A sales rep who pastes a confidential pricing grid into ChatGPT to have it reworded. An HR manager who has Gemini analyze resumes. An accountant who submits a projected balance sheet to Claude via his personal account. None of these actions go through the IT department; none are tracked. This is Shadow AI : the use of artificial intelligence tools by employees outside of any framework approved by the organization’s IT department.
Shadow AI Statistics and Figures in France
Not all studies on this topic measure the same thing, which explains the significant discrepancies between sources. A YouGov YouGov conducted for Microsoft France in January 2026 among 657 executives and managers at French companies reveals that 61% of corporate AI users access the technology through their personal accounts at least once a week, outside of any IT framework. In contrast, theOkta AI Agents at Work 2026 , conducted in seven countries (Australia, the United States, England, Canada, Japan, Germany, and France), ranks France as the most cautious of the seven countries studied, with a “Shadow AI” rate of approximately 31%—the lowest level compared to a global average that is significantly higher.
This discrepancy is not an inconsistency: Okta measures self-reported instances of unauthorized use, while YouGov measures the frequency of logins via personal accounts. Above all, the data from Okta’s report shows that the risk is not limited to unauthorized use: even approved AI tools can expose organizations when governance and security controls are insufficient.
Why Shadow AI Is More Dangerous Than Shadow IT
The term is derived from “Shadow IT,” which has long referred to the use of software not approved by the IT department. But the comparison has its limits. An unapproved project management tool poses a governance issue; an unapproved generative AI tool actively absorbs the data submitted to it, can store it, reuse it for its own training, and in some cases expose it to other users. The data does not simply pass through the tool—it becomes an integral part of how it operates.
The Samsung case remains the benchmark in this area: in March 2023, three engineers copied confidential source code into ChatGPT to debug a program and generate a meeting summary. In less than a month, the company experienced three separate leaks, with proprietary code left exposed on third-party servers for an extended period—code that could not be removed.
The 4 Major Risks of Shadow AI to Corporate Security
- Data Leaks and Intellectual Property: Several recent studies estimate that a majority of the Shadow AI tools detected in companies had already ingested sensitive data: source code, customer files, and regulated internal documents.
- GDPR Non-Compliance: As soon as a consumer-grade tool processes personal data (resumes, HR data, customer information) without a data processing agreement or a guarantee of deletion, the company remains responsible for the processing, regardless of the tool used by the employee.
- Lack of traceability: Without logging, it is impossible to determine which employee used which tool to produce which deliverable, which becomes critical in the event of a customer dispute or industry-specific documentation requirements.
- Direct financial impact: the IBM report on the cost of data breaches estimates the average additional cost of breaches for organizations with high levels of Shadow AI at several hundred thousand dollars, compared to those that have it under control.
AI Risk Management: Why a Blanket Ban Fails
Several large organizations, including banks, have attempted to outright block access to consumer AI tools, only to find that employees continued to access them via their personal devices or connections outside the corporate network. An executive interviewed in an Inria x Datacraft conducted in 2025 among major French companies sums up the paradox: bans lead to more covert use, not less. The driving force behind this phenomenon is not malicious intent but a lack of alternatives: when a company fails to provide a validated tool that is as effective as the ones employees are already familiar with in their personal lives, they bridge the gap themselves.
Action Plan: How to Map and Manage Shadow AI in 3 Steps
An effective response generally follows three steps, in this order:
- Measure before acting: An anonymous internal survey or a technical audit of network traffic can quantify the gap between actual usage and reported usage, without moralizing judgments that might encourage concealment.
- Provide a validated alternative: Deploying supervised access to one or more templates (via an enterprise platform with logging, filtering of sensitive data, and controlled data residency) automatically reduces the use of personal accounts, provided that the user experience remains competitive.
- Training and documentation: Clear guidelines for use, combined with brief training on what can and cannot be entered into an AI tool, address the skills gap identified as an aggravating factor in most recent studies.
This gradual approach—rather than a ban—is now supported by several case studies from French companies that have significantly reduced their rates of unauthorized use within a few weeks, not by blocking access, but by making the in-house alternative simpler and more reassuring than the consumer-grade solution.
→ To put this approach into a comprehensive framework, see our article on AI governance in business, as well as our article onthe EU AI Act for regulatory requirements.
Frequently Asked Questions About Shadow AI Security and Governance
Is Shadow AI only for large companies?
Is blocking access to ChatGPT at the network level enough?
How can you detect Shadow AI without monitoring each employee individually?
Map Your Exposure to Shadow AI
Our experts conduct audits that include an assessment of your exposure to Shadow AI and provide support for implementing an AI governance framework tailored to the size of your organization. Contact them.

