What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Shadow AI is AI used at work outside your organization’s visibility, approval, or governance process. It may be a consumer chatbot an employee uses to draft a document—or an AI agent connected to company systems and able to take actions. The second case can create much greater exposure, so organizations need to discover both, assess them by risk, and make responsible use easier than going around the rules.

What is shadow AI?

Shadow AI is the unsanctioned or unauthorized use of AI tools without explicit approval or oversight from IT or a central AI governance team, as KPMG defines it in its 2025 guidance. The term describes a visibility and governance gap; it does not, by itself, mean that an employee has caused a data breach or acted maliciously.

It can include several different situations:

  • An employee enters work material into a personal account on a consumer chatbot.
  • A team adopts an AI feature built into a service without checking whether it is covered by company controls.
  • An employee or team creates an AI agent that can access business data or take actions in work systems without review.
  • A pilot or experiment operates outside the organization’s usual approval and monitoring process.

These cases should not be treated as equivalent. A chatbot that receives text may present a data-handling risk; an agent with permissions to read or change business records adds access, action, and oversight risks.

Is shadow AI already inside my organization?

It may be, but available figures are indicators from specific sources—not a universal census of workers. In an article dated February 24, 2026, Microsoft reported that 29% of employees had used unsanctioned AI agents for work tasks. Microsoft said its Cyber Pulse report combines first-party telemetry from Copilot Studio and Agent Builder with a multinational survey of 1,725 data-security leaders conducted in 2025. The 29% is Microsoft-reported employee usage; it is not a result showing that 29% of those surveyed leaders used agents, nor a representative count of every workforce. Microsoft’s Cyber Pulse article.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

The same article says more than 80% of Fortune 500 companies are deploying active agents built with low-code/no-code tools, based on Microsoft ecosystem telemetry. That provides context for agent adoption, not an independent audit of Fortune 500 companies or a measure of unsanctioned use.

Other findings suggest that employees use AI at work, but they do not establish the prevalence of shadow AI specifically. KPMG’s 2025 report cites a University of Melbourne and KPMG global study in which up to 58% of employees reported intentionally using AI tools regularly at work. Regular use may be sanctioned or unsanctioned. Separately, 58% of U.S. respondents in that study reported relying on AI output without evaluating its accuracy; this is a U.S.-scope finding, not a global estimate. KPMG’s 2025 guidance and cited study findings.

Inventory work should account for more than chatbot websites. AI features can sit inside platforms the organization already approves, and employees may use personal accounts, create agents, or run informal experiments. A list of known AI domains can therefore help with discovery but cannot establish what is or is not in use by itself.

Why are employees using unapproved AI tools at work?

Employees may turn to outside tools because they seem faster, easier to use, more capable, or less restrictive than approved options. A sanctioned tool that is unavailable, poorly integrated with normal work, or behind the capabilities employees need can leave a practical gap. KPMG’s guidance treats shadow AI as both a control concern and a possible signal that work needs are not being met.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There may also be a perceived productivity payoff. Microsoft UK reports that UK workplace users of generative AI assistants said they saved an average of 7.75 hours a week across administrative tasks. The opened Microsoft passage does not state the underlying survey’s field dates or sample size; the figure is self-reported experience, not a controlled estimate of time saved for all UK workers. Microsoft UK’s account of shadow AI and reported time savings.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

In the same account, Dr Chris Brauer, Director of Innovation at Goldsmiths, University of London, estimates 12.1 billion hours saved across the UK economy each year, valued at around £208 billion of workers’ time. This is an attributed estimate built from reported assistant use, not a measured economy-wide outcome. Microsoft Research’s 2024 report likewise says effects in real workplaces vary by role and use; reported benefits should not be treated as a guaranteed or universal productivity gain. Microsoft Research’s 2024 report on generative AI in workplaces.

What are the risks of shadow AI?

The risk depends on what tool is being used, which account and settings apply, what information is entered, what permissions the AI has, and what people do with its output. Use those details to assess exposure rather than assuming every AI use is a breach—or that every provider handles submitted data the same way.

Data exposure, retention, and reuse

A prompt, uploaded file, or agent connection may put company, customer, personal, regulated, or intellectual-property data outside approved controls. Depending on provider terms and configuration, information may be stored or reused. Check the service’s terms and settings; do not assume that every public chatbot trains on every prompt, or that every service has the same data practices. KPMG and Microsoft UK identify data handling as a concern for unsanctioned tools. KPMG’s guidance and Microsoft UK’s discussion of security concerns.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Compliance, records, and accountability

Processing information in an unapproved service can conflict with an organization’s regulatory duties, retention rules, or access controls. Whether it does depends on the jurisdiction, sector, data, and deployment. A company should identify the applicable obligations for each use case rather than treating the label “AI” as a complete legal analysis.

