ComplianceAI

    88% of Businesses Have a Shadow AI Problem Leadership Can't See

    Theo Bergqvist
    Theo BergqvistSeptember 4, 20265 min read
    88% of Businesses Have a Shadow AI Problem Leadership Can't See — Turbotic automation strategy article

    New Turbotic research finds 88% of UK leaders believe Shadow AI is used in their business, and 51% fear staff are leaking sensitive data into unauthorised tools. Here's what it means and how to fix it.

    Shadow AI is the unauthorised use of AI tools by employees without formal approval or oversight from their organisation. New research from Turbotic, surveying over 1,000 senior UK decision-makers, found that 88% believe it is already happening inside their business — and 51% fear staff are feeding sensitive company data into these unapproved tools. Despite this, 27% of the leaders responsible for AI decisions hadn't heard the term "Shadow AI" before being asked.

    This isn't a hypothetical risk. It's the current, unmanaged reality inside most UK organisations — and it's growing faster than most leadership teams can track.

    Key findings at a glance

    Metric Finding
    Believe Shadow AI is used in their organisation 88%
    Fear staff are sharing sensitive data with unauthorised AI 51%
    Worried about regulatory or compliance breaches 38%
    Concerned about employees using AI without oversight 36%
    Worried inaccurate AI output is influencing decisions 35%
    Weren't familiar with the term "Shadow AI" before the survey 27%
    Say most/all AI pilots have moved into day-to-day operations 64%

    Turbotic research, surveying 1,004 senior UK decision-makers involved in setting and assessing AI projects, conducted by Research Without Barriers, 13–21 July 2026.

    Which teams use unauthorised AI the most?

    Shadow AI isn't evenly distributed across a business. Turbotic's research found unauthorised AI use is highest in:

    1. IT — 36%

    2. Customer service — 30%

    3. Marketing — 28%

    4. Sales — 27%

    These are also the functions handling the most sensitive material day to day — client data, contracts, support tickets, personal information — which is part of why 51% of leaders are worried about what's being typed into unapproved tools.

    Why Shadow AI is growing right now

    Three things are happening at once inside UK businesses:

    • AI use is scaling fast. 64% of leaders say most or all of their AI pilot projects have already moved into everyday operations.
    • Governance hasn't kept pace. More than a third of leaders (38%) worry about compliance breaches, and 36% are concerned about AI being used without any management oversight.
    • Awareness lags behind adoption. 27% of the people directly responsible for AI decisions in their organisation didn't recognise the term "Shadow AI" — meaning the risk is often invisible to the people meant to be managing it.

    Put together, this is a governance gap, not an employee problem. Staff turn to unauthorised tools because they're faster and more capable than whatever's officially sanctioned — not because they're trying to cause harm.

    Start a conversation that leads to progress.

    Connect with our team and explore solutions tailored to your needs.

    What Turbotic's CEO says about it

    "Our research, as we expected, shows that AI is already being used across UK businesses and more are keen to move on from the pilot stage into full-blown integration. But what did surprise us is that, as adoption is increasing, just how many organisations don't know which tools their people are using, what data is being put into them, whether AI is influencing a business decision, or even what the term Shadow AI means. That's a huge problem when it comes to properly managing the risks that come with AI use, and encouraging more adoption will only make the problem harder to manage."
    "If organisations want AI to become part of everyday business, they need to first treat visibility, governance and trust as part of deployment, not something to bolt on afterwards. And this responsibility must sit not with employees, but with leadership, who need to be creating an environment where people know what they can use, what they can't, and why."

    Theodore Bergqvist, CEO and Co-founder, Turbotic

    How to reduce Shadow AI risk without blocking AI adoption

    Restricting tools outright rarely works — employees route around blocks when the sanctioned option is slower than the unsanctioned one. What does work:

    • Give teams a governed alternative, not just a policy. If there's no approved tool that matches the speed of ChatGPT or similar, unauthorised use will continue regardless of what the policy says.
    • Build visibility into deployment from day one. Knowing which tools are in use, and what data flows through them, has to be part of how AI is rolled out — not an audit that happens after the fact.
    • Treat this as a leadership responsibility, not a compliance memo. Employees need to know what they can use, what they can't, and why — communicated clearly, not assumed.
    • Move pilots to production with governance built in. With 64% of pilots already reaching day-to-day operations, the moment to add oversight is now, not after the next audit finding.

    This is the same gap Turbotic works with clients to close — helping organisations move from ungoverned AI experimentation to operational, governed AI that teams can actually use with confidence.

    Frequently asked questions

    What is Shadow AI?

    Shadow AI is the use of AI tools — chatbots, generative AI assistants, or automation platforms — by employees without formal approval, oversight, or visibility from their employer's IT or leadership.

    How common is Shadow AI in UK businesses?

    According to Turbotic's 2026 research, 88% of senior UK decision-makers believe Shadow AI is being used within their organisation.

    Which departments use unauthorised AI the most?

    IT (36%), customer service (30%), marketing (28%) and sales (27%) report the highest levels of unauthorised AI use.

    Is Shadow AI a security risk?

    Yes. 51% of UK leaders surveyed fear employees are feeding sensitive company data into unauthorised AI tools, and 38% are concerned about resulting regulatory or compliance breaches.

    How can businesses reduce Shadow AI without banning AI tools?

    By giving employees a sanctioned, governed alternative that matches the speed and capability of popular tools, and by building visibility and governance into AI deployment from the start rather than adding it after adoption has already spread.

    About the research

    The findings come from a Turbotic study surveying 1,004 senior decision-makers involved in setting and assessing AI projects at UK businesses with 10+ employees. The survey was conducted online by Research Without Barriers between 13–21 July 2026. It is the first release from a wider Turbotic study into why UK businesses struggle to move AI from pilots into day-to-day operations, with further findings to follow.


    Ready to close your own Shadow AI gap? Turbotic helps businesses move AI from ungoverned experimentation to production-ready, governed operations — without slowing teams down. Get in touch to talk about where your organisation stands.

    Is your process ready for AI?

    Find out in 2 minutes with our free Automation & Agent Feasibility Check.

    Get started with Turbotic today

    Discover how Turbotic AI can help you scale automation and AI initiatives with full control and visibility.

    Book a demo