DIRECT ANSWER
Employees use unapproved AI tools because approved options are unclear, slow, or missing, not because they want to break the rules. That makes shadow AI a leadership and change management problem first. Security controls matter, but lasting adoption takes a clear destination, a reason that connects to the work, and less friction than the workaround.
Shadow AI is the use of artificial intelligence tools that an organization has not approved, secured, or even noticed. Think of an employee pasting a client proposal into a free chatbot to tighten the language, or a manager recording meetings with a personal AI notetaker. It is the AI-era cousin of shadow IT, and it is everywhere.
In a 2026 global study of 3,750 enterprise leaders and workers, WalkMe found that at least 45% of workers used unsanctioned AI tools in the past 30 days, and 36% did so with confidential data.1 Another 34% said they do not know which AI tools their employer has approved.1
Leaders also tend to underestimate how much of this is happening. McKinsey found that three times as many employees were using generative AI for at least 30% of their daily work as their executives estimated.2
That 34% figure deserves a second look. A third of workers cannot tell you what is allowed. That is not a rebellion. That is a communication gap.
The instinctive response is to lock it down: block the domains, send the policy memo, add a line to the acceptable use agreement. Some of that is necessary. Sensitive data flowing into unvetted tools is a real risk, and it deserves real controls.
But blocking alone treats the symptom. The OneTrust 2026 AI-Ready Governance Report, a survey of 1,200 senior decision-makers across eight countries, found that 33% of organizations have seen employees use unapproved AI because approved tools or processes were not available quickly enough.3 Those employees were not trying to get around security. They were trying to get their work done.
When you block a tool without offering a better path, the work does not stop. It moves to a personal phone. The risk gets harder to see, not smaller.
There is a trust cost, too. WalkMe found that 88% of executives believe their employees have adequate tools, while only 21% of workers agree.1 A lockdown-first message lands on the wrong side of that gap. It tells people leadership sees them as the threat instead of the talent.
In a July 2026 piece for Fast Company, Jenny Fernandez and Tomer Hason argued that leaders should stop asking employees to adopt AI and start guiding them toward it.4 Their framing points to three gaps. Each one is a leadership responsibility, not an IT ticket.
| The Gap | What It Looks Like | What Leadership Provides |
|---|---|---|
| Destination | "We have Copilot. Now what?" People do not know what good AI use looks like in their specific role. | Role-specific use cases, real examples, and shared prompt libraries |
| Meaning | AI feels like a mandate or a threat to someone's job, not an upgrade to their skills. | A clear story about how AI makes their work better and their expertise more valuable |
| Friction | The approved tool is harder to reach than the free one in the next browser tab. | AI built into the tools and workflows people already use every day |
Gallup's data backs this up. Only 25% of U.S. employees say their organization has communicated a clear plan for integrating AI.5 And employees whose organizations do provide a clear plan report engagement 15 points higher than those without one.6
If there is one lever that moves adoption more than any other, it is the manager. In Gallup's May 2026 data, only 36% of employees in organizations integrating AI strongly agree that their manager supports their team's use of AI.5 The employees who do have that support are 1.7 times more likely to use AI frequently and 7.4 times more likely to say AI helps them do their best work.5
That matches what we see when we help clients roll out Microsoft 365 Copilot. The licenses are rarely the hard part. The teams that get real value have a leader who uses the tool visibly, shares what worked, and gives people permission to experiment on real work. The teams that stall usually got a login and a link to a training video.
There is also a confidence gap to close. WalkMe found that 61% of executives trust AI for complex, business-critical decisions, compared to just 9% of workers.1 Nearly half of employees in McKinsey's research said they want more formal training, and more than a fifth reported minimal to no support.2 Your people are not dragging their feet. Many of them are waiting for someone to show them how.
You do not need a massive transformation program to start. You need a plan people can see. Here is where we recommend beginning:
Notice where security shows up in that list: everywhere, and nowhere first. Guardrails matter. They just work a lot better when people have a reason to stay inside them.
Sentry's Technology Maturity Model (TMM) maps four stages every business moves through: Operate, Secure, Integrate, and Innovate. Real AI adoption lives in the Innovate stage, where technology stops simply supporting the business and starts changing how it works. (We walked through what that looks like in practice in How AI Workflows Are Changing Businesses.)
Shadow AI is what happens when employees try to jump straight to Innovate on their own because the organization has not built the path yet. The good news is that energy is an asset. A team that is already experimenting is a team that is ready to move. Leadership's job is to give it direction.
Your team has already voted on AI with their browsers. The question is whether leadership will meet them there.
Sentry Technology Solutions helps business leaders turn scattered AI experiments into a secure, adopted strategy, from governance and Copilot readiness to manager enablement and AI workflows built around how your team actually works. If you want to know where your organization stands today, start with a TMM Assessment.
Schedule a Discovery Call | Start with a TMM Assessment
Shadow AI is any artificial intelligence tool employees use for work without the organization's approval or oversight, such as free chatbots, browser extensions, or personal AI notetakers. It usually starts with good intentions: people want to work faster, and the approved options are unclear or unavailable.
Yes. When employees paste client data, financials, or internal documents into unvetted tools, that information can leave your control. WalkMe found that 36% of workers who used unsanctioned AI did so with confidential data.1 The most effective fix pairs clear data guardrails with an approved tool that is easier to use than the workaround.
A ban without an alternative tends to push AI use onto personal devices, where you have even less visibility. A better approach is to restrict what data can go into public tools, offer a sanctioned option that fits your security requirements, and explain the reasoning so people understand the line.
Close three gaps: show each role what good use looks like (destination), connect AI to work people care about (meaning), and put the tools inside the apps they already use (friction). Then make sure managers are visibly using and supporting the tools themselves.
A big one. Gallup found that employees whose managers actively support AI use are 1.7 times more likely to use it frequently and 7.4 times more likely to say it helps them do their best work.5 Training managers first is one of the fastest ways to move adoption across a team.
AI adoption is the heart of the TMM's Innovate stage, but it depends on the stages before it. Stable operations, strong security, and integrated data are what make it safe and useful to hand employees powerful AI tools. A TMM Assessment shows which foundations are in place and which need attention first.