TL;DR — Shadow AI is the use of AI tools without the approval and visibility of IT, security and legal teams: personal ChatGPT accounts, browser extensions, unsanctioned APIs. Only 37% of organizations have an AI governance policy (IBM, 2025), and roughly 47% of GenAI users access tools through personal accounts, bypassing corporate controls (Netskope, 2026). Banning does not work; nearly half of employees keep using their personal account even after a ban. The right approach is "governed enablement": visibility, policy, data protection, access, and traceability. In this piece I lay out a 90-day governance plan, the logic of an approved-tool catalog, and the link to KVKK and the EU AI Act.
When I begin an AI consulting engagement at an organization, one of the first questions I ask management is: "Which AI tools are your employees using right now?" The answer is almost always the same: "We don't have any official use yet." Then we go into the field and the truth emerges. The marketing team drafts its copy in personal ChatGPT accounts, a developer pastes code into an unsanctioned extension, an analyst dumps a customer list into a translation tool. What they call "we don't have it" is, in fact, everywhere. That invisible layer has a name: shadow AI.
What exactly is shadow AI
Shadow AI is all the AI tools, services and accounts used outside the knowledge, approval and visibility of an organization's IT, security and legal functions. It is a new and far faster-spreading relative of an earlier phenomenon — "shadow IT." But with one difference: with shadow IT you usually installed unsanctioned software; with shadow AI, most of the time nothing is "installed," you simply visit a website and paste data. The barrier to entry is almost zero, which is why it spreads so much faster.
Typical forms of shadow AI include:
- Personal accounts. Accounts on ChatGPT, Claude, Gemini and the like that an employee opens with their own email, not a corporate one. The organization neither sees nor audits this traffic.
- Browser extensions. Add-ons like "summarize this text" or "write your email" that send your data to a third party in the background.
- Unsanctioned APIs and integrations. Services a team connects on its own, with no corporate data-processing agreement in place.
- Embedded AI features. A new AI feature in a SaaS tool you already use, switched on without you realizing.
Note: most of this is not done with bad intent. On the contrary, the employee is trying to do their job better and faster. The problem is not in the intent but in the lack of visibility and control.
Why it is so widespread: what do the numbers say
To grasp the scale of this issue, let's look at a few verified figures. According to IBM's 2025 data, only 37% of organizations have an AI governance policy. In other words, in two out of every three organizations there is not even a written rule about how employees may use AI. Where there is no rule, everyone makes their own; and that, by definition, is shadow AI.
According to Netskope's 2026 data, roughly 47% of GenAI users access these tools through personal accounts, thereby bypassing corporate controls. That is a striking proportion: nearly half of users operate through a channel the organization cannot see.
So should we ban it? Here is the crux. What we see from the field and the data is this: nearly half of employees keep using their personal AI account even after a ban. In other words, a ban does not eliminate the tool; it merely drives it underground. Visible shadow AI is a problem; invisible shadow AI is a disaster. Because when you ban it, all you are left with is a false sense of security.
"A ban does not destroy shadow AI; it moves it somewhere you cannot see. The first condition for managing a risk is being able to see it. The moment you make it invisible, you also lose your chance to manage it.
Risks: what is the cost of invisibility
So what does this invisible layer bring upon the organization? I group the risks under four headings.
1. Data leakage. This is the biggest and most frequent risk. When an employee pastes a customer list, a financial statement, health data, or an unannounced strategy into a public chatbot, that data has left the organization's control perimeter. Where the data is stored, whether it is used for model training, and who can access it are no longer in your hands.
2. Loss of intellectual property (IP). Source code, design files, pre-patent inventions, original content... When these enter a third-party tool, your control over the intellectual property weakens. In some scenarios its confidential status becomes contested.
3. Compliance breach. KVKK, sectoral regulations, the EU AI Act... Transferring personal data to an unsanctioned tool is often a direct regulatory breach. The fact that an employee did it in good faith does not absolve the organization of liability.
