Ask a room of executives whether their company uses AI and you'll get a careful answer about the two or three approved tools. Ask their employees and you'll get a different picture entirely. In 2026 surveys, close to every organization — around 98% — has staff using AI tools that were never approved, and a large majority of knowledge workers who use AI at work bring their own. This is shadow AI: the drafting assistant in a browser tab, the coding copilot on a laptop, the chatbot someone pastes a contract into to 'summarize it quickly.' It is not malicious. It is just invisible.
2026 research is consistent: unsanctioned AI is nearly universal, it shows up in a large share of breaches, and a meaningful fraction of employees have put confidential data into public tools.
Why it turns into data loss
The risk is not that employees are careless; it's that public AI tools are frictionless and confidential data is right there in the clipboard. Studies of what people actually paste into consumer chatbots find sensitive content in a meaningful share of interactions — customer records, financial figures, internal strategy. Once that text leaves your environment, you have lost control of it: you don't know how it's retained, who can see it, or whether it becomes training data. And because the tool was never approved, none of it shows up in your logs. The first time security hears about it is often the incident.
Why 'ban it' doesn't work
The instinct to block all unapproved AI fails for the same reason blocking all cloud storage failed a decade ago: the tools make people faster, so people find a way. A ban you can't enforce simply pushes usage further into the dark, where you have even less visibility. The organizations getting ahead of shadow AI are not the ones with the strictest policy on paper; they're the ones who can see what's being used and then decide, tool by tool, what to sanction, what to route through controls, and what to shut off.
The path that works: discover, then govern
- Discover first: get visibility into which AI tools and agents are actually in use across the organization, because an unregistered tool is both a security gap and, increasingly, a compliance gap.
- Give people a sanctioned path: offer approved tools routed through controls, so the fast option is also the safe one and employees don't need to go around you.
- Put a checkpoint in front of the data: inspect and redact sensitive content before it leaves for a model, so a paste of a customer record doesn't become a leak.
- Turn on evidence: log what was used and what was blocked, so shadow AI becomes something you can see trending down instead of a blind spot.
This is the discover-then-govern loop, and it maps cleanly onto how Intertrace approaches the problem: find the AI in use, route it through a gateway that inspects and isolates, and keep the evidence. The goal is not to catch employees; it's to make the sanctioned path the easy path, and to make sure the sensitive data has a checkpoint between it and the open internet.