Shadow AI at Work: How to Turn Hidden Use Into Skill
Shadow AI at work is everywhere: 66% of employees who use AI don't check its output. Learn how training turns hidden AI use into real skill.

Two out of three employees who use AI at work rely on its output without checking whether it is right, and more than half admit AI has already caused mistakes in their work. Most of that usage happens on tools nobody approved, under policies nobody wrote, with training nobody delivered. That is shadow AI at work, and this post breaks down the new evidence on how widespread it is, why bans and policy PDFs fail to contain it, and the five-step playbook that turns hidden, risky AI use into a skill your company can actually count on.
What is shadow AI at work?
Shadow AI is employees using AI tools their employer never approved, never trained them on, and often never finds out about. The name borrows from "shadow IT," but the stakes are higher: an unapproved spreadsheet plugin rarely invents facts or leaks a customer contract, while a public AI chatbot can do both before lunch.
The problem just got a fresh spotlight. In an op-ed published this week, corporate and AI governance lawyer Chisom Obiudo describes what she sees in her own training sessions: most participants already use AI at work, yet almost none know how to verify what it produces or which information should never be pasted into it. Her verdict is blunt: "You cannot govern what you do not understand."
The scale makes this urgent. Gallup's workplace research shows AI use among US employees nearly doubled in two years, from 21% to 40%, with daily use doubling in the last twelve months alone. Usage is compounding. Guidance is not.
How common is shadow AI? More common than your policy assumes
The honest answer: at most companies, ungoverned AI use is the default, not the exception. Gallup found 44% of organizations have begun integrating AI, but only 22% have communicated a clear plan for how employees should use it, and just 30% have published general guidelines or formal policies. That gap between adoption and guidance is exactly where shadow AI lives.
What happens inside that gap is measurable, and it is not pretty. The University of Melbourne and KPMG surveyed over 48,000 people across 47 countries and found:
- 66% of employees who use AI rely on its output without evaluating accuracy.
- 56% say AI has caused mistakes in their work.
Read those two numbers together. The majority of your AI users are not double-checking, and the majority have already shipped an AI-generated error. Every unverified summary, misquoted figure, or fabricated citation that slips into real work is a small invoice that arrives later, in an audit, a customer call, or a courtroom.
Meanwhile, the money is flowing to the wrong side of the problem. US corporate training spend grew to $102.8 billion, with spending on external learning products up 29% in a single year, according to Forbes' reporting on the state of corporate learning. Companies are buying more learning than ever. Very little of it teaches the one behavior shadow AI makes urgent: using AI critically on your own real tasks.

Why banning AI tools does not work
Bans do not stop AI use, they stop honesty about it. An employee who saves forty minutes with an AI assistant is not going to give those minutes back because of a memo. They will keep using the tool on a personal device or a personal account, and now the usage you most needed visibility into is precisely the usage you cannot see.
That is the worst possible trade. A ban converts a training problem you could solve into an invisible risk you cannot even measure. Sensitive data still flows into public tools, unverified output still flows back into client work, and the company learns about both only when something breaks.
Obiudo's op-ed lands on the same point from the legal side: governance and competence are different things. "Governance sets the rules. Literacy develops the competence to follow them," she writes. A rule that employees are not equipped to follow does not reduce risk. It just relocates the risk somewhere quieter, and makes employees hide the very behavior you need to coach.
The alternative is making disclosure safe. People will only tell you how they actually use AI if the response to honesty is training, not punishment.
Why an AI policy PDF will not change behavior
A policy document creates awareness, not capability, and shadow AI is a capability problem. Reading "verify AI outputs before use" does not teach anyone how to verify anything, any more than reading a seatbelt policy teaches someone to drive.
The competence that actually reduces risk is role-specific. A lawyer needs to catch a fabricated citation. A financial analyst needs to sense-check a plausible but wrong number. A support rep needs to know which customer details can never leave the approved environment. A generic one-hour webinar on prompting covers none of those moments, which is why companies that "have AI training" still leak data and ship AI-generated errors.
There is also a communication dividend that most leaders leave unclaimed. Gallup found that when leadership communicates a clear AI plan, employees are three times as likely to feel very prepared to work with AI and 2.6 times as likely to feel comfortable using it. Clarity itself is a performance intervention. Silence, by contrast, is a decision to let every employee invent their own rules.
How to turn shadow AI into a trained skill
The fix is to treat shadow AI as demand for training that nobody has met yet. Employees have already voted: the tools are useful. The playbook is to meet that demand faster than the risk compounds.
- Start with amnesty, not an audit. Ask teams what AI tools they actually use and for what, with a guarantee that honest answers trigger support rather than discipline. You cannot train against a usage map you do not have.
- Write rules people can act on. Swap the 30-page PDF for a one-page decision guide: which tools are approved, which data classes never leave the building, and what must be verified before AI output touches a customer, a regulator, or a decision.
- Train by role, on real scenarios. Build practice around the actual failure modes of each job: the fabricated citation, the confident wrong number, the pasted contract clause. Generic AI literacy fades; job-specific judgment sticks.
- Make verification a practiced habit, not a slide. People learn to catch AI errors by catching AI errors. Interactive training videos that pause, present a realistic AI output, and ask the learner to find what is wrong before moving on turn verification from a compliance sentence into a reflex. Passive video cannot do this, because watching someone else be careful trains nothing.
- Measure behavior, not completions. Track disclosure rates, verification catches in practice scenarios, and AI-related incidents over time. A completion certificate proves attendance. Changed behavior proves training.

Run that loop and the shadow shrinks on its own, because the safe path becomes the easy path: approved tools that work, rules that fit the job, and skills rehearsed until they are automatic.
FAQ
How do I find out if employees are using shadow AI at my company?
Ask them, in a way that is safe to answer. Anonymous surveys and team-level amnesty conversations surface far more truth than monitoring software, because the riskiest usage happens on personal devices where monitoring cannot see. If your survey says nobody uses unapproved AI, that is not reassurance. Given that 40% of employees now use AI at work, it usually means people do not feel safe telling you.
Should we just block public AI chatbots on work devices?
Blocking has a place for genuinely high-risk systems, but as a strategy it mostly relocates usage to personal phones and home laptops where you have zero visibility. The evidence-backed move is to pair a small set of approved tools with role-specific training, so the sanctioned path is more convenient than the shadow one. A ban with no trained alternative is how shadow AI got this big in the first place.
What should shadow AI training actually cover?
Four things, in the context of each role: which data can and cannot be shared with AI tools, how to verify outputs before they touch real work, when AI is the wrong tool entirely, and how to disclose AI use without fear. The format matters as much as the content. Practice with feedback on realistic scenarios changes behavior; a slide deck read once does not.
Shadow AI is not a discipline problem, it is the largest unmet training need in your company, and it is growing at the speed of a doubling adoption curve. The companies that come out ahead will be the ones that make AI competence something employees practice, not something they sign. Interactive, role-specific learning that lets people rehearse judgment calls and get corrected in the moment is how hidden use becomes visible skill.
Turn your training into an interactive experience
Nesoi transforms static content into interactive video experiences with AI tutors your team actually finishes.
Book a demo