4. Accuracy and reputational risk. An unverified output from an unaudited tool, once it enters a customer document or an official report, creates reputational and legal risk. Hallucination, miscalculation, fabricated sources — none of these has passed through an audit filter.
These risks also carry a concrete cost. According to IBM's 2025 data, shadow AI playing a role in a data breach means roughly $670K in additional cost per breach and a process that takes roughly 10 days longer to contain and resolve. In other words, shadow AI is not just a "might happen" risk; it is a measurable cost item expressed in money.
Why not a ban, but "governed enablement"
If you have read this far, your natural reflex might be "then let's ban all of it." But we just saw: a ban does not work, it only makes the risk invisible. A ban also takes the productivity gains AI brings off the table. While your competitors accelerate with these tools, you leave your employee's hands tied.
The approach I recommend is called governed enablement. The idea is simple: instead of banning AI, formally make it possible within a safe and auditable framework. Instead of telling the employee "do not use it," say "here are the approved tools, here are the rules, here is the safe path." This approach has five pillars:
| Pillar | What it means | Practical equivalent |
|---|---|---|
| Visibility | Seeing who uses which tool | Network/traffic discovery, usage inventory |
| Policy | Written, clear rules of use | Acceptable use policy |
| Data protection | Preventing sensitive data from reaching the tool | Data classification, DLP, masking |
| Access governance | Corporate, auditable accounts | SSO, role-based access, enterprise subscription |
| Traceability | Record of who did what, when | Logging, audit trail, review |
This framework is also consistent with the internationally recognized NIST AI RMF (AI Risk Management Framework) logic: the govern, map, measure and manage cycle. The goal is not zero risk — that is impossible anyway — but a level of risk that is acceptable, visible and managed.
How to detect shadow AI
We said "visibility"; so how do you make it visible in practice? Here are the detection methods I use:
- Network and traffic analysis. See which AI services traffic goes to from the corporate network. Most security tools (CASB, secure web gateway) can report this.
- Anonymous survey. Ask employees, stating clearly that you will not punish them: which tools do you use, and for what work? People answer honestly when they are not afraid. This is the fastest and cheapest discovery method.
- SaaS and expense audit. Detect AI subscriptions bought with personal cards or department budgets from invoices and expense records.
- Browser extension inventory. List the extensions installed on corporate devices; flag AI add-ons that send data.
- Embedded feature scan. Review which AI features are enabled in the SaaS tools you already use.
The most important principle in detection is this: do not accuse, discover. Your aim is not to punish the employee but to see the truth. The reflex to punish drives the tool underground and leaves you worse off than where you started.
The 90-day governance plan
Now let's get to the concrete side. Below I share a three-phase, 90-day roadmap I have applied in many organizations. This plan is designed to be both fast and sustainable.
First 30 days: see and understand
- Run discovery. Map current usage with the detection methods above. The goal is not an exhaustive list but a realistic picture.
- Launch the anonymous survey. Open an honest, penalty-free channel for employees. Learn which jobs they do with AI.
- Classify risk. Which data types are being processed? Personal data, trade secrets, public information. This classification is the basis for later decisions.
- Gather stakeholders. IT, security, legal, HR and the business unit doing the work should sit at one table. This is as much a culture project as a security project.
Days 30-60: build the framework
- Write the acceptable use policy. Short, clear, full of examples. As clear as "you can do this, never do that." Not in lawyer's language, but in language the employee will understand.
- Create the approved-tool catalog. A list of tools the organization formally supports, with corporate contracts and data-processing safeguards. Tell the employee "here are the safe options."
- Set up corporate accounts and SSO. Replace personal account use with corporate, auditable accounts. If people are already using it, make the safe channel attractive.
- Turn on data protection controls. Masking, DLP and, where necessary, blocking for sensitive data classes.
