Shadow AI & Governance

The 'Free Claude' Problem: Why Shadow AI Is Your Next Governance Nightmare

Employees are routing around Claude's API costs, running unapproved bots, and pasting company data into tools IT has never seen. Blocking it won't work. Here's what will.

At a glance
  1. 01Over 80% of workers use unapproved AI tools, including nearly 90% of security professionals.
  2. 02Employees who feel confident about AI risks are actually more likely to bypass IT policies.
  3. 03Shadow AI breaches cost organizations an average of $670,000 more than standard data breaches.
  4. 04Providing a sanctioned, fast alternative is the most effective way to reduce unauthorized AI use.
Minimal ink-and-crimson illustration of an office desk with a small chat-bubble icon glowing on a laptop, its shadow looming large and dark on the wall behind it, symbolizing hidden shadow AI use

The short answer

You manage shadow AI by replacing prohibition with provisioning: find out what employees are actually using, give them a sanctioned version that is just as fast, and instrument everything for visibility. Blocking tools without a plan mostly just makes the usage harder to see, not less common.

The 'Free Claude' problem is bigger than one repo

Search GitHub right now and you will find projects literally named "free-claude-code," proxy tools that route the Claude Code CLI through cheaper or free model providers so developers can skip Anthropic's metered API billing entirely. One of the more popular ones has racked up tens of thousands of stars and forks. It is not a fringe hack. It is a widely shared, actively maintained workaround for a real cost problem: teams love Claude Code, but the token bill adds up fast, so someone finds a way around it.

That is the shape of shadow AI in 2025 and 2026. It is not shadowy in the sense of secretive. It is shadowy in the sense of ungoverned. Employees are not sneaking around, they are Googling "how do I get this for free" in broad daylight, sharing the answer in Slack, and moving on with their day.

The data backs this up at scale. More than 80% of workers, including nearly 90% of security professionals, use AI tools their employer has not approved, according to a November 2025 report from UpGuard.1 Roughly half of those employees say they use unapproved tools regularly, and fewer than 20% stick exclusively to company-sanctioned tools.1 Executives are not the exception. They are often the worst offenders, with senior leadership using shadow AI at higher rates than the rank and file.2

Why people bypass IT instead of asking

The UpGuard research found something that should reshape how security teams think about this problem: employees who believe they understand AI risk are more likely to ignore policy and use unapproved tools anyway.2 Confidence, not ignorance, is driving the behavior. A quarter of workers now say AI tools are their most trusted source of information, nearly on par with their own manager.2 Training programs built on "here is why this is risky" are talking past people who already think they have the risk covered.

That is the real difference between shadow AI and classic shadow IT. Nobody trusted a rogue Dropbox folder the way people now trust a chatbot. The tool feels like a colleague, and it never says no.

What the data says about cost and exposure

The economics are not abstract. IBM's 2025 Cost of a Data Breach Report found that 20% of breached organizations had suffered an incident tied to shadow AI, and those breaches cost an average of $670,000 more than breaches at organizations with low or no shadow AI use.3 Shadow-AI-linked breaches also exposed more personally identifiable information (65% versus a global average of 53%) and more intellectual property (40% versus 33%).3 Ninety-seven percent of the organizations that suffered an AI-related breach had no access controls on the AI system involved.3 Sixty-three percent of breached organizations either had no AI governance policy or were still writing one.3

Figure 1
Shadow AI usage vs. governance readiness
Percentage (%)
81%Employees using unapproved AI20%Orgs with high shadow AI use during a breach63%Orgs with no or incomplete AI governance policy97%Breached orgs with no AI access controls
Source: Remy analysis

Put plainly: the risk is not hypothetical, and it is not evenly distributed. It concentrates in the gap between adoption speed and governance speed, and right now that gap is enormous.

Why blocking doesn't work

The instinct at most companies is to block. Firewall the domains, disable the extensions, send a memo. It does not hold. Employees who lose access to a tool they rely on for real productivity gains do not stop using AI, they route around the block, often through a personal device or a personal account where IT has zero visibility. That is worse, not better, because now the data leaving the building is invisible instead of merely unmonitored.

The more useful signal from the research: when organizations provide an approved alternative that meets the same need, unauthorized use drops sharply.2 People are not chasing rebellion. They are chasing speed. Give them a fast, sanctioned path and most will take it.

A governance approach that doesn't kill velocity

Find it before you fight it. Run an actual discovery pass: network telemetry, browser extension audits, expense report line items, and a plain survey asking teams what they use and why. You cannot govern what you cannot see, and right now most companies cannot see the majority of their own AI usage.

Fund the workaround instead of banning it. If engineers are routing around Claude Code's metered billing because the team-wide API bill is unpredictable, that is a budgeting problem dressed up as a security problem. Negotiate a real seat-based or capped plan, put it on a company card, and the incentive to find a free proxy mostly disappears.

Tier data by sensitivity, not by tool. Blanket bans treat a marketing brainstorm the same as a customer PII upload. Classify what data can go where, and let low-risk work move fast while gating anything that touches regulated or sensitive information.

Build a sanctioned fast lane. Give teams an internal AI environment or a small, well-lit set of approved tools with real support, not a six-week procurement form. Speed is the entire reason shadow AI exists. Match it or lose the argument.

This is also where the build-versus-rent conversation gets interesting. A lot of what employees are quietly building with AI, whether it's a Grok-powered Slack bot that summarizes tickets or a scraped-together internal dashboard, is genuinely useful software that nobody asked IT to approve. Treating that instinct as pure risk misses half the story. The right response is not just governance, it's giving teams a legitimate way to own and operate what they build instead of running it off someone's personal API key forever. Platforms like Remy exist for exactly that gap: turning the software employees are already building into something the company actually owns, with visibility built in from day one, rather than discovering it during a breach postmortem.

The bottom line

Shadow AI is not a rogue-employee problem. It is a governance-lag problem. The tools are good, the productivity gains are real, and the workaround culture around them, from free Claude Code proxies to homemade Grok bots, is a rational response to slow, expensive, or absent official options. Companies that try to out-block their own workforce will lose. Companies that out-provision them will get the productivity gains and keep the visibility.

Frequently asked
What is shadow AI?

The use of AI tools, models, or workarounds by employees without IT or security approval or oversight, including public chatbots on personal accounts and unofficial API proxies.

How common is shadow AI at work?

More than 80% of employees and nearly 90% of security professionals report using AI tools their employer has not approved, per UpGuard's 2025 report.

How much does shadow AI cost companies in a breach?

IBM found breaches involving high shadow AI use cost $670,000 more on average, with 97% of affected organizations lacking basic AI access controls.

Does blocking AI tools stop shadow AI?

No. Employees typically route around blocks via personal devices or accounts, reducing visibility. Providing a fast, approved alternative reduces unauthorized use far more effectively.

Who uses shadow AI the most?

Usage spans every department, but senior leaders and even security professionals report some of the highest regular usage rates.

Sources
  1. 1.New Research from UpGuard Reveals 68% of Security Leaders Admit to Unauthorized AI Usage — UpGuard
  2. 2.Shadow AI is widespread — and executives use it the most — Cybersecurity Dive
  3. 3.Average global data breach cost now $4.44 million — Help Net Security
Portrait of Priya Nair
Priya Nair
AI Tooling
Priya covers the daily churn of AI agents, coding tools, and what actually ships.
© 2026 The Official Remy BlogDrafted by AI authors, reviewed by human editors.