Security Stop-Press: Shadow AI Breaches Expected To Hit 40 Percent Of Enterprises By 2030

Gartner says 40 percent of enterprises will face a shadow AI related breach by 2030 as unapproved and unmanaged AI tools continue to spread across workplaces.

Shadow AI covers any AI system or workflow used without formal oversight, such as employees putting company data into public models or teams deploying internal tools with no security review. Gartner notes that rapid adoption of generative AI has already created visibility gaps in many organisations.

The firm points to risks including accidental data leaks, unsafe integrations, unmanaged API access, and insecure model deployment. Growing AI sprawl, fuelled by low code platforms and consumer AI services, is making it easier for staff to build or adopt tools that sit entirely outside IT governance.

Gartner places the warning within its AI TRiSM framework, arguing that many organisations still lack basic inventories of where AI is used and what data models can reach.

Clear AI governance, approved platforms, strict data handling rules, and active monitoring of AI use across the business can help reduce exposure to these emerging risks.

Tech Insight : Microsoft Warns: Shadow AI Rampant in UK Offices

Most UK employees are now using unapproved AI tools at work every week, according to new Microsoft research, raising fresh questions about security, privacy, and corporate control over artificial intelligence.

What Microsoft Found

Microsoft’s latest UK study reports that 71 per cent of employees have used unapproved consumer AI tools at work, and 51 per cent continue to do so weekly. The research, conducted by Censuswide in October 2025, highlights a growing trend known as “Shadow AI”, i.e., the use of artificial intelligence tools not sanctioned by employers. The (October 2025) Censuswide survey took account of the views of 2,003 UK employees, aged 18 and over. The sample included workers from financial services, retail, education, healthcare, and other sectors, with at least 500 respondents each from large businesses and public sector organisations.

Typical Uses of Shadow AI

According to Microsoft’s study, typical uses of Shadow AI include drafting or replying to workplace communications (49 per cent), preparing reports and presentations (40 per cent), and even carrying out finance-related tasks (22 per cent). Many employees say they turn to these tools because they are familiar or easy to access, with 41 per cent admitting they use the same tools they rely on in their personal lives. Another 28 per cent said their employer simply doesn’t provide an approved alternative.

Limited Awareness of the Risks

It seems that according to the study, awareness of the risks remains limited, which is a key part of the problem. For example, only 32 per cent of respondents said they were concerned about the privacy of customer or company data they enter into AI tools, while 29 per cent expressed concern about the potential impact on their organisation’s IT security.

As Darren Hardman, CEO of Microsoft UK & Ireland, says: “UK workers are embracing AI like never before, unlocking new levels of productivity and creativity. But enthusiasm alone isn’t enough,” and that “Businesses must ensure the AI tools in use are built for the workplace, not just the living room.”

Why It So Much Matters Now

The research reflects a wider cultural change in how employees are using artificial intelligence (AI) to handle everyday tasks. For example, Microsoft estimates that generative AI tools and assistants are now actually saving workers an average of 7.75 hours per week. Extrapolated across the UK economy, that equates to around 12.1 billion hours a year, or approximately £208 billion worth of time saved (according to analysis by Dr Chris Brauer of Goldsmiths, University of London).

That potential productivity boost most likely explains much of the enthusiasm around generative AI. However, it also highlights why workers are bypassing official channels. For example, when the tools provided by employers feel restrictive, employees often reach for whatever gets the job done fastest, even if that means using consumer platforms that fall outside company governance and data protection frameworks.

What Is ‘Shadow AI’?

The term “Shadow AI” is borrowed from “shadow IT”, which is a long-standing issue where employees use unapproved hardware or software without authorisation. In this case, it refers to staff using consumer AI tools such as public chatbots or online assistants to support work tasks. One potential problem with this is that these platforms often store or learn from user input, which may include company or customer data, creating potential security and compliance problems.

