Shadow AI is an emerging organizational phenomenon in which employees or teams use, develop, or integrate artificial-intelligence tools for work without the explicit approval, supervision, or effective governance of the organization’s IT, security, legal, or compliance functions.
Method
Exploratory practitioner survey via social media polling
Key findings
• AI use is already embedded in daily work: 69% of respondents use AI assistants for most tasks, and another 22% use them for repetitive work.
• Productivity benefits are tangible but uneven: 47% report daily acceleration, while 47% say AI helps only a little.
• Organizational knowledge is being privatized: 100% of respondents keep their most useful prompts in personal accounts rather than shared company repositories.
• Employees are asking for enablement, not prohibition: 56% prioritize professional licenses and 22% want team training.
• Data protection remains improvised: respondents use inconsistent sanitization practices, and there is no common understanding of where data sent through AI tools ultimately goes.
Shadow AI
Shadow AI is an emerging organizational phenomenon in which employees or teams use, develop, or integrate artificial-intelligence tools for work without the explicit approval, supervision, or effective governance of the organization’s IT, security, legal, or compliance functions. It can be understood as an AI-specific extension of shadow IT, but it introduces additional risks because employees may disclose sensitive information to external models, rely on unverifiable outputs, or embed probabilistic AI decisions into business processes without adequate transparency, validation, traceability, or accountability. Typical examples include using personal accounts for ChatGPT, Claude, Gemini, or other generative-AI services to summarize confidential documents, generate software code, analyze customer data, prepare reports, evaluate job candidates, transcribe meetings, or create unofficial AI agents and automated workflows outside approved corporate platforms. Researchers emphasize that such use is not necessarily malicious and is often motivated by productivity pressures, easy access to consumer AI tools, or the absence of adequate organizational alternatives.
Although no globally standardized measure of Shadow AI prevalence yet exists, available evidence suggests that it is widespread: Microsoft and LinkedIn’s 2024 survey of 31,000 workers across 31 countries found that 75% of knowledge workers used AI at work and that 78% of those users brought their own AI tools into the workplace, implying that approximately 59% of surveyed knowledge workers engaged in behavior that could potentially fall within the broader category of Shadow AI, depending on whether those tools and use cases were organizationally approved and governed. The practical scale of the associated governance problem is further illustrated by Cisco’s survey of 2,600 privacy and security professionals across 12 countries, in which 48% reported that non-public organizational information had been entered into generative-AI tools, despite widespread restrictions on acceptable tools and data.
Over the past few weeks, we ran a small but telling piece of research on LinkedIn, reaching out directly to developers and IT professionals. The goal was simple: to see what AI adoption actually looks like in day-to-day work, beyond the marketing claims. We asked six questions covering how often AI assistants are used, their impact on delivery speed, how prompt knowledge is managed, and — perhaps most importantly — how data is handled.
The results paint a clear, and slightly unexpected, picture: AI has been adopted deeply, but almost entirely without oversight. That's the definition of what the industry now calls Shadow AI.
What the numbers show






AI is already everywhere — it's not "coming." A striking 69% of respondents use AI assistants daily for most of their tasks, with another 22% using them for repetitive work. Practically no one (0%) works without AI at all. The question is no longer "should we adopt AI," but "do we actually know what's already happening."
Productivity gains are real, but not dramatic. 47% of users say AI speeds up their work every day, while an equal 47% say it "helps a little." Interestingly, no one reported too many mistakes caused by AI, though 6% said it actually slows them down. The takeaway: AI delivers real, measurable value — but not magic. Results depend heavily on how well a team actually knows how to use it.
The best knowledge stays locked in private accounts. This might be the single most important finding of the research: 100% of respondents keep their best, most useful prompts in a personal, private account. None share them through internal channels, a central database, or a team space. In other words, companies are already building organizational knowledge about AI — except that knowledge physically lives in individuals' heads and private accounts, not inside the organization.
Teams know what they need — they're just waiting on the company. When asked what would make working with AI assistants easier, 56% said Pro licenses for everyone, 22% wanted team training, and 11% each pointed to ready-made prompts or clearly defined, client-approved AI use. The message is clear: people aren't asking for permission to use AI — they're already using it. What they're asking for is the tooling and framework to do it safely and efficiently.
Data hygiene is inconsistent and improvised. An equal 33% of respondents said they clean up code before pasting it into a free AI tool, manually strip out names and IDs, or rely on an enterprise AI solution instead. Not a single respondent admitted to pasting code "as-is" — which is somewhat reassuring, but it also shows that everyone is improvising their own informal safeguard, rather than following a single, unified policy.
No one really knows where their data actually ends up. The final question gets to the heart of the issue: when asked whether they had ever checked where their private AI plugins send their code, answers split evenly across four categories — from "no idea, it just gets done" to "I read the fine print." That even split itself is telling: there's no standardized practice or organizational awareness — everyone is figuring it out on their own.
Conclusion: welcome to the Shadow AI era
Taken together, these results reveal a clear pattern. AI isn't something on the horizon for the software industry — it's already deeply embedded in everyday work, with a real, measurable impact on productivity. But most of that adoption is happening below the radar: individually, informally, and without any organizational structure behind it.
That's the essence of the Shadow AI phenomenon — not malicious use, but entirely rational behavior from individuals who want to work faster and better in the absence of clear tools, policies, and guidance from their company. The problem isn't that people are using AI. The problem is that companies often have no visibility into how it's being used, what data is involved, or which channels it's flowing through.
The consequences are concrete:
- Knowledge loss — the best prompts and hard-won lessons disappear the moment an employee leaves or simply forgets what they did.
- Security risk — code, credentials, and client data may be passing through tools whose privacy practices no one at the company has ever formally reviewed.
- Wasted potential — teams that could be sharing proven prompt libraries and workflows instead reinvent the wheel every single time.
The answer isn't banning AI tools — the research makes clear that would be both unrealistic and counterproductive. The answer is channeling the energy that's already there: enterprise-grade tools, clear data policies, a shared knowledge base, and proper team training — so that what today happens spontaneously becomes tomorrow's competitive advantage instead of a hidden risk.
Why this is more than research to us
At TIAC, we don't treat AI as a trend to talk about — we treat it as a tool we test, measure, and refine on a daily basis, both within our own teams and through our work with clients. This research is part of our broader commitment to understanding how AI is actually being used in software engineering — grounded in real data from the community, not assumptions.
That's exactly why we're investing in building internal AI practices that address these very challenges — from properly storing and sharing prompt knowledge, to securely handling client code and data, to training teams to use AI responsibly and effectively. Our goal isn't just to keep up with AI trends, but to be the partner of choice for companies that want to adopt AI the right way: structured, secure, and with measurable results.
If your organization recognizes a similar pattern — high but informal AI usage — we'd be glad to share what we've learned and how we're approaching this challenge.
This research is part of a broader TIAC study on AI adoption in software engineering. The full report, with additional insights, will be available soon.





