Key takeaways
- Separately, Salesforce's 2026 Workforce AI Survey puts general AI usage at 67 per cent of employees, against just 18 per cent of…
- This is a different story from the one HR trade coverage has spent the past year telling.
- But it skips past a bigger, messier one: what employees are doing with AI entirely outside HR's sanctioned tools, on their own initiative…
What happened
Sixty-six per cent. That's the share of office professionals at large enterprises — companies with $500 million or more in annual revenue — who admit to using AI tools at work that they believed were not permitted under company policy, according to PagerDuty's 2026 Shadow AI Survey of 1,250 workers across Australia, Japan, the UK and the US.
The content of what employees share matters as much as the scale. 7 per cent two years before that. For context, that's candidate data, performance reviews, compensation details and internal HR documents potentially being fed into tools with no contractual data protections, no audit trail, and no way for the organisation to later prove what left the building.
IBM's 2025 Cost of a Data Breach report found that one in five organisations has already suffered a breach involving unsanctioned shadow AI — adding roughly $670,000 to the average cost of that breach compared to incidents without an AI component. The instinct is to treat this as a cybersecurity issue to hand off to IT. That instinct is precisely why the gap persists.
Shadow AI touches the data HR is most directly responsible for protecting — candidate records, employee performance data, compensation benchmarking, disciplinary records — and the behaviour driving it is a workforce and culture problem before it's a technical one. Employees aren't circumventing policy out of malice; they're doing it because sanctioned tools are slower, more restrictive, or don't exist for their use case.
Notably, one industry analysis found that providing an approved AI alternative drove an 89 per cent drop in unauthorised usage — a strong signal that this is a design and enablement failure as much as an enforcement one. There's also a retention dimension HR can't ignore: one survey found 54 per cent of new employees say AI access actively influences which employer they choose to join.
Why it matters
Separately, Salesforce's 2026 Workforce AI Survey puts general AI usage at 67 per cent of employees, against just 18 per cent of organisations reporting a formal AI security policy. However, the number is sliced, the pattern is identical: employees adopted AI faster than any governance function could keep pace with, and most organisations still don't know how far the gap has grown.
This is a different story from the one HR trade coverage has spent the past year telling. The dominant narrative has been about AI inside HR — recruitment tools, workforce analytics, agentic HR systems, and whether the function has the governance maturity to deploy them responsibly. That's a real conversation.
But it skips past a bigger, messier one: what employees are doing with AI entirely outside HR's sanctioned tools, on their own initiative, often without IT or HR ever finding out. Shadow AI — unauthorised, ungoverned use of AI tools at work — is not a fringe behaviour.
LayerX's 2025 research found that 77 per cent of employees paste data into generative AI prompts, and 82 per cent of those pastes come from personal, unmanaged accounts rather than any company-approved system. PagerDuty's research adds a sharper detail: this happens even at organisations that have explicit policies against it.
Two-thirds of employees at large enterprises used unauthorised AI tools despite believing it wasn't allowed — meaning the problem isn't primarily one of unclear policy. It's one of policies nobody's enforcing, or nobody's able to see. Visibility is the crux of it.
Only 12 per cent of companies can detect all shadow AI usage happening inside their organisation, according to industry research cited in ShadowLock's 2026 State of Shadow AI report. Gartner separately found that 69 per cent of cybersecurity leaders suspect or have evidence of prohibited generative AI use in their own organisations — which means most security leaders already know this is happening; they simply can't quantify it.
What to watch
Simply blocking AI tools risks losing exactly the talent an organisation is trying to attract. Most organisations have spent the past two years building AI governance frameworks for the tools they deployed on purpose. Far fewer have built any visibility into the tools employees deployed on their own.
Given that 43 per cent of companies reportedly have no AI usage policy at all, and only 38 per cent describe their AI policy as comprehensive, the honest starting point for most HR functions isn't more governance for sanctioned AI. It's a basic audit of what's actually already running, unsanctioned, across their own workforce.




