AI Strategy

Shadow AI is not a discipline problem

August 20, 2026 Shadow AI AI Governance AI Strategy

Shadow AI is what happens when your team uses AI tools your business has not approved. This piece explains why bans increase hidden use in professional services firms, and what to look at instead of writing a stricter policy.

Two thirds of office workers have used AI at work while believing it was against the rules.

Not people who were unsure. People who thought there was a policy, and used it anyway.

A third said they would not tell their manager.

That finding comes from a PagerDuty survey of 1,250 office professionals, reported in June. Almost every write-up of it landed in the same place. Governance failure. Write a clearer policy. Run a training. Lock the tools down.

I read it the other way around.

The pressure is running the wrong direction

I research what I call the pressure to AI. What happens to people when adoption gets pushed on them before they have decided anything.

Nearly every incident I log runs downward. The board wants an AI strategy. A client asks what you are using. Someone buys a tool and mandates it in a Monday meeting. Pressure lands on a professional from above, and they comply, resist, or find some third way through.

This one runs upward.

Nobody told these people to use AI. They were told not to. They did it anyway, and they hid it.

The rule did not stop the behaviour. It moved it somewhere you cannot see.

That is a different problem than the one most firms think they have.

What people are actually protecting

The same survey asked why. About 30% pointed at restrictive policy or how coworkers would react. Another 29% said they were not clear what the rules were.

Eighty one percent believed leadership plays by a different set of rules than everyone else.

Seventy two percent believed they understood AI better than the people writing the governance.

Sit with that last one for a second. Your team has quietly decided they know more about this than you do. They may be wrong. It does not matter. They are acting on it.

Researchers at Duke ran four preregistered experiments with 4,439 people and found that using AI at work earns you negative evaluations of your competence and your motivation. Not the work. You.

The same study found the penalty disappears when the person evaluating you uses AI themselves.

Read those two findings next to the 81% who think leadership plays by different rules, and the hiding stops looking like dishonesty. It starts looking like a correct reading of the room.

So the person doing good work with AI has a straight choice. Say nothing and keep the reputation. Say something and take the hit.

Most people say nothing.

An attorney sanctioned in Hawaii for filing a fake AI citation put it plainly to a reporter. Nearly every lawyer he knows uses AI. It is only a problem if they get caught.

The penalty attached to being seen. Not to using it.

The part that should actually worry you

Here is what walks out the door while everyone is arguing about policy.

Forty three percent of respondents had pasted emails or work data into public AI tools. More than a third had pasted customer information. Thirty one percent had pasted financial records, confidential documents, or internal strategy.

Some of them do it on personal devices, specifically so there is no trace.

That is the cost of the ban. Not that people use AI. That they use it on hardware you do not manage, in accounts you cannot audit, with your client files in the prompt.

I work with law firms, financial practices, and consultancies here in Halifax and across Atlantic Canada. The exposure is the same everywhere. The firm that wrote the strictest policy usually has the least idea what is actually happening.

One caveat, because it matters

PagerDuty sells workplace AI and automation tooling. A vendor running a survey that finds widespread unmanaged AI use has an interest in the answer.

I still think the finding holds, because three other datasets point the same way. KPMG and the University of Melbourne surveyed more than 48,000 people across 47 countries and found 57% hide their AI use and present the work as their own. A Slingshot survey of 500 US workers in January found 45% keep it quiet. Microsoft and LinkedIn found 52% of people who use AI at work are reluctant to admit using it on their most important tasks.

Different firms. Different years. Different sample sizes, and one of those is small. Same shape.

But you should know who paid for the number before you quote it. Most of the articles about this one did not tell you.

What this changes

The question is not whether your team uses AI. Assume they do. Two thirds of them, at minimum, and the number climbs at larger firms.

The question is what happens to the first person who tells you.

If the honest answer is “a difficult conversation,” you already know why nobody is telling you.

Eight percent of organisations have a comprehensive approach to governing AI. Among small firms, 2% say theirs is robust.

The other 98% are not reckless. They are just running a business that changed faster than anyone could write it down.

