Things that make us go hmmm…
The AI you can’t see is still at work
Nu U Staff | June 2026
Over the past few months, several major AI reports have been released that, taken together, might be cause to go hmmm... Verizon found that frequent employee use of unapproved AI tools (aka “shadow AI”) tripled in a year. Okta found that 52% of surveyed knowledge workers had used AI without approval, despite 95% of executives reporting that they were confident employees were using AI responsibly. At the same time, BCG and Ramp reported that workplace AI use and company spending are climbing again. Two things are clear: Organizations are making more AI available, and employees are still going off-menu. Shadow AI use is growing even as organizations provide more technology and access, and the company-sponsored tools themselves become more capable. So, what keeps driving employees into the shadows, and what does that mean for managers living in the tension between compliance and practice?
Contrary to some of the clickable rhetoric, the use of non-approved company technology isn’t new, and it didn’t start with AI. Shadow IT has been studied for years, with research repeatedly linking it to gaps between the tools organizations provide and what the work requires, as well as slow development and procurement processes. Similarly, research suggests shadow AI spreads “through curiosity, productivity boosts, and peer influence.” Additionally, it typically isn’t done maliciously or by people who don’t understand the technology. According to a recent report in CIO: “Often, the employees who best understand the capabilities of gen AI are also the most likely to bend or break organizational rules governing its use … A recent LexisNexis report found that 74% of AI-trained employees use unauthorized AI tools, versus only 17% of untrained employees.”
Just because it isn’t nefarious, doesn’t make it harmless. Shadow AI is shadow IT with a self-replicating superpower. As AWS cyber-security expert Aditya Patel wrote for Cloud Security Alliance, “Every prompt, upload, or query is a potential breach. The problem isn’t just volume—it’s velocity. AI’s self-learning nature means risks compound faster.” The Okta research found that users of unapproved tools shared internal messages, HR information, and confidential company documents. That’s not something any leader wants to see happen on their watch.
Managers may not choose the tools, set the rules, or control the approval processes, but they sit directly in the tension of what has now become a persistent management problem with no easy answers. Enterprises can’t deploy new policies and fixes fast enough to combat today’s shadow AI, particularly when new models are entering the chat and changing the game daily. Want to bury your head in the sand and pretend it doesn’t exist? It’s too consequential to shrug off. Want to shut it all down and micro-manage your team’s use? You’re in for a long game of whack-a-mole you probably can’t win. As CTO Magazine recently affirmed: “Most organizations respond to shadow AI risks by trying to restrict it …But this approach rarely works … Trying to stop this does not make it go away; it just makes it harder to see.”
Instead, some leaders are working to bring what’s in the shadows into the light, using sunlight AI approaches (“enable, not prohibit”) or conducting regular audits or anonymous AI censuses (establishing “no judgment” ground rules, then asking people to share without penalty the tools they use for work, including any they use on their own with personal accounts). Interventions like these can surface the motivators behind the shadow usage. Are people excited about what’s new and shiny, scared of falling behind, or is something else going on? Those are different problems, and they deserve different conversations.
And the key word here is conversations. Because shadow AI is not just a tech story, it’s a people story. If you’re leading people, teams, or learning, a few gut-check questions are worth sitting with now: Do we know how, where, and why we’re using AI (approved and unapproved)? What’s motivating use? When people say an approved tool cannot do the job, do we have a practical way to test that? Which issues can be worked through on the team, and which need to travel upward? What hard conversations have we been avoiding that we need to have to drive real change?
SHRM notes that experts are converging on a better way forward, relying on “employee education, detailed acceptable use policies, and governance to mitigate the risks of shadow AI while still capitalizing on its advantages.” That makes intuitive sense. But surfacing what’s in the shadows takes courage on all sides. Shadow AI now sits in a messy middle. The new models and tools continue to be exciting enough that people feel they have to try them and contentious enough that they may hesitate to admit it. Meanwhile, policy and practice norms remain unclear enough that managers may not know whether to invite the conversation or avoid it. In that environment, silence can look prudent on all sides. But when the personal risk is in speaking up and the organizational risk is in everyone staying quiet, shadow AI has exactly the room it needs to grow. That’s a hmmm worth watching in your organization.