New · France 2027 presidential election: what the candidates propose on AI, quoted and sourced. Explore the tracker →

Last reviewed:

Shadow AI in the workplace: what's the 2026 state of play?

In 2026, the ungoverned use of generative AI at work is no longer marginal. Two-thirds of office professionals who use AI for work have done so with a tool they believed was not permitted, and 88% have shared work information with a public AI tool: emails, meeting notes, customer data.

This barometer brings together the public data published between November 2025 and September 2026 on shadow AI in the workplace (St. Louis Fed, PagerDuty, Ipsos bva, Netskope, IBM) and offers a grid to locate your organisation. The question is no longer "should we allow generative AI?": your teams already use it. It has become "how do we govern it before it costs us?". Edition 2.0, October 2, 2026.

66%of office professionals who use AI for work have done so with a tool they believed was not permitted.

PagerDuty / Wakefield Research · 1,250 non-IT office professionals · April 2026

2026 Shadow AI Barometer infographic: 66% have used AI they believed was banned, 88% shared work information (34% client data), 45.2% use generative AI at work.
Key figures of the 2026 Shadow AI Barometer. Infographic free to reuse (CC BY 4.0).

01The state of play

Adoption is not decided in a committee. It rises from the ground up, faster than any IT department can frame it.

45.2%of employed US adults aged 18 to 64 use generative AI for their job (37.4% in August 2025)St. Louis Fed · FRED series · Q2 2026
73%of French private-sector employees use AI at work (up 10 points in a year), 55% regularly or dailyGreenworking × Ipsos bva · May 2026
89%of office professionals who use AI for work first adopted it in their personal lifePagerDuty · Apr. 2026
79%of them now use it more often at work than outside workPagerDuty · Apr. 2026
WYP reading

Use does not come down from management. It settles in from below, carried by free tools that are useful from the first minute. A ban does not catch up with a free tool.

02What actually leaks

The risk is concrete. 88% of respondents have shared work-related information with a public AI tool (ChatGPT, Claude, Gemini, outside company systems). Here is what they entered:

Emails and correspondence43%
Meeting notes or summaries40%
Customer data34%
Financial information31%
Confidential documents or strategies31%
Code or technical specs23%

PagerDuty Shadow AI Survey, Wakefield Research, fieldwork April 9 to 20, 2026, published June 11, 2026. Margin of error ±2.8 points for the total sample.

Another signal: 38% have shared AI-assisted work without disclosing it, and 39% would rather use AI without telling anyone than risk being told they cannot.

WYP reading

Every line is data leaving the company for a third-party service, often with no contract and no legal review. As soon as personal data is involved, it is a GDPR processing operation for which the company remains responsible.

03Why it happens

Shadow AI is rarely an individual fault. Four mechanisms make it predictable.

1

It is free

A personal account and an email address are enough. No barrier to entry.

2

Perceived performance

Public models help right away. 89% of users started in their personal life, convinced before any framework existed.

3

Slow official rollout

Months go by between the need and the approved tool. 44% use AI to work around the limits of company-approved tools.

4

A vague policy, or one seen as unequal

Without a written rule, silence passes for permission. Even where a policy exists (86% of respondents believe so), 81% think leadership plays by different rules from the rest of the company.

In France, the Greenworking × Ipsos bva Observatory (May 2026) confirms it: only 37% of users systematically use tools approved by their company. Conversely, where an official tool exists, personal use declines. Netskope network data for its European customers, March 2025 to March 2026:

43%of AI users go through personal accounts, down from 79% a year earlier; company-managed accounts rose from 28% to 72%Netskope Threat Labs · Europe · May 2026
59%of data policy violations involving AI and personal apps concern regulated dataNetskope Threat Labs · Europe · May 2026
WYP reading

Banning without an alternative pushes use into the shadows: the risk stays, visibility disappears. A good official tool, on the other hand, makes shadow AI recede.

04What it costs, what it commits

The cost of an incident and the company's liability are now documented.

1 in 5breached organizations reported a breach due to shadow AI; high levels of shadow AI were associated with $670,000 in higher breach costsIBM / Ponemon · Cost of a Data Breach · July 2025
63%of breached organizations either have no AI governance policy or are still developing oneIBM / Ponemon · Cost of a Data Breach · July 2025

The Air Canada precedent. On February 14, 2024, a Canadian tribunal ordered the airline to compensate a customer misinformed by its website chatbot about bereavement fares: CA$650.88 in damages, CA$812.02 including interest and fees. Air Canada argued that the chatbot was a separate legal entity responsible for its own actions. The tribunal called this a "remarkable submission" and rejected it.

Case law · 2024

"It should be obvious to Air Canada that it is responsible for all the information on its website."

Moffatt v. Air Canada, 2024 BCCRT 149, para. 27, Civil Resolution Tribunal (British Columbia), February 14, 2024

WYP reading

A company answers for what the AI it lets people use produces. An error built into a service or a deliverable commits the employer, not the model.

