Shadow AI: when staff use personal AI accounts with company data
Shadow AI is AI your staff use for work that the company has not approved, such as a personal ChatGPT, Gemini or Claude account. This page shows you how to find it in your company with tools you already have, and what to give your team in its place. When someone pastes a drawing, a price list or a customer list into a personal account to get a quote out faster, the company can no longer see or manage that copy. In a survey run in March 2026, Statistics Canada found that 35.9% of workers had used generative AI tools at work in the previous 12 months. The release does not say how many of them used a tool their employer had approved.

What shadow AI means
Shadow AI is the use of AI tools for work without the company’s approval. IBM’s Cost of a Data Breach Report 2026 defines it as the case where “workers use unapproved AI.” A 2024 Software AG study of 6,000 knowledge workers called it AI tools that employers do not provide. Microsoft and LinkedIn’s 2024 Work Trend Index calls the same habit bring your own AI, or BYOAI.
Shadow AI is one part of AI security, which covers the security of every AI tool your company uses. Attacks that use AI against your company, such as fake supplier emails and cloned voices, are covered in AI cybersecurity.
Shadow AI and shadow IT
Shadow IT is any software or online service that staff use for work without approval, such as a personal file-sharing account. Shadow AI is the part of it built on AI models. A file-sharing account stores a price list. A chatbot reads it and answers questions about it. On some personal accounts, the vendor may also use it for training, which means it feeds your text into the next version of its model. OpenAI’s model improvement article says that for services for individuals, such as ChatGPT, “we may use your content to train our models.”
Is ChatGPT shadow AI?
ChatGPT is shadow AI when an employee uses it on a personal login for company work. It is approved AI when the company holds a business workspace, with an administrator and a written rule on what may go in.
Microsoft draws the same line. Its Copilot FAQ says Copilot Chat offers enterprise data protection “for users signed in with a Microsoft Entra account,” which is a work account. With a personal Microsoft account, Copilot is for personal use. Both carry the Copilot name, so ask staff which account they sign in with.
Shadow AI examples in a plant or a distribution business
From the inside, shadow AI looks like an estimator or a buyer trying to finish the day’s work sooner. Which records go into these tools, and what each account keeps, is covered below in what a personal account does with your data. Here are the channels a manager can find:
- A chatbot on a personal login. An estimator pastes the notes from a customer drawing into a free account to draft a quote. On a personal phone over cellular data, the company network never sees it.
- An AI note-taker on a customer call. An inside sales rep lets a note-taking app join a customer meeting. The recording and summary sit in the rep’s own account with that app.
- An AI app connected to the company mailbox. A buyer clicks “Sign in with Microsoft” on a new AI assistant. Microsoft’s user consent guide says that by default, a user can allow an app to access their mailbox.
- A browser extension. In December 2025, The Register reported that extensions installed by more than 8 million people captured their conversations with AI chatbots.
- A résumé screen in a chatbot. Someone in HR pastes job applications into a chatbot to build a shortlist. In Ontario, an employer with 25 or more employees that uses AI to screen applicants for a public job posting must disclose it there.
Netskope’s manufacturing report counted data policy violations in personal cloud and AI apps at its manufacturing customers. Regulated data, such as personal and financial information, made up 41% of them, and intellectual property 32%.
Why people use AI you have not approved
A Microsoft survey of UK employees points to two reasons: habit, and no approved option at work. Censuswide surveyed 2,003 UK employees for Microsoft in October 2025, and 71% had used unapproved consumer AI tools at work. Asked why, 41% said it was what they used in their personal life. Another 28% said their company did not provide a work-approved option.
Microsoft and LinkedIn’s 2024 Work Trend Index surveyed 31,000 people in 31 countries. It found that 78% of AI users bring their own AI tools to work, rising to 80% at small and medium-sized companies. It also found that 52% of people who use AI at work are reluctant to admit using it for their most important tasks. That is why the check below starts with an amnesty.
