Overview: Most employees already use AI tools their company never approved, and almost none of them have been trained for it. Instead of treating shadow AI as misconduct, L&D teams can read it as needs analysis data and build training from what people are already doing in the dark.
Summarise this page with your favorite AI assistant

Unapproved AI Use Is Data, Not Defiance

Last year I found out that one of our writers at the agency I run had been pasting client briefs into a free chatbot account to summarize them. She was not hiding it, exactly. It came up on a call the way you might mention a new keyboard shortcut. My first reaction was irritation. My second, about an hour later, was the uncomfortable realization that I had never given her anything better. We had no approved tool for that task, no rule about what could or could not be pasted, and no training that covered any of it. She had work to do, and she solved it with whatever was closest.

That conversation changed how I read the research on unapproved AI at work. Security teams call it shadow AI and treat it as a threat surface, which it is. But for Learning and Development (L&D) teams it is something else as well: a needs analysis that ran itself, for free, without anyone commissioning it. Every unapproved tool in your company marks a task where the official stack failed someone, and no training reached them. You could pay a consultancy a lot of money for a map that accurate.

Nearly Everyone Is Using It, Almost Nobody Was Taught

The numbers on this stopped being ambiguous a while ago. PagerDuty's 2026 shadow AI survey, run by Wakefield Research across 1250 office professionals at large companies, found that 66% had used AI tools at work despite believing it was against policy. More than a third had put customer data into public models. And the finding that should worry L&D most: nearly half said they would rather keep using AI quietly than ask and risk being told no.

Set that against training coverage. A WalkMe survey put unapproved AI use at 78% of employees, while only 7.5% said they had received extensive AI training. The distance between those two numbers is the entire case for treating this as a training problem. Nearly everyone is using the tools. Almost nobody has been shown how.

Bans Change Visibility, Not Behavior

Verizon's 2026 Data Breach Investigations Report recorded a fourfold jump in shadow AI detections in a single year, which tells you how well prohibition has been working. When a company blocks the tools, use moves to personal phones and free personal accounts, which is the worst possible outcome. Free tiers come with the weakest data controls, and personal accounts sit outside every audit trail the company has.

There is a second cost that rarely shows up in security reports. Concealment kills feedback. An employee who hides the tool will also hide the mistake the tool caused, right up until it reaches a client. If your policy punishes disclosure, you are training people to stay silent at exactly the moments you most need them to speak up. I made a similar argument about deepfake reporting in an earlier piece, and it holds here: the person who admits to a risky workflow is handing you information. Treat that as a gift or you will stop receiving it.

Each Disclosed Use Case Is Intake Data

Once you stop reading shadow AI as misconduct, every instance breaks down into four useful pieces of information. The task someone needed done. The pressure behind it, usually deadlines or sheer volume. The gap in the approved stack, either a missing tool or one nobody knew existed. And the data that went somewhere it should not have.

A finance person cleaning spreadsheet exports with a chatbot is telling you the reporting workflow is too manual. A support rep drafting replies in their second language is telling you where writing confidence is thin. A designer summarizing a 40-message feedback thread is telling you your review process produces 40-message threads. None of these people would have written any of that on an annual training survey. They told you by acting.

Run An Amnesty Audit Before Writing Any Training

The order matters here. Training built before you know actual usage turns into generic AI literacy, and generic AI literacy modules get clicked through and forgotten. Start by finding out what is really happening, and make honesty cheap.

Announce a window, two weeks is plenty, during which anyone can disclose the tools they use and what they use them for, with zero consequences attached. The message has to come from leadership, in writing, or nobody sensible will believe it. Keep the form short: what task, which tool, what kind of data went in. Then share the aggregate results back with the whole team, because people disclose once and then watch what you do with it.

When we ran ours, the disclosures were mundane. Summaries, first drafts, spreadsheet formulas, translation checks. The riskiest thing we found was unpublished client URLs sitting in prompt histories, which our onboarding now covers explicitly. Nobody was doing anything exotic. That is the finding, really. Shadow AI is mostly ordinary people doing ordinary tasks with the nearest tool that works.

Build The Training From What People Disclosed

Data boundaries come first, and they work better as examples than as policy language. "Never paste client credentials, unpublished work, or anything with a person's name in it" survives in memory. A paragraph about acceptable use categories does not. Keep the never list short enough to recite.

Then turn the disclosed use cases into the actual modules. If 11 people admitted to summarizing documents, the summarization module writes itself, built around your real document types and your real quality bar. Training based on tasks people already do gets attention that abstract AI literacy never will, because everyone in the room has already met the problem.

Every "stop doing that" needs a "do this instead" attached. If the approved alternative is slower than the shadow tool, people will nod in the session and go back to the shadow tool by Thursday. Sometimes the honest conclusion of an audit is that the company needs to buy something, and L&D should be the function saying so out loud.

And keep the format short and recurring rather than long and annual. The tools change every few months. A 90-minute module recorded in January is a museum piece by June.

Where To Start This Month

You do not need a governance committee or a budget line to begin. Ask your team this week which AI tools they already use when nobody is watching, and make it genuinely safe to answer. The answers will be less alarming than you fear and more specific than any survey you could commission. Somewhere in your company, the AI training program is already running. It is unofficial and invisible, and the people teaching it to themselves have no idea where the boundaries are. The job is to bring it indoors.

About the author

Change your privacy settings to see the content.
In order write or read comments you need to have functional cookies enabled.
You can adjust your cookie preferences here.
Share