Incorrect output trusted without review

AI output can be inaccurate, and an employee may rely on it without checking. In the University of Melbourne and KPMG study cited in KPMG’s 2025 report, 58% of U.S. respondents said they had relied on AI output without evaluating its accuracy. That finding does not mean every user skips review. Set human review according to the consequences: a low-stakes draft and a consequential decision should not have the same review threshold.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Agent access and actions

An agent may be able to read from or act in work systems, so excessive permissions, unclear ownership, or misleading inputs can have consequences beyond an incorrect chat response. Microsoft recommends clear accountability, continuous visibility, and centralized governance as agents spread. Give agents defined roles, limit their privileges to what they need, and oversee their access and actions over time. Microsoft’s Cyber Pulse article.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can a company detect and manage shadow AI?

Effective governance makes legitimate AI work possible within understandable boundaries. Combine proportionate discovery with clear rules, usable approved tools, technical protections, and a route for teams to test ideas safely.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

1. Build an inventory that includes embedded AI and agents

Record sanctioned products, embedded AI features, agents, pilots, and employee-reported experiments. For each use, note the business owner, purpose, users, data involved, systems it can access, and whether it can take actions. Use proportionate technical discovery alongside disclosure and intake; a network block list alone is not a complete inventory. KPMG recommends AI discovery and inventory, while Microsoft describes governance needs across platforms as agent use grows.

2. Triage by data, access, and consequence

For each entry, ask what information can enter the tool, what accounts and permissions it can use, whether the provider retains outputs, and whether the system can trigger changes or decisions. Prioritize sensitive or regulated information, broad permissions, high-impact workflows, and autonomous actions. The NIST AI Risk Management Framework and Generative AI Profile provide risk-management references; NIST released the Generative AI Profile on July 26, 2024, and its page says AI RMF 1.0 is being revised.

3. Publish plain rules and an intake path

Tell employees which tools are approved, what data may be used with them, and which uses are prohibited. Give people a straightforward way to request a tool or use case, and assign responsibility for review, approval, monitoring, and escalation. Clear rules without a workable request path can leave employees with no practical way to meet legitimate needs.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

4. Protect identity, access, and data

Apply least privilege, manage access throughout its lifecycle, and use data protections appropriate to the information and workflow. Microsoft documents Entra and Purview capabilities relevant to these controls; they are vendor implementation examples, not a requirement to choose those products. The underlying principles apply regardless of platform. Microsoft Learn’s guidance on securing generative AI with Entra.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Give teams a safe place to experiment

Use sandboxes and bounded pilots so employees can test ideas before broad deployment. Define what data and systems are allowed in the environment, who owns the experiment, and what evidence is needed to move it into production. KPMG recommends secure experimentation and pilots as part of a governance approach.

6. Revisit the controls as tools change

Review the inventory, permissions, approved-tool usability, policy, and training regularly. Reassess when a tool gains new capabilities or an agent’s access changes; a one-time approval does not replace ongoing oversight. Microsoft’s guidance on AI governance also recommends integrating AI risk into wider cybersecurity and privacy processes. Microsoft Learn’s AI governance guidance.

Should companies ban AI tools employees use without approval?

There is no evidence-based case for one blanket answer for every tool, data type, or use. A company may need to prohibit a specific service, data category, or high-risk activity when the exposure cannot be acceptably controlled. But a broad ban can leave legitimate work needs unmet and may push use into less visible channels. KPMG recommends approved boundaries, curated choices, secure experimentation, and tools that employees can actually use.

Compare approaches against the risks and needs in your organization:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Approach Visibility and control Employee friction and experimentation When it may fit
Ban or block specified tools or uses Can restrict known services or prohibited activity, but does not by itself reveal embedded features, personal accounts, or agents. May obstruct legitimate work or encourage workarounds if no usable alternative exists. When a specific tool, data use, or activity presents unacceptable risk or lacks necessary controls.
Managed enterprise tools Can provide an approved path with defined ownership and controls; effectiveness depends on configuration and scope. Offers a sanctioned option, but a narrow or poorly fitting tool may not meet all needs. When the organization can approve and support tools that fit common work and data requirements.
Curated choices plus sandboxed pilots Pairs approved boundaries with an intake and review path for new tools and use cases. Supports bounded experimentation while keeping a route to review and wider adoption. When teams need room to test new capabilities and the organization can set and monitor safe limits.

The comparison is a decision aid, not a published test of these approaches. Whichever policy you choose, assess visibility, data and permission risk, auditability, employee friction, room to experiment, and the consequence of the use case. NIST’s risk-management framing and Microsoft and KPMG governance guidance support matching controls to risk rather than treating every AI interaction alike.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.