In May 2024, Microsoft and LinkedIn published the Work Trend Index, a study run by Edelman Data & Intelligence with 31,000 professionals across 31 countries. The number that made the headlines: 75% of knowledge workers were already using generative AI at work.
The number that deserved more attention is different. According to the same report, 78% of those people bring their own AI tools to work — tools the company did not choose, did not buy and, in most cases, does not know exist. In small and mid-sized companies the figure rises to 80%. Among Gen Z professionals, it reaches 85%.
And there is a third data point, the most uncomfortable one: 52% of people using AI at work are reluctant to admit they used it on their most important tasks. It is not only the tool that stays invisible to IT. The task does too.
The market gave this a name: shadow AI — personal AI assistants, in personal accounts, with company information inside. It is not an individual behaviour problem; it is a problem with how work is set up.
The case that became a global warning
In April 2023, engineers at one of Samsung's largest divisions pasted chip source code, internal meeting notes and confidential information into a public AI assistant. On 2 May, an internal memo temporarily restricted generative AI on corporate devices and asked employees not to submit company information to those tools, even on personal devices. Non-compliance could lead to dismissal.
The most revealing part of that memo is not the ban. It is the justification: the company said it was "reviewing security measures to create a secure environment for safely using generative AI" and that, until those measures were ready, use would be restricted.
In other words: not even Samsung believed banning was the answer. Banning was what could be done while no official place existed for that work to happen. Three years later, most companies are still in that holding pattern — except the usage never stopped.
Banning does not work, and there is evidence

A survey by the security training company Anagram, published in August 2025 with 500 full-time US employees, found that 45% of respondents had used AI tools banned by their employer at work — 26% of them within the week before the survey.
The Cloud Security Alliance, in a research note from May 2026, reached a similar picture from the infrastructure side: 80% of employees use unapproved AI tools and 71% of all connections to generative AI tools happen through personal accounts, outside the company's identity controls. The same note records that only 37% of organisations maintain any AI governance policy.
The correct reading of these numbers is not "employees are undisciplined". It is simpler: someone has work to deliver today, and the only tool that solves it sits outside the company. Between breaking a policy and not delivering, a good share choose to deliver. A policy with no official alternative does not reduce usage — it reduces visibility of it.
And visibility has a price. IBM's 2025 Cost of a Data Breach Report, produced with the Ponemon Institute, measured that organisations with high shadow AI usage carried an additional USD 670,000 per incident. In the same study, 63% of affected organisations had no AI governance policy and 97% of those that suffered an AI-related security incident admitted they lacked proper access controls.
The pattern across all three studies is the same: the problem is rarely the AI model, and more often that nobody knows who asked what, with which information, and under whose authorisation.
What is actually at stake
When someone in finance pastes an accounts-receivable spreadsheet into a personal assistant to "summarise the overdue items", four things happen at once:
- the information leaves the company perimeter through a route nobody designed;
- the answer is produced with no connection to what the company considers official — the current policy, the current price list, the approved process;
- there is no searchable record that any of it happened;
- and the knowledge created there dies in that one person's chat history.
The first two items are risk. The last two are waste: the company pays the cost of the risk and gets nothing in return — not the routine that was discovered, not the script that worked. That is why the useful answer is not a stricter policy, but an official place where the same task is easier to do than in a personal account — and, by design, better controlled.
What has to be in place

A governed AI environment is defined by four verifiable mechanisms, not by a promise.
Corporate identity, not a personal account. Access comes from the company directory: people sign in with the same network login, the profile comes from there, and someone removed from the directory loses access along with it — no dependency on a person remembering to revoke a stray account. That is exactly the gap those 71% of personal-account connections leave open: when AI sits outside the identity lifecycle, a former employee keeps signing in and nobody notices.
Access role by role. Each person and each agent see only what their role authorises. If an integration exposes dozens of functions and the support team needs two, those two can be released — not the whole tool because "there was no other way".
Approval matching the risk. Sensitive actions stop and ask a person to confirm before going ahead, inside the conversation itself. Critical documents can require two-step review and approval, with whoever writes kept separate from whoever approves. That answers one specific question: who authorised this content to become official information the AI will use?
Audit trail. Creating an agent, approving a document, changing a permission, running a sensitive action: all of it recorded. In an audit or an incident investigation, that is the difference between reconstructing what happened in minutes and not being able to reconstruct it.
None of these controls is about distrusting the team. They are about giving it a place to use AI without every individual carrying alone the decision of what may go into a text box. That is how Skyller was designed: identity from the company directory, role-based permissions, approval and logging as the default rather than an optional setting.
From individual improvisation to team capability
The governance gain is the easiest one to sell internally. But what usually settles the conversation is different: when AI use happens in personal accounts, whatever works well stays locked to whoever discovered it. The analyst who spent months building the perfect script for answering a tax dispute is the only person in the company who has it.
In a governed environment, the path is different. Agents, scripts, conversations, spaces and flows can be made available to other people and groups within the permitted scope, with defined roles and permissions. Someone on the team creates; the whole company moves forward. And the company does not start from scratch: Skyller, for instance, ships with more than 170 ready process and policy templates.
There is a budget effect too. In the personal-account model, everyone buys their own subscription — leaving underused individual licences on one side and people hitting their limit on the other. Credits shared across the team solve both: whoever needs more uses more, and consumption stays visible.
Three questions to take into your next meeting
Before writing another policy, answer these three questions with IT and operations leadership:
- If an employee is let go today, how many AI tools can they still sign into tomorrow? If the answer depends on somebody remembering to cancel accounts, this is not a policy problem — it is an identity problem.
- When AI answers a question about an internal rule, where did that content come from and who authorised it to be used that way? With no review and approval step, any outdated file can become the official answer.
- What did the company learn about its own AI usage last quarter? If the answer is "nothing", usage is not lower. It is just out of sight.






