ACADEMY
All posts

Shadow AI at Work: What Founders Should Actually Do About Unauthorized AI Tools

66% of employees have used AI tools at work they believed violated company policy, and 88% have pasted work data into public models. Here's what the 2026 survey data says actually stops it.

Two-thirds of office workers have used an AI tool at work that they believed violated company policy, according to PagerDuty's 2026 Shadow AI Workplace Survey. Not "tried once." Used, knowingly, against a policy they knew existed. If you run a company with more than a handful of people, this isn't a hypothetical risk you're managing for someday. It's already happening inside your Slack, your inbox, and your CRM, and the honest starting point for any founder is to assume it's happening on your team right now too.

What "shadow AI" actually means

Shadow AI is the AI version of shadow IT: employees adopting tools the company hasn't reviewed, approved, or secured, because the sanctioned option is slower, worse, or doesn't exist. It's not usually malicious. Someone hits a wall in their workflow, remembers that ChatGPT solved a similar problem for them personally, and pastes in whatever gets the job done fastest. PagerDuty's survey found 88% of respondents have shared work-related information with a public AI tool like ChatGPT, Claude, or Gemini, and 89% of workers who use AI at work say they first encountered it personally, before their employer ever introduced it. The tool isn't new to them. Your policy is.

What's actually leaking

The specifics matter more than the headline number, because "AI usage" and "data exposure" are two different problems with two different fixes.

Source: PagerDuty, "2026 Shadow AI Workplace Survey" — 88% of respondents reported sharing at least one of these categories with a public AI tool.
Source: PagerDuty, "2026 Shadow AI Workplace Survey" — 88% of respondents reported sharing at least one of these categories with a public AI tool.

Emails and correspondence top the list at 43%, followed by meeting notes and summaries at 40%. Those feel low-stakes until you remember what's actually in a meeting note: pricing discussions, a candidate's salary expectations, a customer's complaint about a bug that hasn't shipped a fix yet. Customer data landed at 34%, and financial or confidential documents at 31%, per the same PagerDuty report. None of that data disappears after the prompt. Depending on the tool's terms and the account tier, it can be retained, used for model training, or sit in a vendor's logs indefinitely, outside your data processing agreements, outside your cyber insurance policy's assumptions, and outside your ability to delete it if a customer asks you to.

Why the gap exists: leadership already believes the pitch

The uncomfortable finding underneath the security story is a trust and communication gap, not a discipline problem. RSM's 2026 Middle Market AI Survey found 86% of organizations have partially or fully integrated AI, with 97% of leaders reporting satisfaction with their AI investments. But the same survey found 85% of respondents agree executive leadership is more enthusiastic about AI than employees are, and PagerDuty's data adds a sharper edge to that: 81% of employees believe leadership operates under a different, looser set of AI rules than everyone else. Whether or not that perception is fair at your company, it's the perception doing the damage. A policy that isn't visibly followed at the top reads as decoration, and employees route around decoration.

Why banning it doesn't work

The instinctive founder response is to write a policy that says "no unauthorized AI tools" and consider the problem handled. PagerDuty's data suggests that's closer to theater than a fix: 66% of workers used an unauthorized tool anyway, and among those who got caught, only 48% faced any formal consequence. A rule with weak enforcement and no faster sanctioned alternative doesn't stop the behavior, it just stops you from seeing it. This is the same lesson covered in why 95% of AI pilots fail to show ROI: the tools that get adopted and stick are the ones wired into the workflow people already use, not the ones bolted on next to it. Shadow AI is what happens when you skip that step entirely and hope a memo does the wiring for you.

What actually works: give people a sanctioned tool that's just as good

The fix that shows up across the research isn't stricter enforcement, it's supply. Employees default to unapproved tools because nobody gave them an approved one that does the same job. That means picking a real sanctioned option and rolling it out with the same urgency you'd give any other business-critical tool, and for most teams that comes down to two paths depending on how sensitive the data is.

ApproachBest forExampleData control
Enterprise-tier hosted AITeams that need it running today, minimal setupChatGPT Enterprise, Claude for EnterpriseVendor contractually excludes your data from training; still leaves your org
Self-hosted, open-sourceRegulated or highly sensitive data, engineering capacity availableOllama + Open WebUI, or LibreChatData never leaves your infrastructure

The self-hosted path costs nothing in licensing and runs entirely inside your own network: Ollama serves open models like Llama or Mistral locally, and Open WebUI gives your team the same familiar chat interface as ChatGPT on top of it, so the switch doesn't feel like a downgrade. We walk through the actual setup, and what it really costs in engineering time versus a paid seat, in self-hosting a free ChatGPT alternative with Ollama and Open WebUI. For teams handling regulated data (health records, financial statements, anything under an NDA that a public model's terms of service wouldn't survive), that's the more defensible starting point than an enterprise contract you're trusting to hold.

A founder's four-step response, this week

  • **Audit before you write a single policy line.** Ask your team, in a low-stakes way, which AI tools they already use to get work done. You cannot govern a behavior you haven't measured, and a blunt "have you used unauthorized AI" survey will just teach people to lie better.
  • **Pick and fund a sanctioned tool that's genuinely as fast as what people are already using.** If the approved option requires three extra steps or a slower login flow, you have not solved the problem, you have added friction on top of it.
  • **Draw a bright line on data categories, not tool names.** "Never paste customer PII or unreleased financials into any tool that isn't on this list" is enforceable. "Don't use unauthorized AI" isn't, because nobody agrees on what counts as authorized.
  • **Have leadership visibly use the sanctioned tool first.** The 81% who believe leadership plays by different rules are watching for evidence, not a memo.

The real risk isn't the AI, it's the blind spot

Shadow AI isn't a story about employees being reckless. It's a story about supply lagging demand: people found a faster way to work, and leadership didn't catch up fast enough to give them a safe version of it. The RSM data shows the appetite is already there across the middle market, 86% adoption and rising. The founders who get ahead of this aren't the ones who ban AI the hardest, they're the ones who make the sanctioned option good enough that shadow AI stops being worth the risk. That's the exact governance muscle we build in AI Leadership for Founders: how to roll out AI tools your team actually wants to use, with the guardrails already built in instead of bolted on after the first incident.

Go deeper

AI Leadership for Founders