Skip to content
All posts

21 July 2026

5 min read

Written by

Clément Lacaille

Clément Lacaille

Founder, Tech-Bharat

About the author
Business & compliance

Shadow AI: what a 48,000-person global study found about employees using AI without telling anyone

Employees pasting company data into a free public chatbot, unrecorded and unapproved: shadow AI is not a fringe risk. A global study run with the University of Melbourne puts numbers on how widespread it already is.

Shadow AI is the simplest version of an old problem with a new name: an employee copying a client email, a contract draft or a spreadsheet of figures into a free, public AI chat interface to get a task done faster — with no company oversight of what was shared, where it went, or whether the output that came back was even correct. It is easy to assume this is marginal. The data says otherwise.

A study of 48,000 people across 47 countries

The Trust, attitudes and use of Artificial Intelligence: A global study 2025, led by the University of Melbourne in collaboration with KPMG, surveyed more than 48,000 people across 47 countries. Its findings on workplace use are specific enough to act on: almost half of employees admit to using AI in ways that contravene their company’s policy, including uploading sensitive company information into free public tools; more than half do not disclose that AI was used and have presented AI-assisted content as entirely their own; and only 47% report having received any AI training at all.

What this means for a company with no written AI policy

The risk is not only data leaking into a third-party tool’s training pipeline. It is the blind spots that come with it: work reviewed or approved on the assumption a person produced it, with no record that an AI tool was involved, no way to trace what data left the building, and — per the same study — barely two in five workplaces having any written guidance at all. A company without a policy is not avoiding the exposure by not naming it; it is simply not measuring it.

  • Write a one-page policy on what data can and cannot go into which tool — length is not the point, existence and clarity are.
  • Name a small number of sanctioned tools with an actual contractual data guarantee, rather than leaving staff to choose whatever free tool is fastest.
  • Train people — the study found only 47% had received any AI training, which correlates directly with unsanctioned use.
  • Give staff an approved, genuinely fast path for common AI-assisted tasks — shadow use largely exists because the sanctioned path is slower or does not exist.

Free resource

The self-assessment grid: 20 tasks AI can automate

Sales, admin, support, operations: the 20 tasks AI agents already handle in SMEs — with, for each one, the tell-tale sign that your team is concerned.

Read next