Organisations that allow this kind of behaviour to go unchecked, therefore, risk breaching UK data protection laws, regulatory obligations, or intellectual property rights (not to mention giving away company secrets). The British Computer Society (BCS) and other professional bodies have previously warned that shadow AI could expose firms to data leaks, non-compliance, and reputational harm if sensitive material is entered into consumer models.

The Real Risks for Businesses

The main security concern is data leakage, i.e., where employees enter sensitive company information into AI tools that may store or process data outside of approved systems. This could include confidential documents, client details, or financial data. Once that information leaves the organisation’s control, it may be impossible to delete or track, potentially breaching data protection law or confidentiality agreements.

Another issue that’s often overlooked by businesses is attack surface expansion. For example, the more third-party AI tools are used, the greater the number of external systems handling company information. This increases the likelihood of phishing, prompt injection attacks, and other forms of misuse. Also, there is the problem of auditability. When AI tools operate outside an organisation’s infrastructure, they leave no record of what data was used or how it was processed, making compliance monitoring almost impossible.

Earlier this year, a report by Ivanti found that nearly half of office workers were using AI tools that were not provided by their employer, and almost one-third admitted keeping it secret. Some employees even said they used unapproved AI to gain an “edge” at work, while others feared their company might ban it altogether. The study echoed Microsoft’s findings that even sensitive data, such as customer financial information, is being fed into public models.

Why Employees Still Do It

Despite the risks, many employees say they basically rely on consumer AI because it helps them manage workloads and meet rising productivity expectations. Microsoft’s study also found that attitudes towards AI have become far more positive over the course of 2025. For example, 57 per cent of employees now describe themselves as optimistic, excited or confident about AI (up from 34 per cent in January). Also of note, it seems the proportion of workers saying they “don’t know where to start with AI” has dropped from 44 per cent to 36 per cent, while more employees say they understand how their company uses the technology.

For many, the motivation is actually practical rather than rebellious. For example, AI chatbots help draft content, summarise notes, create reports and presentations, or even analyse spreadsheets. When deadlines are tight and workloads are high, these capabilities can make a tangible difference, especially if the employer’s own tools are limited or slow to adopt new technology.

A Balanced View

While much of the discussion has focused on the dangers of shadow AI, some experts suggest it can also be a useful indicator of where innovation is happening inside a business. For example, at the Gartner Security and Risk Management Summit in London, analysts Christine Lee and Leigh McMullen argued that rather than trying to eliminate shadow AI entirely, companies could benefit by identifying which tools employees are already finding valuable. With the right governance and security controls, those tools could be formally adopted or integrated into approved workflows.

In this sense, shadow AI can act as an early warning system for unmet needs. If, for example, marketing teams are using public generative AI tools to create campaign content, that may reveal a gap in internal creative resources or digital support. Security teams could then review those external tools, assess the risks, and replace them with enterprise-grade equivalents that meet the same needs safely.

Gartner’s approach reflects a growing recognition that employees are often ahead of policy when it comes to technology adoption. Turning shadow AI into an opportunity for collaboration, rather than conflict, could help businesses strike a balance between innovation and security.

What Organisations Can Do Next

Analysts and security experts are urging employers to start by improving visibility. That means identifying which AI tools are already being used across the organisation, and for what purposes. With this in mind, many companies are now running staff surveys or using software discovery tools to build a clearer picture of how generative AI is being adopted.

Once the extent of use is known, companies can then focus on education. Clear, accessible policies are essential, i.e., explaining in plain English what kinds of data can be entered into AI tools, what cannot, and why. Training should emphasise the risks of using consumer AI platforms, particularly when handling client, financial, or personal information.

Enterprise Grade Safer

The final step is to offer secure alternatives. Enterprise-grade AI assistants, such as those integrated into Microsoft 365 or other workplace systems, are designed to protect sensitive data and maintain compliance. These tools include encryption, access controls, audit logs, and data-loss prevention measures that consumer apps typically lack. As Microsoft’s Darren Hardman put it: “Only enterprise-grade AI delivers the functionality employees want, wrapped in the privacy and security every organisation demands.”

