Key Takeaways
- Banning shadow AI doesn't reduce usage — it removes visibility, pushing prompts onto unmonitored personal devices and consumer tools with no logging or data-processing agreement.
- KPMG and the University of Melbourne found that 57% of employees hide their AI use, and only 40% work somewhere with any generative AI policy at all.
- IBM's 2025 data shows shadow AI is behind 1 in 5 breaches, adds USD 670,000 to the average cost, and disproportionately exposes customer personal data — a breach a DPO cannot document within GDPR's 72-hour window.
- The fix is one sanctioned AI entry point that is at least as capable as public tools, with content-level detection and full audit evidence built in.
- EU AI Act Article 4's AI-literacy duty has applied since 2 February 2025 — shadow AI is the direct negation of it, and a governed portal is the practical evidence of compliance.
In the first article of this series I argued that AI transformation stalls not for lack of ambition but for lack of governance. This article is about the most visible symptom of that gap, and the one most CISOs already have on their desk: shadow AI.
The term describes AI tools that employees use without the organisation's knowledge or approval — a consumer chatbot on a personal phone, a browser extension that summarises pages, a free-tier account opened with a work email. None of it is malicious. Almost all of it is invisible. And the first instinct of most security teams, to ban it, turns out to make it worse.
How big is the problem?

Figure 1 — Shadow AI, by the numbers.
Larger than most boards assume. The KPMG and University of Melbourne global study of more than 48,000 people in 47 countries found that 57% of employees who use AI at work hide it from their employer, 48% have uploaded company information to public AI tools, and only 40% say their organisation has a policy on generative AI at all. [1]
Gartner reports that 69% of cybersecurity leaders already have evidence, or strong suspicion, that staff are using public generative AI, and predicts that by 2030 more than 40% of organisations will suffer a security or compliance incident caused by it. [2]
Looking at the numbers alone is not enough — these shadow AI statistics carry a cost that is no longer hypothetical either. IBM's 2025 Cost of a Data Breach Report found that one in five breached organisations had been compromised through shadow AI, that these breaches cost on average USD 670,000 more than others, and that they disproportionately exposed customer personal data. [3]
For a European organisation that last figure has a second meaning: customer personal data is GDPR territory, and a leak through an unsanctioned tool is a leak the DPO cannot document, contain or report within the 72-hour window.
Why the ban fails
When Samsung discovered in 2023 that engineers had pasted source code into a public chatbot, it banned the tools outright. The reaction was understandable and widely copied. It is also a strategy that has never worked for any prior technology — not for USB sticks, not for personal cloud storage, not for messaging apps. Employees are not choosing AI over policy. They are choosing to finish the task by five o'clock, and the tool that helps them do that will be used on whatever device is not being watched.
A ban therefore does not reduce usage. It reduces visibility. The prompt still goes out; it now goes from a personal phone to a consumer service with no logging, no data-processing agreement and no way for anyone in the company to know it happened. The KPMG figures above — 57% hiding their use — are what a policy of prohibition looks like from the employee's side.
The security team has, in effect, traded a governance problem they could see for one they cannot.
Ban it vs. govern it
| Ban it | Govern it | |
|---|---|---|
| What happens to usage | Continues — just hidden | Continues — but visible |
| Where the prompt goes | Personal device → consumer AI tool | Company-sanctioned AI portal |
| Logging & data-processing agreement | None | Full audit trail, DPA in place |
| GDPR 72-hour breach response | Not possible — the DPO never knew | Evidence available on demand |
| EU AI Act Article 4 (AI literacy) | Untrained, unsupported use | Supported, demonstrable use |

Figure 2 — Two responses to shadow AI: the same prompt, two journeys (B as implemented in AnyInsight).
The alternative: one sanctioned door
The organisations that have got ahead of shadow AI share one decision. They stopped asking "how do we stop people using AI?" and started asking "how do we make the governed path the easiest path?" The answer is a single, sanctioned entry point that employees prefer to the consumer alternative, with governance applied inline rather than by policy document.
Three properties matter.

