Shadow AI
From Hidden Habit to Deliberate Strategy
Most companies’ employees are already pasting sensitive data into unapproved chatbots. This briefing turns that hidden habit into a deliberate strategy — diagnosing shadow AI, working through tolerate vs. build vs. buy, and setting the guardrails for AI that acts.
Get a sneak peek of the report at
- of employees already use unapproved AI at work
- 50–90%
of employees already use unapproved AI at work
- in extra breach costs for organizations with high shadow AI
- $670K
in extra breach costs for organizations with high shadow AI
- of breached organizations were compromised through shadow AI
- 20%
of breached organizations were compromised through shadow AI
- of enterprise generative-AI pilots show no measurable P&L impact
- 95%
of enterprise generative-AI pilots show no measurable P&L impact
50–90% of your employees already use AI you never approved. “Doing nothing” isn’t neutral — it’s keeping the risk and forgoing the upside.
Report Overview
A practical briefing on shadow AI: what it is, how widespread it has become, the economics of tolerate/build/buy, and how to govern the shift from AI that advises to AI that acts.
Get the Free Report- 01Preface
- 02What Shadow AI Actually Is
- 03How Prevalent It Is
- 04What Employees Put Into These Tools
- 05Why It Happens
- 06What It Puts at Risk
- 07The Canonical Cautionary Tale
- 08From Bans to “Sanction-and-Steer”
- 09Option 1: Tolerate
- 10Option 2: Build
- 11Option 3: Buy
- 12The Case That Captures Both Promise and Limit: Klarna
- 13The Decision Framework
- 14On Measuring ROI
- 15Regulatory and Compliance Economics
- 16Why Acting Changes the Risk
- 17The Productivity Case, Kept Honest
- 18Why Agents Are Still a Specialist’s Tool
- 19What Broad Autonomy Actually Costs
- 20Accountability When an Agent Errs
- 21The Shape of a Disciplined First Move
- 22The Bottom Line
Key Findings for Your Team
Explore the findings most relevant to your team — each section is tailored to a different set of priorities.
- Security, IT & Compliance
Shadow AI on personal accounts is a data-governance and breach problem. Covers visibility, sanction-and-steer, the enterprise-vs-consumer tier distinction, and EU AI Act exposure.
- Executives & Strategy
“Doing nothing” isn’t neutral. Covers the tolerate-build-buy decision, the opportunity and competitive costs of waiting, and a staged framework for moving deliberately.
- Customer Service & Operations
The highest-volume, best-evidenced place to start. Covers hybrid human+AI models, the Klarna lesson, and measuring ROI against metrics your CFO already tracks.
- AI & Automation Leads
The frontier is AI that acts. Covers why acting changes the risk, bounded-scope agent design, architectural guardrails, and accountability when an agent errs.
Shadow AI added $670K to the average breach and caused one in five. The tolerate-build-buy decision, made deliberately, is inside.
Get the Free Report
Between 50% and 90% of employees already use unapproved AI at work. This briefing turns that hidden habit into a deliberate strategy — diagnosing shadow AI, working through tolerate vs. build vs. buy, and setting the guardrails for AI that acts.
Frequently Asked Questions
Shadow AI is employees’ use of AI tools — public chatbots, personal accounts, “bring your own AI” — outside the visibility or control of the IT organization. It’s the AI-era descendant of shadow IT, with a sharper edge: company data typed into systems that may store, learn from, or expose it.

Ready to automate customer service with a quality agent?
Configure Lyro from your editor, or stand it up from our UI. Same agent, same skills, same evals — your choice of entry point.

