Skip to content

Your Team Is Already Using AI. Here's Why Shadow AI is a Leadership Problem

Why shadow AI is an adoption signal, and what leaders can do about it

 

DIRECT ANSWER

Employees use unapproved AI tools because approved options are unclear, slow, or missing, not because they want to break the rules. That makes shadow AI a leadership and change management problem first. Security controls matter, but lasting adoption takes a clear destination, a reason that connects to the work, and less friction than the workaround.

What Is Shadow AI, and How Common Is It?

Shadow AI is the use of artificial intelligence tools that an organization has not approved, secured, or even noticed. Think of an employee pasting a client proposal into a free chatbot to tighten the language, or a manager recording meetings with a personal AI notetaker. It is the AI-era cousin of shadow IT, and it is everywhere.

In a 2026 global study of 3,750 enterprise leaders and workers, WalkMe found that at least 45% of workers used unsanctioned AI tools in the past 30 days, and 36% did so with confidential data.1 Another 34% said they do not know which AI tools their employer has approved.1

Leaders also tend to underestimate how much of this is happening. McKinsey found that three times as many employees were using generative AI for at least 30% of their daily work as their executives estimated.2

That 34% figure deserves a second look. A third of workers cannot tell you what is allowed. That is not a rebellion. That is a communication gap.

Why Does Treating Shadow AI as Only a Security Problem Fall Short?

The instinctive response is to lock it down: block the domains, send the policy memo, add a line to the acceptable use agreement. Some of that is necessary. Sensitive data flowing into unvetted tools is a real risk, and it deserves real controls.

But blocking alone treats the symptom. The OneTrust 2026 AI-Ready Governance Report, a survey of 1,200 senior decision-makers across eight countries, found that 33% of organizations have seen employees use unapproved AI because approved tools or processes were not available quickly enough.3 Those employees were not trying to get around security. They were trying to get their work done.

When you block a tool without offering a better path, the work does not stop. It moves to a personal phone. The risk gets harder to see, not smaller.

There is a trust cost, too. WalkMe found that 88% of executives believe their employees have adequate tools, while only 21% of workers agree.1 A lockdown-first message lands on the wrong side of that gap. It tells people leadership sees them as the threat instead of the talent.

What Are Employees Actually Waiting For?

In a July 2026 piece for Fast Company, Jenny Fernandez and Tomer Hason argued that leaders should stop asking employees to adopt AI and start guiding them toward it.4 Their framing points to three gaps. Each one is a leadership responsibility, not an IT ticket.

The Gap What It Looks Like What Leadership Provides
Destination "We have Copilot. Now what?" People do not know what good AI use looks like in their specific role. Role-specific use cases, real examples, and shared prompt libraries
Meaning AI feels like a mandate or a threat to someone's job, not an upgrade to their skills. A clear story about how AI makes their work better and their expertise more valuable
Friction The approved tool is harder to reach than the free one in the next browser tab. AI built into the tools and workflows people already use every day

Gallup's data backs this up. Only 25% of U.S. employees say their organization has communicated a clear plan for integrating AI.5 And employees whose organizations do provide a clear plan report engagement 15 points higher than those without one.6

How Does Manager Support Change AI Adoption?

If there is one lever that moves adoption more than any other, it is the manager. In Gallup's May 2026 data, only 36% of employees in organizations integrating AI strongly agree that their manager supports their team's use of AI.5 The employees who do have that support are 1.7 times more likely to use AI frequently and 7.4 times more likely to say AI helps them do their best work.5

That matches what we see when we help clients roll out Microsoft 365 Copilot. The licenses are rarely the hard part. The teams that get real value have a leader who uses the tool visibly, shares what worked, and gives people permission to experiment on real work. The teams that stall usually got a login and a link to a training video.

There is also a confidence gap to close. WalkMe found that 61% of executives trust AI for complex, business-critical decisions, compared to just 9% of workers.1 Nearly half of employees in McKinsey's research said they want more formal training, and more than a fifth reported minimal to no support.2 Your people are not dragging their feet. Many of them are waiting for someone to show them how.

What Should Leaders Do About Shadow AI?

You do not need a massive transformation program to start. You need a plan people can see. Here is where we recommend beginning:

  1. Find out what is already in use. Ask before you audit. A short, no-blame survey about which AI tools people use and for what tells you where the demand is. Treat the answers as a roadmap, not a list of offenders.
  2. Pick an approved path and make it the easy one. Choose tools that fit your environment and security requirements, then put them where people already work. If Microsoft 365 is your backbone, Copilot inside Outlook, Teams, and Word beats a separate portal nobody remembers to open.
  3. Publish a destination for each role. Give every team five to ten concrete use cases: a better proposal draft, a faster customer reply, a cleaner monthly report. Show what good looks like.
  4. Write guardrails people can actually follow. A one-page summary of what data can and cannot go into AI tools beats a 20-page policy no one reads. Our guides on setting AI guardrails and policy and what HR, Legal, and IT need to agree on before an AI rollout walk through the details.
  5. Equip managers first. Train managers before their teams, give them talking points, and ask them to share one real win each week. Our 30-day Copilot training plan is a practical place to start.
  6. Measure adoption, not logins. Track who uses the approved tools, for what, and what it saves. Revisit the numbers every quarter and adjust.