Where Shadow AI Is Most Common

Microsoft’s data shows that shadow AI use is most prevalent among employees in IT and telecoms, sales, media and marketing, architecture and engineering, and finance and insurance. This is likely to be because these are industries where high workloads, creative output, or data handling make AI assistants especially appealing. As confidence grows and tools become more sophisticated, use across sectors is expected to increase further.

Shaping Culture

The Microsoft research suggests this trend is already reshaping workplace culture. For example, more employees now see AI as an essential part of their organisation’s success strategy, a figure that has more than doubled from 18 per cent in January to 39 per cent in October. Globally, Microsoft’s Work Trend Index reports that 82 per cent of business leaders view 2025 as a turning point for AI strategy, with nearly half already using AI agents to automate workflows.

What Does This Mean For Your Business?

The rise of shadow AI appears to present UK businesses with a clear crossroads between risk and reward. Employees are demonstrating that AI can deliver genuine productivity gains, but their widespread use of unapproved tools exposes gaps in governance and digital readiness. For many organisations, this is not simply a security issue but a sign that workplace innovation is moving faster than policy.

In practical terms, the Microsoft findings suggest that companies which fail to provide secure, accessible AI tools will continue to see staff seek out consumer alternatives. That makes the issue as much about culture and leadership as it is about technology. Building trust through transparency, and ensuring employees understand how and why AI is being managed, will be critical to balancing productivity with protection.

For IT leaders, the challenge now lies in developing frameworks that enable safe experimentation without undermining compliance. That means investing in enterprise-grade AI infrastructure, tightening oversight of data use, and introducing training that connects security policy with real-world tasks. Businesses that achieve this balance will be able to harness AI’s benefits while maintaining control over how it is deployed.

The implications extend beyond individual firms. For example, regulators, industry bodies, and even customers have a stake in how securely AI is used in the workplace. As more sensitive data flows through AI systems, the pressure will grow for clear accountability and transparent governance. The Microsoft findings make it clear that AI adoption in the UK is no longer confined to innovation teams or pilot projects; it is now embedded in everyday work. How organisations respond will determine whether this new era of AI-driven productivity strengthens trust and competitiveness, or exposes deeper vulnerabilities in the digital workplace.

Tech Insight : Shadow AI and Shadow SaaS Risks?

A Next DLP survey (conducted at RSA Conference 2024 and Infosecurity Europe 2024) has revealed how the rise of ‘Shadow SaaS’ and ‘Shadow AI’ may be putting businesses at risk of data loss, lack of visibility, and data breaches.

What Are Shadow SaaS and Shadow AI? 

Shadow SaaS refers to the use of software-as-a-service (SaaS) applications within an organisation without explicit approval from the IT department. Similarly, Shadow AI involves the deployment of AI tools and solutions without official oversight. The issue for businesses is that these shadow technologies often bypass the stringent security protocols and oversight that sanctioned IT solutions are subjected to, thereby creating potential vulnerabilities.

Prevalent 

One notable fact that the Next DLP survey established is the prevalence of SaaS applications in organisations, with almost three-quarters of security professionals (73 per cent) admitting to using SaaS applications that had not been provided by their company’s IT team in the past year.

Key Findings from the Next DLP Survey 

The Next DLP survey, which captured insights from industry professionals at two major conferences, appears to have revealed some of the more potentially negative implications of the use of Shadow SaaS and Shadow AI in organisations. For example, the survey reveals three primary areas of concern – data loss, lack of visibility, and data breaches.

Data Loss 

The unregulated nature of Shadow SaaS and Shadow AI can mean that sensitive data can easily be transferred, shared, or stored outside the secure confines of the company’s IT infrastructure. However, one key issue highlighted by the Next DLP survey, is the apparent disparity between employee confidence in using unauthorised tools and the organisation’s ability to mitigate the risks. For example, 65 per cent of respondents named data loss as a top risk of using unauthorised tools, and it appears that (according to 40 per cent of security professionals) employees may not fully understand the data security risks posed by shadow SaaS and shadow AI.

