Shadow AI is the use of AI tools for work outside company rules and approved tools. An employee handles a work task in a personal ChatGPT, Claude or other account, and the company has no idea what data ends up there. The term builds on shadow IT: software people use without going through the IT team.
Why shadow AI is risky:
- Confidential data goes to services the company hasn't vetted
- Personal accounts sit outside company rules and access controls
- There's no log of what was done with AI or where
Pachca's 2026 study surveyed 798 employees at Russian companies: 88% use AI at work, but only one in four say their company has rolled it out officially, with tools and rules. 58% of AI users handle work tasks through personal accounts. The more systematically a company rolls out AI, the less shadow AI there is: where AI hasn't been rolled out, 55% of respondents regularly use personal accounts for work, compared with 27% under a centralized rollout.
The alternative to shadow AI is official tools with clear rules. In Pachca, agents connect as bots or through personal tokens: administrators decide who can use the API, and actions taken through the API go into the audit log.
Learn more in the Help center
Read the article →