Days 60-90: train, monitor, mature
- Provide training. Policy does not live on paper; it comes to life through training. Explain "what we don't do and why" with concrete examples. The most effective training is built on real organizational scenarios.
- Establish traceability. Operate logging and the audit trail; create a rhythm of regular review.
- Open a feedback loop. Define a fast approval path an employee can turn to when they need a new tool. Otherwise the need escapes back into the shadows.
- Measure and report. Did approved-tool use rise, did shadow use fall? Go to management with concrete metrics.
"At the end of 90 days your goal should not be "zero AI"; it should be "visible, governed and safe AI." Your success metric is how willingly employees migrate to the approved channel.
The approved-tool catalog and training: the heart of the matter
I want to emphasize two components of this plan in particular, because most organizations skip them.
The approved-tool catalog is the single most effective step for reducing shadow AI. Why? Because the employee already wants to use AI. If you do not offer them a safe, official, easy path, they will find their own. The catalog is a clear guide that says "these tools are under corporate contract and safe, use them for these jobs." And when a need arises that is not in the catalog, there must be a fast evaluation and addition process — otherwise the catalog turns into bureaucracy that pushes the employee back into the shadows.
Training is where the policy passes from paper to reality. In training I avoid technical jargon and use real scenarios: "You want to summarize a customer email; which tool do you go to, and with what data?" When the employee acts out of understanding rather than a ban, the rule is internalized. We want to build a culture of responsibility, not a culture of fear.
The link to KVKK and the EU AI Act: why it is even more critical in Turkey
For organizations in Turkey, shadow AI is not just a security matter; it is directly a compliance matter. Let me clarify a few points.
From the KVKK angle. Law No. 6698 (KVKK) mandates the lawful processing of personal data and specific conditions for its transfer abroad. An employee pasting a customer's name, phone number, or health or financial information into a public chatbot most often breaches the obligations of the data controller (that is, the organization). Moreover, these tools' servers are mostly abroad; that triggers the cross-border transfer regime. The organization cannot escape liability by saying "the employee did it on their own"; as the data controller it is obliged to take the necessary technical and administrative measures. Shadow AI is precisely the blind spot where those measures cannot be taken.
From the EU AI Act angle. If you touch the EU market or work with EU data subjects, the EU AI Act's transparency obligations concern you too. Unaudited, unrecorded AI use conflicts with expectations of transparency and accountability. Considering that Turkey is moving toward harmonization with EU acquis, the governance structure you build today is also preparation for tomorrow's regulations.
The practical link is this: the five pillars of governed enablement — visibility, policy, data protection, access, traceability — are at the same time the concrete equivalent of KVKK's expectation of "necessary technical and administrative measures" and the EU AI Act's principle of transparency. In other words, good governance both reduces risk and meets your compliance obligation. Two birds with one stone.
A composite real-world example
Let me blend the various cases I've seen in consulting into a typical picture; perhaps it will feel familiar. Imagine a mid-sized services company. Management opens with "we don't have any AI use here." We run discovery.
The marketing team produces its blog and social media copy in personal ChatGPT accounts; often it also pastes in yet-unannounced campaign details. Customer service uses a browser extension to summarize incoming complaints; that extension sends the full messages to a third-party server in the background. Someone in finance has uploaded a report to a public tool to "fix and summarize" it; the report contains employee salary information. A developer on the software team pastes fragments of the company's proprietary codebase into a non-corporate code assistant.
None of this is malicious. Everyone is trying to do their job faster. But when you assemble the picture, the risk is this: personal data, trade secrets, intellectual property and salary information — four different types of sensitive data — are flowing out through channels the organization cannot see at all. And management is unaware of any of it, because it lives on the assumption that "we don't have any use."
The first thing we did to fix this picture was not a ban; it was discovery and transparency. We surfaced the truth with an anonymous survey, understood which jobs employees do with AI and why, and offered them safe, approved alternatives. Within a few months shadow use fell noticeably — because there was now an easier and safer path.
