Hidden AI risks hit company budgets

The rise of artificial intelligence in the workplace has led to employees using AI tools without employer approval. This practice, called “shadow AI,” poses growing security and financial risks for businesses.
Understanding shadow AI
Shadow AI involves employees using AI tools like large language models outside approved corporate systems. Unlike traditional unauthorized software use, this practice often means entering sensitive business data into consumer-grade AI platforms without oversight.
A Lenovo study revealed that 70% of employees globally use AI at least weekly, though companies remain unaware of a third of this activity. The issue extends beyond wasted resources—it creates security vulnerabilities. When workers input confidential documents, financial data, or proprietary code into public AI tools, they expose that information to potential breaches or unintended retention by providers.
Dr. Leanne Allen, UK head of AI at KPMG, identifies two main groups driving this trend: novice users who rely on mainstream AI for convenience, and experienced employees who purchase advanced AI accounts to bypass corporate restrictions. “A typical shadow AI pattern is straightforward,” she explains. “Someone copies work material into a consumer tool to work faster, or uses AI to quickly generate code outside approved environments. This behavior usually isn’t malicious—it’s everyday optimization under time pressure.”
Related: Why and How To Switch To Business Email Hosting?
Security incidents and risks
Shadow AI risks have already caused real-world problems. Samsung experienced three separate confidential data exposures within 20 days, all linked to employee use of ChatGPT. Cloud provider Vercel reported a potential customer data breach after attackers hijacked an AI tool used by a staff member, gaining access to their Google Workspace and subsequently Vercel’s systems.
Even when AI companies claim to delete sensitive data, experts warn protections aren’t reliable. Imperial College London research found that AI models can reconstruct documents from fragments of older versions, a phenomenon called “mosaic memory.” Igor Shilov, who worked on the study, describes the issue: “Text contains inconsistencies—typos, multiple document versions with minor changes. Over time, a chatbot might combine overlapping text to recreate what should remain private.”
Allen points out that employees may trust AI tools more than traditional software because they mimic human-like interactions. “When an AI manages communications or automates responses, people often overlook potential misuse,” she says.
Finding the right balance
Companies face a difficult choice: restricting shadow AI could slow innovation and frustrate employees who depend on these tools, while ignoring the issue leaves them exposed to data leaks and regulatory violations. Nearly half of employees in a KPMG and University of Melbourne survey admitted their AI use violated company policy.
Related: Cisco chief tackles digital skills shortfall
The answer, Allen suggests, isn’t just stricter enforcement. “Shadow AI often indicates employees want to work more effectively but lack proper tools,” she says. Instead of bans, businesses should make secure, approved AI tools more accessible and role-specific. This might mean integrating AI into workflows with built-in safeguards rather than treating it as a separate restricted resource.
Shilov notes that fully eliminating risks would require costly data processing most companies won’t invest in. “It’s a trade-off,” he says. “Businesses must decide whether to accept some risk to keep pace with AI adoption.”
The challenge remains: how to benefit from AI without exposing sensitive data. Cybercriminals are increasingly using AI to refine attacks, leaving unprepared businesses at risk of costly consequences.

Activists target firms over AI plans