I am not going to tell you the fix is a better policy. A policy is a sentence. What you actually need is to know what your people are already doing and why they decided not to mention it.

That is a harder question. It is also the only one with a useful answer in it.

Start there.


If you want a place to begin, the AI Reality Check is a free diagnostic that sorts where you and your team actually sit with AI adoption. It takes a few minutes and there is no pitch at the end. For how this plays out inside a law practice, the Koby Smutylo case study covers the version of this conversation I have most often. And if the vocabulary is the barrier, shadow AI and 66 other terms are defined in plain language in the glossary.

Frequently asked questions

What is shadow AI?

Shadow AI is the use of AI tools inside a business without the approval or knowledge of the people responsible for the business. Carol Roderick defines it in her glossary as the AI tools your team is definitely using, right now, without telling you, probably with a client's files pasted in. It is called shadow because it happens in the dark.

Why do employees hide their AI use from managers?

Research points at reputation rather than rule breaking. A Duke study found that disclosing AI use makes colleagues judge a person as less competent and less motivated. PagerDuty found around 30% of workers cite restrictive policy or coworker reaction as the reason they stay quiet, and 29% are simply unsure what the rules are. The penalty attaches to being seen using AI, not to using it.

Does banning AI tools stop shadow AI?

The available data suggests it does not. In the PagerDuty survey, 66% of office professionals used AI while believing it was prohibited, rising to 72% at organisations with more than 1,500 staff. Carol Roderick's position is that a ban relocates the behaviour onto personal devices and unmanaged accounts rather than ending it, which increases exposure instead of reducing it.

What is the real risk of shadow AI for a professional services firm?

Data leaving the business through channels nobody can audit. In the same survey, 43% of respondents had entered work data or emails into public AI tools, more than a third had entered customer information, and 31% had entered financial records or confidential documents. For firms holding client files under professional obligation, that is a confidentiality and insurance question, not an IT one.

How many businesses have a real AI governance approach?

Very few. Research by Economist Impact, surveying 639 senior decision makers across five global cities, found that 8% of organisations have implemented a comprehensive AI governance approach, and only 2% of small firms describe theirs as robust. Carol Roderick's view is that adoption moved faster than anyone could write rules for it, one subscription at a time.

Sources

Efosa Udinmwen, “Intentionally hide using AI: two-thirds of office workers admit to secretly using banned AI tools, despite the risks,” TechRadar Pro, 18 June 2026. Reporting a PagerDuty survey of 1,250 office professionals at organisations with revenue above $500 million, across Australia, Japan, the United Kingdom and the United States. Read it here.

PagerDuty, Shadow AI Workplace Survey 2026. Read it here.

Reif, J. A., Larrick, R. P., and Soll, J. B., “Evidence of a social evaluation penalty for using AI,” Proceedings of the National Academy of Sciences, 122(19), May 2025. Four preregistered experiments, N = 4,439. Read it here.

Gillespie, N., Lockey, S., Ward, T., Macdade, A., and Hassed, G., Trust, attitudes and use of artificial intelligence: A global study 2025. University of Melbourne and KPMG International, 29 April 2025. Over 48,000 respondents across 47 countries, fielded November 2024 to January 2025.

Slingshot and Infragistics, Digital Work Trends Report, Part 1, 15 January 2026. Survey of 500 US adults, fielded by Dynata.

Microsoft and LinkedIn, 2024 Work Trend Index Annual Report, 8 May 2024. 31,000 knowledge workers across 31 markets.

Economist Impact, From intent to action: the leaders' guide to building AI-powered workplaces, 2026. Survey of 639 senior decision makers across London, New York, Singapore, Sydney and Tokyo.

404 Media, on a Hawaii attorney sanctioned for an AI-generated citation.


Carol Roderick, PhD is an AI adoption consultant and implementation partner working with professional services firms across Canada and the United States. She holds a doctorate in education and researches the pressure to adopt AI, drawing on a live incident log of real cases. She is the author of AI Jargon: A Dictionary for the Rest of Us and is based in Nova Scotia. Connect on LinkedIn or visit carolroderick.ca.