Forty-seven employees touched an unapproved AI tool last week. Twenty-one are using personal accounts on managed devices. Eight tools you've never heard of are flagging signals this morning.
If those numbers feel made up, they're conservative. A Gartner survey of 302 cybersecurity leaders in 2025 found that 69% of organizations suspect or have evidence that employees are using prohibited public GenAI. A separate Gartner survey of 175 employees found that 57% use personal GenAI accounts for work purposes, and 33% admit inputting sensitive information into unapproved tools.
An inventory of approved AI tools tells you what your organization sanctioned. It tells you nothing about the other half of usage, who's behind it, what data is flowing into it, or whether the tool on the other end is storing or training on what it receives. The 2025 Verizon DBIR found that 15% of employees routinely access GenAI systems on corporate devices, and 72% of them do so through non-corporate email accounts, completely outside your authentication and logging perimeter. IBM's 2025 Cost of a Data Breach report found that shadow AI added an average of $670,000 to global breach costs.
The AI surface is already inside your environment, and most organizations can see very little of it.
Why Shadow AI Is Harder to See Than Shadow IT
Shadow IT used to mean someone signing up for a SaaS app without filing a ticket. That was a single application with a single set of permissions. Shadow AI is a different problem because each tool an employee brings in carries an expanding surface behind it.
When someone installs an AI coding assistant on their own, they're not adding one app. They're adding an agent that can load plugins, connect to MCP servers, read local files, and invoke shell commands. Each of those extensions has its own permissions and data access. The tool your team might have approved six months ago may have a completely different capability surface today because the employee added four plugins and two MCP server connections since then.
This is why Gartner predicts that by 2030, more than 40% of enterprises will experience security or compliance incidents linked to unauthorized shadow AI. The surface compounds in ways that shadow IT never did.
- Agents nobody provisioned. Employees install AI coding assistants, writing tools, research agents, and automation bots on their own devices and managed endpoints. Most don't go through procurement. Many don't appear in your SSO logs because they authenticate with personal accounts or API keys rather than corporate identity.
- Plugins, skills, hooks, and CLIs. AI tools are modular. A single coding assistant might have dozens of plugins installed, each with its own permissions and data access. These extensions change frequently and silently.
- MCP servers connected to internal systems. The Model Context Protocol lets AI agents connect directly to databases, file systems, APIs, and internal tools. An employee who pulls an MCP server from a public registry and wires it into their AI assistant has just handed that assistant access to systems that were never part of the original tool approval, if there was an approval at all.
- Permissions employees don't understand. When someone connects an AI tool to their Google Workspace or Microsoft 365 account, they approve OAuth scopes that often grant read-write access to entire repositories, shared folders, or CRM datasets. Most users don't grasp the scope of what they're approving. Most security teams never see the approval happen.
- No identity behind the activity. Traditional security tools tie activity to a machine or an IP address. AI agents operate through tokens, inherited sessions, and service accounts. When an agent pulls data from an internal API at 2 AM, there's no login event, no user session, no MFA challenge. The activity happens inside the bounds of authorized access, which makes it nearly invisible to tools designed around human authentication patterns.
Where Your Data Goes
The most common shadow AI risk is an employee trying to work faster.
Source code pasted into a personal ChatGPT account. Financial models summarized in an unapproved Claude instance. Customer records used as context in an AI browser extension. Board decks uploaded for analysis. None of these actions are malicious in intent. All of them move sensitive data outside your control.
Gartner found that 33% of employees admit to inputting sensitive information into unapproved AI tools. The Verizon DBIR found that of the 15% of employees routinely using GenAI on corporate devices, nearly three-quarters access those tools through personal accounts with no corporate authentication. IBM's Cost of a Data Breach report found that 63% of organizations have no AI governance policies in place, and among organizations that did experience an AI-related security incident, 97% lacked proper AI access controls.
Gartner also predicts that 40% of AI data breaches will stem from cross-border GenAI misuse by 2027, meaning that the data employees paste into AI tools may end up processed or stored in jurisdictions your compliance program doesn't cover.
Employees adopt AI tools because those tools make them more productive. The data exposure happens as a side effect of productivity, not malice. That makes it hard to detect and even harder to prevent through policy alone without alienating the workforce.
The Governance Gap
The gap between AI adoption and AI governance is wide and measurable.
IBM found that 63% of organizations have no AI governance policies to manage AI usage or prevent employees from using shadow AI. Forrester predicts that uncontrolled generative AI adoption across marketing, sales, and product teams will trigger data leaks and compliance breaches in 2026. Gartner predicts that by 2028, 25% of all enterprise GenAI applications will experience at least five minor security incidents per year, up from 9% in 2025.
Meanwhile, 60% of employees say they'll use unapproved AI tools if those tools help them meet deadlines, regardless of what the policy says. Blocking AI entirely doesn't work because it pushes usage underground, where it becomes even less visible. The organizations getting this right are the ones that can see the AI surface clearly enough to distinguish ordinary productivity usage from genuine risk.