Statistics Canada measured two different things in 2026. In its survey of workers, 35.9% had used generative AI at work. In a separate survey of businesses, 19.2% reported using AI to produce goods or deliver services, and 7.9% in wholesale trade. One counts workers and the other counts businesses, so the two figures are not directly comparable.
The real risks of shadow AI
What a personal account does with your data
The table sets each vendor’s personal account beside its business account, as the vendors’ own pages read on September 25 to 27, 2026.
| Vendor | Personal account | Business account |
|---|---|---|
| OpenAI | ChatGPT on an individual plan may train on your content, unless the user opts out under Settings > Data controls. | No training by default on ChatGPT Business, Enterprise, Edu or the API (OpenAI). |
| Anthropic | When the user’s model-training setting is on, Anthropic uses Claude Free, Pro and Max chats to train new models and keeps them for five years. With the setting off, it keeps them for 30 days (Anthropic). | No training by default on commercial products such as Claude for Work and the API (Anthropic). |
| With Keep Activity on, Google uses Gemini Apps chats to improve its services, including training AI models. Human reviewers read some chats, and Google asks users not to enter confidential information (Google). | On qualifying Workspace editions, content is not human reviewed or used for AI training outside your domain without permission (Google). | |
| Microsoft | Unless the user opts out, Microsoft uses Copilot conversations on a personal account to train its generative AI models, and it stores conversation activity for 18 months by default (Microsoft). | Signed in with a work account, Copilot Chat prompts and responses are not used to train foundation models (Microsoft). |
On a business account, the company holds the administrator role, and the vendor’s terms carry the no-training default. On a personal account, training depends on a setting that only the employee controls. How to set up a business account is covered in secure AI at work.
Nobody at the company can see what went in
Microsoft’s Copilot FAQ says that with enterprise data protection, prompts and responses “are logged, retained, and available for audit, eDiscovery” and other compliance tools. eDiscovery is the search a company runs to find records for a dispute. A personal account gives the company none of that. The chat history stays in the employee’s own account, including after they leave the company.
Your customers’ drawings and your obligations
A personal account puts your records with a vendor your company has no contract with. Under PIPEDA, the federal private-sector privacy law, you stay responsible for personal information you send to a third party for processing, and you must protect it by contract or other means (clause 4.1.3). A personal account leaves you no contract to point to. Quebec’s private-sector privacy act and the rules for controlled goods drawings add their own conditions, and secure AI at work sets them out rule by rule, with a link to each source. Your customers’ confidentiality terms can add more, so read your supply agreements and non-disclosure agreements before a customer’s drawing goes into any outside tool. This section is not legal advice, so ask your counsel how each rule applies to your records.
What the breach studies show
IBM’s 2026 report studied 602 organizations worldwide that had a breach between March 2025 and February 2026. Of those, 43% reported a security incident involving shadow AI, up from 20% the year before.
IBM’s 2025 report found that shadow AI incidents compromised intellectual property in 40% of cases, against a global average of 33%. Both studies look only at organizations that had a breach, so they do not measure how often shadow AI leads to one.
Not sure which AI tools are already in use
Tell Derik which teams use AI today and which records they work with. He will tell you where to start looking.
Start a conversationHow to find shadow AI in your company
The Canadian Centre for Cyber Security (the Cyber Centre) published its Top 10 AI security actions (ITSAP.10.049) in May 2026, for organizations of all sizes. Action 8 says to “map and identify sanctioned and unsanctioned models operating on a network.” A 30-person company can do that with the tools it already has.
- Ask everyone, with an amnesty. Ask which tool, for which task, with which data and on which account. Say in writing that an honest answer carries no penalty.
- Read the card statements. Check company card statements and expense claims for AI subscriptions.
- List the apps connected to company mail and files. In Microsoft 365, open Enterprise applications in Microsoft Entra. In Google Workspace, open Accessed apps.
- Review browser extensions. Check the extensions on company computers, and remove the ones nobody can explain.
- Look at meetings. Look for AI note-takers among meeting participants and in calendar invitations.