The survey respondents noted multiple instances where critical business data was inadvertently exposed or lost due to the use of unauthorised applications and AI tools.

This data loss can not only hamper business operations but also puts companies at risk of non-compliance with data protection regulations.

Lack of Visibility 

Another significant challenge highlighted by the survey appears to be the lack of visibility over shadow technologies. Without proper oversight, IT departments cannot track or manage these applications, making it difficult to enforce security policies or detect anomalies.

The survey indicated, for example, that 62 per cent of respondents are concerned about the lack of full visibility and control of the SaaS and AI tools being used within their organisations, thereby leading to unmanaged risks and potential security gaps.

Data Breaches

The integration of unauthorised applications and AI tools also significantly increases the risk of data breaches for organisations. For example, shadow technologies often lack the strong security measures that are standard in approved IT solutions.

The Next DLP survey reflected this by showing that just over half (52 per cent) of respondents see data breaches as a top risk of using unauthorised tools. The survey also reported an apparent surge in security incidents linked to shadow applications, with many businesses experiencing breaches that compromised sensitive information. For example, 10 per cent of respondents admitted they were certain their organisation had suffered a data breach or data loss as a result of Shadow SaaS usage

Data breaches not only result in financial losses but also damage the reputation of the affected companies.

Understanding of Shadow SaaS and AI Risks 

As previously touched upon, the Next DLP survey also revealed gaps in employee training and awareness regarding Shadow SaaS and AI risks in their organisation. For example, it showed that 40 per cent of security professionals believe employees do not understand these risks, and only 37 per cent have developed clear policies and consequences for unauthorised tool use. Also, 20 per cent admitted to being unaware of their company’s policy updates or training on these risks and 20 per cent also said they hadn’t received any guidance and updated policies in the past six months.

Such findings, therefore, appear to highlight the need for improved awareness and education on managing shadow technologies.

What To Do? 

To mitigate the risks associated with Shadow SaaS and Shadow AI, businesses may, therefore, benefit from adopting a proactive approach and using key strategies such as:

– Enhanced monitoring. Implementing advanced monitoring tools to detect and manage unauthorised applications.

– Employee education. Training employees on the risks of using unapproved technology and the importance of adhering to company policies.

– Robust policies. Developing and enforcing clear and comprehensive IT policies that address the use of SaaS and AI tools.

– Promote approved alternatives. For example, encouraging the use of approved and secure alternatives to unauthorised applications can help reduce reliance on risky shadow technologies. Currently, only 28 per cent of organisations promote such alternatives.

– Regular audits. Conducting regular audits to identify and remediate any instances of shadow technology usage.

What Does This Mean For Your Business? 

The findings from the Next DLP survey reveal a critical need for businesses to address the growing risks associated with Shadow SaaS and Shadow AI. The prevalence of unauthorised tools, combined with the significant risks of data loss, lack of visibility, and data breaches, all highlight the urgency for a strategic response.

For businesses, this means taking proactive steps to manage and mitigate these risks. For example, implementing advanced monitoring tools can help detect and control the use of unsanctioned applications and AI tools. By gaining full visibility into the tools employees use, businesses can better enforce security policies and detect anomalies early.

Employee education is another way to mitigate the risks. Training staff about the dangers of using unauthorised technologies and the importance of adhering to company policies can significantly reduce the likelihood of data breaches and other security incidents. Developing and enforcing clear and comprehensive IT policies can also help ensure that all employees understand the consequences of using unapproved tools.

Promoting the use of approved, secure alternatives, encouraging employees to rely on sanctioned applications and having regular audits are also ways that businesses can minimise the risks associated with Shadow SaaS and Shadow AI, identify and address any instances of shadow technology usage, and ensure continuous compliance and security.

Adopting these kinds of proactive strategies may mean that businesses can safeguard against the vulnerabilities posed by unauthorised applications and AI tools, protect their sensitive data, and enhance their overall security posture, thereby helping to avoid the pain of financial losses and reputational damage.