How Anzenna Helps
Anzenna reads the AI surface through the integrations you already have. EDR and MDM tools (CrowdStrike, Jamf) show what's running on endpoints. Identity providers (Okta, Entra) show who's behind the activity. Developer tool integrations (GitHub, GitLab) show what's being committed and where. SaaS logs show OAuth grants and data movement. Anzenna doesn't add another daemon to your endpoints. It reads the stack you already run.
Here's what that visibility looks like in practice:
- The full AI surface, mapped. Anzenna tracks how people use AI across browser and desktop. On the browser side, it detects web logins to AI services (personal or corporate), AI browser extension installs, OAuth grants to AI providers, and DNS-level traffic. On the endpoint, it picks up desktop AI app installs, IDE extension installs, MCP client and server connections, and configuration changes. Anzenna also has direct hooks into major AI platforms, including Claude, GitHub Copilot, Cursor, Gemini, Codex, and Windsurf, so it can see what those tools actually do on a managed device, from file reads and shell commands to MCP server connections and configuration tampering. Each signal is tied to the employee and device behind it, and the 1-2% of genuinely risky activity gets separated from ordinary productivity usage.
- Every action tied to a person. An AI agent pulling data from an internal API isn't useful information by itself. An AI agent pulling data from an internal API, operated by an employee in their notice period whose peer group has never used that tool, whose download volume is 8x their historical average, is an investigation. Anzenna connects AI activity to the human identity behind it, including employment status, role, peer group, and behavioral history.
- Peer-group baselines for AI usage. Anzenna doesn't flag "employee used an AI tool" as a risk. It flags "employee used an AI tool in a way that deviates from how their peers use it." An engineer wiring an MCP server to their own repo is normal. The same agent reaching across the org is not. The baseline adapts to role, department, and individual history.
- Investigation Agents write the case. When an AI-related risk surfaces, Anzenna's Investigation Agents automatically draft a case file: what tool was involved, what data was accessed, who was behind the activity, how the behavior compares to the person's baseline and their peer group, what the recommended action is. Your analyst reviews a written narrative, not a raw log. Median case draft time is under 2 minutes.
- Read-only, metadata-only, secrets redacted. Anzenna doesn't read the content of what employees type into AI tools. It reads metadata. Which tools, which endpoints, which data stores, how much, how often, by whom. Secrets and sensitive content are redacted before they enter the platform. SOC 2 Type II certified. Tenant isolation. Every agent decision reviewable and audited end to end.
Built to Be Trusted
AI security tools that surveil employees push AI usage underground, which is the opposite of visibility. Hidden tools are unmonitored tools, and unmonitored tools are where breaches start.
Anzenna is agentless. 15-minute install. No endpoint agents, no browser proxies, no inline inspection of content. It connects through APIs to the tools you already run, reads metadata, and builds behavioral context. Your stack stays unchanged. Your employees' trust stays intact.
Across its customer base, Anzenna has blocked 81,400 AI uploads and 79,500 exfiltrations, protecting more than 756,000 users.
As one security leader put it:
We had no insights into our AI usage and Anzenna was able to provide us with a comprehensive visibility layer.
The Real Lesson
Shadow AI isn't a policy problem you can memo your way out of, and it's not an infrastructure vulnerability you can patch. It's a visibility problem. Employees are using AI tools because those tools make them better at their jobs. The risk comes from not being able to see which tools, which data, which people, and whether any of it falls outside what's normal.
The organizations that get ahead of this won't be the ones that block AI. They'll be the ones that can see the AI surface clearly enough to tell ordinary productivity from genuine risk, and respond to the genuine risk without punishing the productivity.
Ready to see what your AI surface actually looks like? Request a demo and see it on your data in 30 minutes.
Statistics sourced from Gartner (2025 cybersecurity leader and employee surveys, 2025-2026 predictions), IBM/Ponemon 2025 Cost of a Data Breach Report, Verizon 2025 Data Breach Investigations Report, and Forrester 2026 Predictions. Anzenna product metrics from anzenna.ai.
Frequently asked questions
What is shadow AI?
The AI tools employees adopt on their own without approval, from a personal ChatGPT tab to an unvetted browser extension or agent, along with the data those tools can reach.
How do you detect shadow AI?
By correlating identity, browser, SaaS and endpoint signals to surface the AI in use, sanctioned or not, and mapping the access and data path each tool holds.
Who offers automated shadow AI detection?
Anzenna detects sanctioned and shadow AI as part of AI usage control, agentlessly, and flags risky usage with full business context so you can govern the AI you know and find the AI you don't.
Is shadow AI detection agentless?
Yes. Anzenna connects through APIs, with nothing to install on endpoints.
Related reading: AI discovery, AI posture management, and the AI posture management guide.