- Check the DNS or firewall logs. DNS turns a web address into a server address, so its logs show which AI services your computers reach. The Cyber Centre’s baseline controls say to put a DNS firewall on outbound requests (BC.9.2).
If you already license Microsoft Defender for Cloud Apps, its app catalog has a Generative AI category. Put the results on one page, one line per tool: the tool, who uses it, the task, the data and the kind of account. That list feeds the approval step below.
What happens when a company bans AI tools
Cisco’s 2024 Data Privacy Benchmark Study surveyed 2,600 privacy and security professionals in 12 geographies. Of them, 27% said their organization had banned generative AI applications for the time being.
A ban does not always stop the habit. In the Software AG survey of 6,000 knowledge workers, 46% said they would refuse to stop using personal AI tools under a ban. A network block has limits too. When Samsung restricted generative AI in 2023, TechCrunch reported that the rule covered company devices and personal devices on internal networks. A personal phone on cellular data does not touch the company network, so a block on that network does not reach it.
Netskope tracked generative AI use at a subset of its manufacturing customers from September 2024 to September 2025. Use of personal accounts held at around 83% through December 2024, then fell to 51% by September 2025. Over the same period, use of organization-approved tools rose from 15% to 42%. Netskope reads this as a growing preference for company-approved platforms, though the report does not show that one trend caused the other.
The Cyber Centre’s generative AI guidance (ITSAP.00.041) adds one more question. It says to consider “whether developing an in-house AI tool would be of higher value than using third-party products.”
How to prevent shadow AI: what to put in place
Give people an approved account that does the job
If your company runs Microsoft 365, start there. Microsoft’s Copilot FAQ says Copilot Chat comes with a Microsoft 365 subscription, with enterprise data protection when staff sign in with a work account. If it does not do the job your team needs, compare the options in ChatGPT alternatives for business in Canada.
Write the rule on one page
A shadow AI policy lists the approved tools, the records each one may receive and what to do about personal accounts. The AI policy page has a template you can adapt. Action 8 of the Cyber Centre primer also asks for an acceptable use policy for AI tools, with allow and deny lists.
Name who approves a new tool
Pick one person to approve new AI tools, and give staff a short way to ask. In Microsoft Entra, the admin consent workflow lets users request approval for an app they cannot connect on their own. Microsoft recommends allowing user consent only for apps from a verified publisher. Who decides, and which records to keep, is set out in AI governance.
Show people what goes where
PIPEDA asks organizations to train staff on their privacy policies (clause 4.1.4). It also asks them to make employees aware of why personal information stays confidential (clause 4.7.4). Use real examples from your own files, and name the account each one may go into. Hands-on AI training shows staff how to do the same work on the approved tool.
Repeat the check every quarter
Run the six checks again each quarter. New apps and extensions appear, and vendors change their terms, as Anthropic did for consumer accounts in August 2025. Update the approved list and the policy when that happens.
How ThriveAI helps
ThriveAI is an AI engineering company in Ottawa that builds private AI systems for manufacturers and distributors in Ontario and Quebec, on their own data. When staff reach for a personal account because the approved tool cannot do the job, such as drafting a quote from your own drawings and price history, ThriveAI builds a tool that can, and works hands on with your team while it does. Derik Lawlis, the founder, leads every project and stays close to the build.
The platform ThriveAI builds on is designed to keep your data on its own server in Canada. You choose the model. It can run on that server, or it can be a hosted model, one that a vendor such as Anthropic or OpenAI runs on its own computers. A hosted model is used under a written zero data retention agreement, which means the provider keeps no copy of your request or its answer. A hosted model may process requests outside Canada, so the contract names the model and its service tier.
Working sessions run on site with your team, in French or English. ThriveAI also runs hands-on training for your team, planned around the jobs you choose. Stage one is a working prototype for one job, at a fixed price, in weeks, and you keep it. For the company, see About ThriveAI. For the rest of the security picture, see AI security.