Shadow IT vs shadow AI: what's the difference
Some executives say "we already manage shadow IT, this is just a type of it." Partly true, but there are important differences, and these differences amplify the risk.
The barrier to entry is far lower. With shadow IT you usually download and install software; that leaves a trace and requires some technical skill. With shadow AI, visiting a website and pasting data is enough. Any employee can start in seconds, with no technical knowledge.
Data goes beyond the tool. With classic shadow IT the risk was usually limited to the tool itself. With shadow AI the real issue is the data flowing into the tool: once you paste it, you cannot take it back, and you cannot know where it goes.
The spread is very fast. When a new AI tool appears, it can spread by word of mouth within hours. Governance must be designed to keep up with that speed — that is, a living process, not a static ban list.
These differences tell us: you cannot manage shadow AI with your old shadow-IT reflexes. A new mindset is required — one of opening a safe channel, not of blocking.
Role-based responsibilities: who does what
The place governance most often gets stuck is "everyone's job but no one's responsibility." That is why sharing out roles clearly is essential. The simple responsibility split I use in the field:
| Role | Main responsibility |
|---|---|
| Senior management | Sets direction, allocates budget and priority, sets the tone |
| IT / Security | Visibility, technical controls, corporate accounts and logging |
| Legal / Compliance | KVKK and EU AI Act assessment, contractual safeguards |
| HR | Policy communication, training, culture |
| Line managers | Own the implementation in their team, relay needs |
| Employee | Use approved tools, protect sensitive data, report needs |
The heart of this split is this: governance is not one department's job. IT cannot write policy alone, legal cannot make a tool usable alone, HR cannot build technical controls alone. Without a core team and clear roles, the plan stays on paper.
How to measure success: concrete metrics
The saying "you cannot manage what you cannot measure" applies here too. When you go to management, you should have concrete metrics in hand. The main indicators I recommend tracking:
- Approved-tool adoption rate. What share of AI-using employees work through the approved channel? As this rises, the shadow shrinks.
- Number of detected shadow uses. A fall in this number over time (through offering alternatives, not banning) is a sign of success.
- Policy awareness rate. Do employees know the rules? Measurable with a short survey.
- Training completion rate. What share of the team completed AI usage training.
- Data protection trigger count. How many times DLP/masking controls kicked in; an indicator of both risk and awareness.
- New-tool approval time. When an employee requests a new tool, how quickly do they get an answer? If this time grows, people flee to the shadows again.
Reporting these metrics to management quarterly turns governance from a "project" into a continuous organizational discipline. And remember: the target metric should not be "zero AI use" but "zero invisible AI use."
Objections I often hear, and my answers
When I present this plan to management, I keep meeting similar objections. They may have crossed your mind too; let me share the ones I hear most and the answers I give.
"If we ban it, the problem ends — why bother with all this?" A ban does not end the problem; it makes it invisible. We know from the data that nearly half of employees keep using it even after a ban. When you ban it, what you are left with is not reduced use but use you cannot see. So your risk is the same, but now you are in a blind spot.
"Our sector is very sensitive, we should not touch AI at all." Sensitivity is precisely what makes governance mandatory, not what justifies avoidance. Staying away entirely while competitors accelerate with these tools both creates a competitive disadvantage and fails to stop shadow use — the employee will still find their own way. The right move is to build a safe channel that protects sensitive data.
"Won't the cost of this be high?" The cost of governance is small next to the cost of a breach. Remember: shadow AI brings roughly $670K in additional cost per breach and a resolution process roughly 10 days longer. Starting with an anonymous survey, a one-page policy and the reporting from your existing security tools is almost free.
"Employees ignore rules anyway — what good is a policy?" The reason they ignore rules is often that there is no rule, or no workable alternative. When people see a safe and easy path, they choose it. The trio of rule + easy alternative + training is far more effective than a dry ban.