Notice where security shows up in that list: everywhere, and nowhere first. Guardrails matter. They just work a lot better when people have a reason to stay inside them.

Where Does AI Adoption Fit in the Technology Maturity Model?

Sentry's Technology Maturity Model (TMM) maps four stages every business moves through: Operate, Secure, Integrate, and Innovate. Real AI adoption lives in the Innovate stage, where technology stops simply supporting the business and starts changing how it works. (We walked through what that looks like in practice in How AI Workflows Are Changing Businesses.)

  • Operate: Stable, supported systems your team can rely on.
  • Secure: The identity controls, data protection, and policies that make an approved AI path safe to offer.
  • Integrate: Connected data, so AI has something useful to work with.
  • Innovate: AI woven into daily workflows, with people who know how and why to use it.

Shadow AI is what happens when employees try to jump straight to Innovate on their own because the organization has not built the path yet. The good news is that energy is an asset. A team that is already experimenting is a team that is ready to move. Leadership's job is to give it direction.

Ready to Lead the AI Conversation Instead of Chasing It?

Your team has already voted on AI with their browsers. The question is whether leadership will meet them there.

Sentry Technology Solutions helps business leaders turn scattered AI experiments into a secure, adopted strategy, from governance and Copilot readiness to manager enablement and AI workflows built around how your team actually works. If you want to know where your organization stands today, start with a TMM Assessment.

Schedule a Discovery Call | Start with a TMM Assessment

Frequently Asked Questions About Shadow AI and AI Adoption

What is shadow AI?

Shadow AI is any artificial intelligence tool employees use for work without the organization's approval or oversight, such as free chatbots, browser extensions, or personal AI notetakers. It usually starts with good intentions: people want to work faster, and the approved options are unclear or unavailable.

Is shadow AI a security risk?

Yes. When employees paste client data, financials, or internal documents into unvetted tools, that information can leave your control. WalkMe found that 36% of workers who used unsanctioned AI did so with confidential data.1 The most effective fix pairs clear data guardrails with an approved tool that is easier to use than the workaround.

Should we ban public AI tools like ChatGPT?

A ban without an alternative tends to push AI use onto personal devices, where you have even less visibility. A better approach is to restrict what data can go into public tools, offer a sanctioned option that fits your security requirements, and explain the reasoning so people understand the line.

How do we get employees to actually use approved AI tools?

Close three gaps: show each role what good use looks like (destination), connect AI to work people care about (meaning), and put the tools inside the apps they already use (friction). Then make sure managers are visibly using and supporting the tools themselves.

What role do managers play in AI adoption?

A big one. Gallup found that employees whose managers actively support AI use are 1.7 times more likely to use it frequently and 7.4 times more likely to say it helps them do their best work.5 Training managers first is one of the fastest ways to move adoption across a team.

How does AI adoption relate to the Technology Maturity Model?

AI adoption is the heart of the TMM's Innovate stage, but it depends on the stages before it. Stable operations, strong security, and integrated data are what make it safe and useful to hand employees powerful AI tools. A TMM Assessment shows which foundations are in place and which need attention first.

References

  1. WalkMe. "State of Digital Adoption 2026." Press release, April 9, 2026. Online survey of 3,750 respondents (1,700 senior leaders and 2,050 office and hybrid workers) at enterprises with 1,000+ employees across 14 countries, conducted by an independent research agency. https://www.globenewswire.com/news-release/2026/04/09/3270721/0/en/Enterprises-Lose-51-Workdays-Per-Employee-to-Technology-Friction-Annually-Despite-Record-AI-Investment-WalkMe-Global-Study-of-3-750-Finds.html
  2. McKinsey & Company. "Superagency in the Workplace: Empowering People to Unlock AI's Full Potential at Work." January 28, 2025. Survey of 3,613 employees and 238 C-level executives, conducted October and November 2024. https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/superagency-in-the-workplace-empowering-people-to-unlock-ais-full-potential-at-work
  3. OneTrust. "OneTrust 2026 AI-Ready Governance Report." Press release, September 14, 2026. Survey of 1,200 senior business decision-makers in the U.S., Canada, U.K., France, Germany, Spain, Australia, and Singapore, conducted by Sapio Research. https://www.globenewswire.com/news-release/2026/09/14/3361166/0/en/onetrust-research-86-of-organizations-experienced-ai-related-incidents-yet-few-slowed-deployment.html
  4. Fernandez, Jenny, and Tomer Hason. "Stop Asking Employees to Adopt AI." Fast Company, July 5, 2026. https://www.fastcompany.com/91568873/stop-asking-employees-to-adopt-ai
  5. Gallup. "Global Indicator: Artificial Intelligence." U.S. employee survey data through May 2026. https://www.gallup.com/699797/indicator-artificial-intelligence.aspx
  6. Ewen, Lara. "AI Use May Improve Engagement, but Only Under the Right Conditions." HR Dive, July 29, 2026, reporting on Gallup workplace research. https://www.hrdive.com/news/ai-use-may-improve-engagement-but-only-under-the-right-conditions/826425/