A 2026 PagerDuty survey found that many office workers are secretly using AI tools at work, even when they believe those tools may violate company policy. As TechRadar reported, 66% of office professionals said they had used AI tools for work despite thinking they were not permitted, and 43% said they had entered work-related emails or data into public AI tools. The lesson for leaders is clear: if employees need AI to get work done, but do not trust the rules around it, the risk moves underground.
In June 2026, PagerDuty released research on shadow AI in the workplace. The survey found that two-thirds of office professionals had used AI tools for work despite believing that doing so was not allowed by company policy. In larger organizations, the figure rose to 72%.
The findings get more uncomfortable from there. According to PagerDuty’s own report, 88% of office professionals said they had shared work-related information with public AI tools such as ChatGPT, Claude, or Gemini. That included emails and other correspondence, meeting notes or summaries, customer information, financial information, and confidential company documents or strategies.
This is not a story about a single rogue employee doing something wildly unusual. It is a story about normal workers using useful tools in a governance fog. Employees are under pressure to move faster, write better, summarize more, analyze quickly, and keep up with everyone else who seems to be magically more productive by Tuesday.
So they use AI. Sometimes they hide it. Sometimes they paste things they probably should not. Sometimes they assume the risk is theoretical because nothing bad has happened yet.
That last bit is where security teams start sweating through their branded quarter-zips.
Shadow AI is what happens when employee behavior moves faster than company policy. It does not mean people are trying to be reckless. More often, it means the approved path feels unclear, slow, unavailable, or unrealistic.
That matters because generative AI is now woven into daily knowledge work. People use it to draft emails, clean up presentations, summarize meetings, analyze spreadsheets, rewrite customer responses, prepare proposals, troubleshoot code, and make sense of long documents. The productivity value is obvious. The data-risk questions are less obvious in the moment.
The problem is not only what employees type into public AI tools. It is what those prompts reveal: customer names, internal strategy, contract details, HR matters, financial assumptions, source code, legal concerns, product plans, incident notes, and confidential communications. Even when a tool has privacy controls, most employees are not equipped to assess vendor terms, retention settings, data boundaries, or enterprise configuration.
If the company’s AI policy is vague, punitive, or buried somewhere between the expenses policy and a PDF from 2023, people will improvise. Shadow AI grows in the gap between what employees need and what the organization has clearly enabled.
Shadow AI is a human risk management issue because it is about trust, pressure, clarity, and behavior.
Employees may hide AI use because they fear judgment, because managers send mixed signals, or because leadership talks about transformation while security says “do not touch that.” Some may believe they understand AI better than their own internal technology teams. Others may simply be copying what colleagues are doing quietly.
That creates two risks. First, sensitive information may end up in tools the company has not approved or monitored. Second, the organization loses visibility into how work is actually being done. Hidden behavior is hard to guide, hard to measure, and very hard to improve.
This is where culture matters. If people think admitting AI use will get them in trouble, they will not ask for help. If they think policy is unrealistic, they will route around it. If they believe leadership bends the rules for convenience, they will treat governance as theater.
Cyber culture is not what the policy says. It is what people do when they need to finish the deck before the client call.
Organizations should start by accepting reality: employees are already using AI. The useful question is whether they are using it safely, transparently, and with enough guidance to avoid creating unnecessary exposure.
Create simple rules that people can remember. Define which tools are approved, what types of data can be used, what must never be pasted into public tools, and where employees should go when they are unsure. Use real examples by role: sales proposals, customer tickets, HR notes, code, contracts, board materials, financial forecasts, and incident reports.
Give people a safe path. If employees need AI to work efficiently, provide approved tools that are easy to access and good enough to use. A secure tool nobody likes will not beat a public tool that helps them finish the job.
Train managers, not just employees. Managers shape behavior by what they reward, ignore, or quietly encourage. If a team is expected to produce more with fewer resources, AI use will happen. Leaders need to set clear expectations around disclosure, review, data handling, and quality control.
Finally, measure the culture. Do employees understand the rules? Do they trust them? Do they know what sensitive data looks like in their role? Are they comfortable asking questions? Are teams using AI outputs without review? Those answers matter more than a signed policy acknowledgement.
Shadow AI is one of the clearest human risk management stories in the AI era because it shows the difference between official governance and real behavior.
People are not waiting for perfect policy. They are solving work problems with the tools available to them. That can be good for productivity and dangerous for data protection at the same time. The job is not to shame employees for using AI. The job is to build a culture where safe use is practical, visible, and normal.
For Cybermaniacs, this is exactly why AI risk belongs inside human risk management. Organizations need role-based learning, behavior measurement, cyber culture insight, practical nudges, and leadership assurance. They need to understand where employees are confused, overconfident, pressured, or hiding behavior.
AI adoption is not just a technology rollout. It is a people system. If the people system is unclear, shadow AI will happily fill the gap with a browser tab and a pasted contract.
Shadow AI is the use of AI tools by employees without formal approval, oversight, or clear governance. It often includes public AI tools used for workplace tasks without security, privacy, or compliance review.
Employees may enter sensitive business data into unapproved tools, including customer information, emails, meeting notes, contracts, financial data, HR issues, source code, or confidential strategy documents.
Employees may hide AI use because policies are unclear, approved tools are unavailable, they fear judgment, or they feel pressure to work faster. Some may also believe company rules are unrealistic or inconsistently enforced.
Provide approved AI tools, create clear data-use rules, train employees with role-specific examples, support managers, monitor risky patterns, and build a culture where employees can ask questions without fear.
Because the risk comes from daily behavior: what people paste, share, summarize, disclose, hide, and trust. Human risk management helps organizations understand and improve those behaviors before they become incidents.