"How will we know which tools are safe?" This is exactly what the approved-tool catalog is for. With your legal and security teams, evaluate and list tools that have a corporate contract, data-processing safeguards and, where possible, suitable data residency. The employee should not have to wonder "is this tool safe"; you decide for them.
Why this is really a culture matter
Technical controls, policies and catalogs matter — but the lasting solution to shadow AI is really a culture matter. I have seen this again and again: even if you deploy the most advanced DLP tool, if the employee finds the safe channel burdensome and punitive, they will find a way and flee to the shadows. Conversely, if you have built an open and supportive culture, the employee tends to do the right thing even when your technical controls are incomplete.
The core of this culture is trust. Instead of telling the employee "we are watching you and will catch you," say "we offer you safe tools, ask if you are confused, and if you make a mistake we will fix it together." A culture of punishment pushes people to hide; a culture of responsibility invites transparency. And transparency is the antidote to shadow AI.
In practice I nurture this as follows: managers visibly use the approved tools themselves (leading by example), new-tool requests are met quickly and positively, and when a mistake happens the focus is learning, not blaming. These three behaviors create a feeling in an organization that "it is safe to talk about AI." Once that feeling forms, employees knock on your door instead of fleeing to the shadows — and that is the moment you have truly begun to solve the shadow AI problem.
Why traceability is not negotiable
Among the five pillars, the most neglected is traceability. Organizations readily adopt visibility and policy, but often treat the "who did what, when" record as a luxury. Yet when a problem arises — a suspected data breach, an audit, a customer complaint — if you have no record, you cannot explain what happened, cannot manage liability, and cannot prevent a recurrence.
Traceability is both a legal and an operational necessity. Under KVKK, as the data controller you are expected to be able to demonstrate your processing activities in an accountable way. The EU AI Act looks the same way with its principles of transparency and record-keeping. When an auditor sits across from you, being able to say "our employees use AI with these tools, under these rules, with these records" is a very different position from saying "we don't know."
In practice you need not build traceability as a heavy surveillance system. The natural records from corporate accounts and SSO, the admin panels the approved tools offer, and your security tools' logs cover most needs. The aim is not to profile the employee; it is to leave a trace you can look back on when a problem hits, show in an audit, and learn from for improvement. If you design this trace in from the start, you spare yourself the cost and panic of trying to build it after the fact.
Where to start: steps you can take this week
Do not treat all this as one big project and postpone it. This week you can take these three steps and build momentum:
- Launch a discovery. With an anonymous, penalty-free survey, ask "who is using what." You will probably find more than you expected.
- Publish a one-page interim rule. Until the full policy is ready, even a clear interim rule like "never paste personal data into a public tool, apply to IT for approved tools" makes a big difference.
- Assign an owner. This work must have an owner; a core team from IT, security and legal. Ownerless work does not move forward.
- Give management a starter report. Summarize what discovery found, the risk it carries, and the first steps you propose on a single page. Sitting down with a concrete picture turns the topic from an abstract worry into a decision that gets budget and priority. Executives fund the risk they can see; not the one they cannot.
Shadow AI is an invisible reality organizations must face today. Ignoring it does not make it disappear; it only makes it more invisible and therefore more dangerous. The good news is this: the solution lies not in the tension a ban creates, but in the trust enablement creates. When you open a safe path for your employee, they will use that path willingly. Your job is to build that safe path; the rest, when set up correctly, follows on its own.
Consulting Pathways
Consulting pages closest to this article
For the most logical next step after this article, you can review the most relevant solution, role, and industry landing pages here.
AI Governance, Risk and Security Consulting
A governance framework that makes enterprise AI usage more sustainable across data, access, model behavior and operational risk.
Enterprise RAG Systems Development
Production-grade RAG systems that provide grounded, secure and auditable access to internal knowledge.
Safe AI Applications for Healthcare Organizations
AI solutions that safely support operations, training, documentation and information access without stepping into clinical decision-making.