Shadow AI is Here: When Employees Build the Features You Won't Buy
Shadow IT was employees signing up for unapproved software. Shadow AI is employees building their own, with an agent instead of a purchase order.

What is shadow AI
Shadow AI is employees using AI tools, agents, and no-code builders to get work done, or to build software outright, without IT approval or visibility.1 It is the direct descendant of shadow IT, the old habit of expensing an unauthorized SaaS tool on a company card. The difference is what employees are doing with the access. They are not just adopting software anymore. Many are building it.
The distinction matters because the two problems have different fixes. Shadow IT was a procurement gap. Shadow AI is a production gap: unsanctioned code, workflows, and agents now sit inside real business processes, often touching production data, with no owner and no audit trail.
The numbers say this is not an edge case
This is not a rounding error in a security survey. It is close to universal.
- 78% of employees use AI tools their IT department has not approved, per WalkMe's 2025 State of Digital Adoption survey of more than 3,500 knowledge workers.2
- 60% of builders have shipped software, workflows, or automation outside IT oversight in the past year, and 25% say they do it frequently, according to Retool's 2026 Build vs. Buy Shift Report, a survey of 817 builders.3
- 35% of enterprises have already replaced at least one SaaS tool with something built in-house, and 78% plan to build more custom tools in 2026.3
- IBM's 2025 Cost of a Data Breach Report made shadow AI a formal breach category for the first time. Organizations with high shadow AI involvement took on an extra $670,000 in breach costs and a median of 247 days to detect the incident.4
Retool's data is the most useful part of this story because it separates intent from accident. Among builders who went around IT, 31% said it was simply faster than waiting, 25% said the sanctioned tool did not meet their needs, and 18% said IT's process was too slow.3 These are not junior employees hiding mistakes. 64% of the respondents who admitted to unsanctioned building were senior managers or above.3
Why this generation of shadow IT looks different
Old shadow IT meant a marketing manager expensing a project management tool. The tool did one thing, in one place, and IT could eventually find the invoice.
Shadow AI does not leave that kind of paper trail, and it does more than store data. As IBM's research group at CIO put it, unlike shadow IT, these systems "not only move data but also influence decisions," turning unsanctioned technology into unsanctioned intelligence.5 An employee's AI agent might read support tickets, pull customer records, draft a response, and send it, all without a human reviewing the output or a system logging that it happened.
Retool's survey shows what employees are actually building in the shadows: internal tools (53%), automated workflows (53%), custom dashboards (51%), and even database structures (30%).3 These are not toys. They are functioning replacements for categories of software companies pay for every month. Workflow automation (35%) and internal admin tools (33%) are the SaaS categories most at risk of quiet replacement, followed by BI tools at 29%.3
And the reason employees keep doing it despite the risk is straightforward: it works. About half of builders who shipped production software say it saves their team six or more hours a week.3 When a spreadsheet jockey can prompt their way to a working internal tool over a weekend, waiting three months for procurement to approve a vendor starts to look like the risky option, not the safe one.
The governance gap is the real story
The risk is not that employees are building things. It is that almost nobody is watching what gets built. 63% of organizations lack a formal AI governance policy altogether, and 97% of organizations that suffered an AI-related security incident had no proper AI access controls in place. Only 17% of builders in Retool's survey said they'd been blocked from shipping something because IT flagged it as unsanctioned, but that number is misleading. IT cannot block what it does not know exists, and 60% of builders already have something running outside its view.3
The blockers that do stop AI-built software from reaching production split cleanly into two buckets: technical gaps like missing secure data integrations and hallucinated code, and organizational friction like lost priority or IT approval delays.3 Neither bucket is solved by a ban. Banning generative AI tools tends to just push the behavior further underground, since a large share of employees say they would keep using unauthorized tools even if their company explicitly prohibited it.
What companies are actually doing about it
The useful response is not prohibition. It is bringing the activity into a governed environment rather than pretending it does not exist. IBM's own guidance for managing shadow AI centers on flexible governance frameworks, registries of approved tools, and monitoring rather than blanket bans.1 Retool's report frames the same idea from the builder's side: enterprises that give employees a sanctioned way to build, with access controls and audit logs already inherited from existing permissions, capture the productivity gains without the blind spots.3
This is also where the build-versus-buy conversation and the shadow AI conversation converge. Companies that treat internally built software as a real asset, one with an owner, a security review, and a maintenance plan, get the speed benefit of shadow AI without absorbing all of its risk. Companies that keep pretending the only two options are "buy the SaaS tool" or "stop employees from building things" will keep discovering unsanctioned tools the same way most organizations do now: after something breaks. For teams evaluating whether to formalize an internally built feature instead of continuing to rent the equivalent SaaS module, Remy is built around treating that software as an owned asset rather than a shadow project nobody signed off on.
FAQ
What is shadow AI? Shadow AI is the use of AI tools, models, or agents by employees without the knowledge, approval, or oversight of the IT or security team.1 It covers everything from pasting company data into a public chatbot to building a full internal application with an AI coding assistant.
How is shadow AI different from shadow IT? Shadow IT was employees adopting unauthorized software, usually SaaS. Shadow AI includes that, but adds employees building or running AI-driven systems that make decisions and take actions, not just store data.5
How common is shadow AI really? Very common. Estimates range from 71% to over 80% of employees using AI tools without IT approval, depending on the survey, and 60% of builders say they've shipped software outside IT oversight in the past year.23
Does banning AI tools stop shadow AI? No. Bans tend to push usage further out of sight rather than eliminating it, since a large portion of employees say they would keep using unauthorized tools even if the company banned them outright.
What is the actual cost of shadow AI to a company? Organizations with high shadow AI involvement in a breach incurred an extra $670,000 in costs on average and took a median of 247 days to even detect the problem, according to IBM's 2025 Cost of a Data Breach Report.4
Shadow AI is the use of AI tools, models, or agents by employees without the knowledge, approval, or oversight of the IT or security team, covering everything from unauthorized chatbot use to full internal apps built without sign-off.
Shadow IT was employees adopting unauthorized software. Shadow AI includes that but adds employees building or running AI systems that make decisions and take actions on company data, not just store it.
Very common. Surveys put unapproved AI tool use among employees between 71% and over 80%, and 60% of builders say they've shipped software outside IT oversight in the past year.
No. Bans tend to push usage further out of sight, since a large share of employees say they would keep using unauthorized AI tools even if their company banned them outright.
Organizations with high shadow AI involvement in a breach incurred roughly $670,000 in additional costs and took a median of 247 days to detect the incident, per IBM's 2025 Cost of a Data Breach Report.
- 1.What is shadow AI? — IBM
- 2.Shadow AI Is the New Shadow IT: 78% Use AI Without IT Approval — Second Talent
- 3.The build vs. buy shift: how vibe coding and shadow IT have reshaped enterprise software — Retool
- 4.Shadow AI Is Consuming the Enterprise: 68% of Employees Use AI Without IT Knowing — NoCode.Tech
- 5.Shadow AI: The hidden agents beyond traditional governance — CIO