05The WYP grid: where does your organisation stand?

Locate your maturity at a glance. Levels 0 and 1 are exposed.

0

Denial

No policy, no measure. Use exists and stays invisible. Maximum exposure.

Exposed
1

Ban

Restrictive policy with no tool and no support. Use continues, hidden. The risk stays, visibility disappears.

Exposed
2

Framing

Written policy, approved and properly hosted tool, team training. Use is framed. Risk under control.

Controlled
3

Governance

Framing, regular audit of use, human review of high-stakes outputs, continuous improvement. Shadow AI becomes plain AI again.

Controlled

WYP.agency analysis grid. It is not based on a survey: it is a positioning tool.

06The three non-negotiable measures

A written AI policy

One page is enough: approved tools, data never to be entered, outputs that need review. Without a written rule, silence means permission.

An approved, properly hosted tool

Offer a credible alternative: enterprise contract, data not reused for training, hosting suited to your constraints. Personal use recedes when the official tool is just as good.

Human review of high-stakes outputs

No client, legal or financial deliverable goes out without review. Generative models sometimes produce plausible errors: it is a known limit, to be built into the process.

Train before you sanction. Discovering shadow AI should first trigger information and training, except in cases of serious breach of confidentiality.

Citation and reuse. Edition 2.0, October 2, 2026. The surveys cited differ in method and scope: do not add them up. Data reusable under a CC BY 4.0 licence, with attribution: "Shadow AI Barometer 2026", WYP.agency, https://wyp.agency/en/glossary/shadow-ai-barometer-2026/

Get the barometer as a PDF

The synthesis, the maturity grid and the three measures, in a format to share with your leadership team.

PDF · 8 pages · October 2026 edition · FR / EN / ES · delivered in under a minute

See also

Further reading

PagerDuty Shadow AI Survey, Wakefield Research, 2026 (external resource)

Sources

  1. PagerDuty, press release "PagerDuty Report Finds Two-Thirds (66%) of Office Professionals Have Used Unauthorized AI Tools at Work", June 11, 2026. https://www.pagerduty.com/newsroom/shadow-ai-workplace-survey-2026/ (accessed 2026-10-02)
  2. PagerDuty Shadow AI Survey, full report, Wakefield Research, fieldwork April 9 to 20, 2026 (1,250 non-IT office professionals, companies with $500M+ revenue, US, UK, Australia, Japan; margin of error ±2.8 points). https://cdn.pagerduty.com/wp-content/uploads/2026/06/FINAL-PagerDuty-Shadow-AI-Report-June-11-2026-1.pdf (accessed 2026-10-02)
  3. Generative Artificial Intelligence, Adoption Rate for Work: Employed Adults (series RPSGENAIUSAGESHAREWORK, Real-Time Population Survey, workers aged 18 to 64), FRED, Federal Reserve Bank of St. Louis, Q2 2026 value released August 4, 2026. https://fred.stlouisfed.org/series/RPSGENAIUSAGESHAREWORK (accessed 2026-10-02)
  4. Bick, Blandin and Deming, "The State of Generative AI Adoption in 2025", Federal Reserve Bank of St. Louis, November 13, 2025. https://www.stlouisfed.org/on-the-economy/2025/nov/state-generative-ai-adoption-2025 (accessed 2026-10-02)
  5. Greenworking × Ipsos bva, "IA au travail : derrière l'adoption massive, des usages fantômes et des managers en première ligne", September 23, 2026 (fieldwork May 12 to 25, 2026, 1,100 French private-sector employees excluding manual workers, including 474 managers; in French). https://www.ipsos.com/fr-fr/ia-au-travail-derriere-ladoption-massive-des-usages-fantomes-et-des-managers-en-premiere-ligne (accessed 2026-10-02)
  6. Netskope Threat Labs Report: Europe 2026, May 25, 2026 (data from March 1, 2025 to March 31, 2026). https://www.netskope.com/resources/threat-labs-reports/threat-labs-report-europe-2026 (accessed 2026-10-02)
  7. IBM, "IBM Report: 13% Of Organizations Reported Breaches Of AI Models Or Applications, 97% Of Which Reported Lacking Proper AI Access Controls", Cost of a Data Breach 2025 (Ponemon Institute, 600 organizations), July 30, 2025. https://newsroom.ibm.com/2025-07-30-ibm-report-13-of-organizations-reported-breaches-of-ai-models-or-applications,-97-of-which-reported-lacking-proper-ai-access-controls (accessed 2026-10-02)
  8. Moffatt v. Air Canada, 2024 BCCRT 149, Civil Resolution Tribunal (British Columbia), February 14, 2024. https://www.canlii.org/en/bc/bccrt/doc/2024/2024bccrt149/2024bccrt149.html (accessed 2026-10-02)
  9. CNIL (French data protection authority), "Intelligence artificielle" topic page (in French). https://www.cnil.fr/fr/intelligence-artificielle (accessed 2026-10-02)

← Back to glossary

Address copied