an acceptable answer is closing. Technical evidence of controls is becoming the new bar.

The organizations that close the gap in 2026, adding endpoint + browser detection with content classification and audit logs, will be the ones whose 2027 audits and insurance renewals go smoothly. The technical pattern is well-understood and well-documented. The remaining question is execution.

Section 1

Adoption: AI use at work is now near-universal

  • According to the Microsoft Work Trend Index, 75% of knowledge workers used AI tools at work in 2024, and 78% of them brought their own AI rather than using sanctioned tools.
  • Adoption skews highest in technology, professional services, and customer-facing roles. We have not found a published figure for per-function adoption that we would put a number against here.
  • The conversation has moved from "should employees use AI at work" to "we know they do, how do we govern it." Programs treating adoption as a Phase 0 question are 18 months behind.

Section 2

The shadow gap: most AI use is unsanctioned

  • Gartner’s March–May 2025 survey of 302 cybersecurity leaders found 69% of organizations suspect or have evidence that employees are using prohibited public GenAI. Netskope Threat Labs, measuring traffic rather than opinion, found 60% of the enterprise population using personal SaaS genAI apps in May 2025 — shadow AI by definition, though down 12 percentage points since February.
  • We have not seen a published measurement of what share of organizations have any shadow AI activity, and we are not going to assert one. What the measured research does show is that the behaviour is common enough that planning around its absence is not a defensible position.
  • Netskope puts the average organization at 7 genAI apps in use by May 2025, up from 5.6 three months earlier. ChatGPT remains the most widely reported; Claude, Gemini, Perplexity, and Copilot variants make up much of the remainder.

Section 3

Data leakage: regulated content is the bulk of what leaks

  • Cyberhaven endpoint research shows 11% of all paste content into ChatGPT-class tools contains sensitive data, and 27% of data shared with AI tools in 2024 was confidential-classified.
  • The top three categories by frequency: customer PII, source code (in engineering organizations), and credentials. The top three by severity: credentials, PHI (in healthcare), and MNPI (in public companies).
  • Industry variation matters. In healthcare, PHI dominates. In financial services, account and transaction data leads. In tech, source code leads. Build classifier priorities accordingly.

Section 4

Detection: network-only is no longer sufficient

  • Network-layer detection sees the destination, not the account or the content. Netskope puts 60% of the enterprise population on personal SaaS genAI apps, which resolve the same domains as corporate ones, and Cyberhaven puts about a third of ChatGPT usage on personal accounts specifically. We are not aware of a published study quantifying total network-only miss rate, and we no longer cite one.
  • A CASB or proxy alone is insufficient. Endpoint and browser visibility, the layers where pastes actually happen, has gone from optional to baseline.
  • For multi-organization or MSP environments, multi-tenant architecture is structural, not a configuration option.

Section 5

Compliance: auditors and underwriters are catching up

  • SOC 2 Type II audit scopes increasingly include AI-specific control questions, and the criteria most often invoked are CC6.1 (logical access), CC7.2 (system monitoring), and CC9.2 (vendor management). The “55% of audits” figure carried in earlier editions had no survey behind it and has been removed.
  • AI control questions are appearing on a growing number of cyber applications and AI supplements, though practice varies by carrier and some do not ask at all yet. Brokers frequently draw an analogy to the arrival of MFA requirements, first optional, then expected, then required. That is a forecast about direction of travel, not an established pattern, and it should be read as one.
  • HHS HIPAA risk assessments are starting to include AI as a category. EU data protection authorities are publishing AI-specific guidance under existing GDPR. The regulatory direction is converging.

Section 6

The state of controls: policy without enforcement is the norm

  • Gartner expects more than 40% of enterprises to experience a security or compliance incident linked to unauthorized shadow AI by 2030. Many organizations have a written policy; far fewer have technical enforcement behind it.
  • The gap between a written AI policy and evidence that it is enforced is the pattern we see most often in customer conversations. We are describing our own experience here, not a surveyed finding.
  • Organizations that close the gap, adding endpoint + browser detection with content classification and audit logs, move from "we have policies" to "we have evidence." That difference matters more every quarter.

What to do about it

The working response pattern

The response pattern ShadowLock recommends, in the order we would sequence it. This is our operational opinion rather than a benchmarked result:

  1. Publish a written AI acceptable use policy. The cheapest, fastest control. Use the free template as a starting point.
  2. Deploy endpoint + browser detection with content classification on paste. ShadowLock's shadow AI detection covers all the layers from a single deployment.
  3. Block sensitive data submissions on the highest-severity classifiers first: credentials, PHI, regulated PII. AI DLP with per-classifier policy.
  4. Produce audit logs that map to your compliance frameworks. SOC 2, HIPAA, GDPR, and cyber insurance underwriters all increasingly ask for this evidence.

In our experience this sequence gets a mid-market organization from "policy without enforcement" to "policy with audit evidence" inside a quarter, though we have not benchmarked that across a sample. MSPs can extend the same pattern across their entire client base via multi-tenant AI governance.

Methodology

How this report was made

This report synthesizes published research from primary authoritative sources. Every statistic in it comes from a named external publisher and links to that publisher's own page. The sizing, sequencing, and operational recommendations are ShadowLock's editorial analysis of that research.

This report contains no ShadowLock first-party telemetry. Earlier editions described it as incorporating aggregated customer telemetry. It did not display any, and a claim to hold data without a sample size, an observation window, or a stated methodology is not a claim a reader can evaluate — so we removed it rather than dress it up. If we publish first-party numbers in a future edition, they will arrive with a sample size, a date range, a methodology, and their limitations stated up front.

External sources are cited as published. We do not reanalyze or recompute the underlying figures. Where multiple sources report a similar statistic with different methodologies, we cite the most commonly referenced figure and note material methodological variation.

Where two publishers report a similar measure from different populations, we cite each separately rather than blending them into a single number. Figures that we could not trace to a named publisher have been removed from this edition.

For more detail on how this content is produced and sourced, see our editorial standards.

Frequently asked

About the report

What is the State of Shadow AI 2026 report?

It is a ShadowLock-published synthesis of the most widely cited shadow AI research from 2025–2026, drawing on Gartner, Microsoft, Cyberhaven, Netskope, IBM, and NIST. Every statistic comes from one of those named publishers and links to its source. The analysis, sequencing, and recommendations are ShadowLock's. The report contains no first-party ShadowLock telemetry.

How is this report different from the blog statistics post?

The report is the flagship synthesis intended for citation and download. The blog statistics post is the granular running record of individual statistics, refreshed quarterly. The two reference each other and stay in sync.

Are the figures in this report independently verifiable?

Yes. Every figure in this report comes from a named external publisher and links to that publisher's own page, so you can check any of them directly. We do not publish unattributed statistics, and this edition contains no first-party ShadowLock data.

Can I cite this report in my own publications?

Yes, freely. Standard journalistic citation is welcome. Direct quotation should reference shadowlock.io/reports/state-of-shadow-ai-2026 as the source. We will provide additional materials (charts, raw data extracts) on request.

How often is the report updated?

Major updates are published annually. Statistic-level updates happen as new authoritative research drops. The "Last updated" date at the top of the report reflects the most recent revision.

How can ShadowLock help close the gaps this report describes?

ShadowLock is the AI governance platform built to close the technical control gap identified throughout this report. Endpoint and browser detection, content classification on paste, blocking of sensitive data submissions, and audit logs that map to SOC 2, HIPAA, and GDPR controls, all in a single multi-tenant deployment.

Close the shadow AI gap

ShadowLock is the AI governance platform built to close the technical control gap this report describes.