Figure 3 — Three properties of a sanctioned AI entry point.
| Property | What it means |
|---|---|
| 1. Equal capability | At least as good as the public tool — the same leading models, a familiar chat interface, and access from the devices people actually work on. If it is worse, it will be bypassed. |
| 2. Content-level detection | Controls act on the content of each prompt, not on the identity of the tool: personal, financial and health data, credentials and injection attempts detected by meaning, and either flagged, blocked, or masked so the work can continue without the sensitive fragment ever leaving. |
| 3. Audit-ready evidence | Every interaction leaves evidence — who asked what, which policy applied, what action was taken — in a form the DPO can hand to a supervisory authority. |
This is the model we built AnyInsight around. Employees work with more than twenty leading LLMs through one governed portal; a zero-trust GenAI firewall sits inline between every user, workflow and model, detecting sensitive content semantically rather than by keyword and applying alert, block or mask rules per workspace; and every event is written to downloadable logs and an immutable vault with the workspace, user, policy breached, severity and action recorded. Data stays in the EU and is never used to train any model. The intent is simple: give people a better tool than the one they are hiding, and make its use visible by design.
Where the EU AI Act comes in

Figure 4 — Two obligations shadow AI already breaks: GDPR and EU AI Act Article 4.
Since 2 February 2025, EU AI Act Article 4 has required providers and deployers to take measures supporting the AI literacy of staff and other people who use AI systems on their behalf. It does not require guaranteeing any specific level of AI literacy for any one individual, but it does require organisations to be able to show they are supporting it — something shadow AI, by definition, makes impossible. Shadow AI is the direct negation of that duty: usage that is untrained, unrecorded, and unsupported by any meaningful AI literacy training. A governed entry point is not only a security control; it is the practical evidence that the organisation knows where AI is being used, by whom, and with what training.
What to do this quarter

Figure 5 — Four steps for this quarter.
- Measure before you decide. Network logs and SaaS discovery tools will show which public AI services are already in use and from where; the number is usually a surprise.
- Replace, don't just restrict. Stand up a governed alternative that is at least as capable as the public tools, and announce it as an enablement rather than a control. Platforms such as AnyInsight are built for exactly this.
- Put the policy in the pipeline. Detection and masking of sensitive data belongs in the request path of the generative AI policy itself, not in a training slide.
- Make the evidence automatic. If an incident happens, the question will not be whether you had a policy, but whether you can show what was sent, by whom, and what stopped it.
Conclusion
Shadow AI is not a discipline problem. It is a demand signal — proof that your people want the productivity and have been given no safe way to get it. Meeting that demand with a governed door is the fastest route from unmanaged risk to managed capability.
If your business is ready to trade an unmanaged shadow AI problem for a governed one, AnyInsight's team can walk you through what a sanctioned entry point looks like for your organisation.
In the next article I will look at what happens when AI stops answering questions and starts reading your systems: identity, access and audit for RAG and connected agents.

Figure 6. This series runs four parts; this is Part 2. Part 1 covered the governance bottleneck; Parts 3 and 4 will cover identity and audit for AI on ERP/CRM, and evaluating an AI Act-era platform.
![[Governed AI Transformation 03]If AI Can Read It, AI Can Leak It](http://www.anyinsight.ai/cdn/shop/articles/Governed_AI_Transformation_03_If_AI_Can_Read_It_AI_Can_Leak_It_36e2b4b3-3d64-4e02-9cad-1d9b6687daf5.png?v=1789973238&width=900)
![[Governed AI Transformation 04]Ten Questions to Ask Before You Buy an Enterprise AI Platform](http://www.anyinsight.ai/cdn/shop/articles/Governed_AI_Transformation_04_Ten_Questions_to_Ask_Before_You_Buy_an_Enterprise_AI_Platform_ec68b633-dcae-4913-a91b-ccf6e5d2a015.png?v=1789973246&width=900)
![[Governed AI Transformation 01]The Bottleneck Isn't Ambition. It's AI Governance.](http://www.anyinsight.ai/cdn/shop/articles/Governed_AI_Transformation_01_The_Bottleneck_Isn_t_Ambition_It_s_AI_Governance_30b77d6a-6b2f-49e4-8f73-703f00562879.png?v=1789973220&width=900)