Conceptual graphic depicting using AI in the workplace

GamePixel // Shutterstock

What happens when shadow AI goes unchecked in the workplace

Adoption of artificial intelligence has been rapid and widespread, with Stanford University researchers pegging organizational uptake at 88%. The same report found that across the general population, generative tools have a far lower penetration level of 28.3% in the U.S., although this is below the global average of 53%.

Regardless of which metrics are considered, the use of and familiarity with AI will continue to grow going forward. While the opportunities for improved productivity and lower costs associated with its rise to prominence are worth celebrating, the issue of unsanctioned AI usage in the workplace, referred to by experts as shadow AI, is an issue. Terminal B, an information technology support and managed services provider, examined how shadow AI creates operational risks that aren’t always easy to detect but can cause measurable security risks.

An infographic reporting overview on the growth of shadow AI and what happens when it goes unchecked in the workplace.

Terminal B

Why Companies Must Control AI Use

Gartner analysis of shadow AI reveals the extent of the issue as it stands. Research from 2025 found 69% of organizations were exposed to unauthorized use of publicly available generative AI tools by employees.

The same report predicts that 40% of companies will encounter negative side effects associated with shadow AI by 2030, whether in the form of security breaches or compliance missteps. Industries with stricter regulations governing their operations will be more exposed to these concerns.

Coupled with the expectation that almost two-thirds of governments globally will act to implement new rules on AI use and data sovereignty by 2028, it’s not difficult to understand the scale of the problem shadow AI poses in the near future, compounding the current worries over its use.

Gartner’s singling out of the technical debt associated with shadow AI use is especially significant. The expectation that 50% of businesses will be hit by project obstacles or costs associated with the unsanctioned use of generative AI, introducing flaws in code and content, leaves many firms exposed to the potential for AI’s efficiency improvements and savings to be undermined.

In simpler terms, the prevalence of shadow AI could roll back any benefits the technology brings in other aspects of an enterprise’s operations. Gartner’s suggested solution is the creation of clear operational standards and parameters for the technology’s use, as well as contingency planning based around the technical debt that companies will still likely face even if they do codify employee-level AI implementation as part of their adoption strategy.

Skill Degradation From the Use of Unsanctioned Tools

The idea that unauthorized generative AI use in the workplace will expose organizations to security risks is an obvious one, and an outcome that has been much discussed. However, a lesser-explored aspect, yet one with similarly significant repercussions, relates to what the technology will do to the skills of employees.

Gartner’s report argues that adopting AI to take over some aspects of a person’s workload will necessarily lead to a degree of skill erosion, dampening the expertise and judgment of human team members while simultaneously creating a situation in which an organization will struggle to replicate or replace them. Again, this is something that businesses can manage by having firm, well-documented AI policies in place, providing employees with the resources they need to function optimally while also carrying out regular skill audits so that the potential for erosion is minimized, especially if shadow AI use might be an unnoticed catalyst of this.

Working Toward Cohesion Governance

Addressing unauthorized software adoption requires structural visibility rather than punitive employee measures. Modern governance models prioritize comprehensive traffic monitoring and strict end-point management to deal with security concerns, and transparent procurement processes that involve employees alongside decision-makers. Establishing clear software evaluation pipelines lets organizations retain complete control over data classification while allowing team members to leverage modern tools safely.

The evolution of enterprise technology demands an active approach to network architecture and an understanding of how it will impact employee performance and skills. Organizations that proactively update risk frameworks ensure long-term resilience against emerging software threats. Maintaining strong internal security controls remains essential for protecting operational integrity, just as auditing tool use and keeping track of team member output, while reinforcing best practices without being purely punitive, will make a positive difference.

This story was produced by Terminal B and reviewed and distributed by Stacker.

About The Author