What is shadow AI? Why Claude, ChatGPT, and Copilot are a business risk
TL;DR: Shadow AI is staff using Claude, ChatGPT, Gemini, Copilot, or an AI notetaker for work without an approved account, a data processing agreement, or IT visibility. IBM's 2026 Cost of a Data Breach Report found shadow AI incidents in 43% of breached organizations, up from 20% a year earlier, with average cost of $5.39 million. PagerDuty's 2026 survey found 88% of office professionals had shared work information with public AI tools, including customer data. The model is not the villain. A personal Free or Pro login is. Move work onto a commercial plan, keep secrets out of chat, and run known processes as playbooks.
What is shadow AI?
Shadow AI is the unsanctioned use of an AI tool at work. IBM defines it as any AI application used without formal IT approval or oversight. It is the AI-era version of shadow IT, with a worse data problem: the tool does not only store a file. It reads, summarizes, and in many consumer plans, may train on what you paste.
It is not "anyone using Claude." Claude for Work (Team and Enterprise), ChatGPT Enterprise, Gemini for Workspace, and Microsoft 365 Copilot under a company tenant are sanctioned AI when IT connected them, signed a data processing agreement, and set the rules. The same product on a personal Gmail login, used to rewrite a customer export, is shadow AI.
Common forms:
- A personal Claude Free, Pro, or Max account used for work email, CRM notes, or code
- ChatGPT, Gemini, or Perplexity in a browser tab with no SSO
- An AI meeting notetaker invited to a customer call without a vendor review
- A browser extension that reads the page and sends it to a model
- A homemade MCP connector that pastes Salesforce or HubSpot into a personal chat
IBM's explainer: What is shadow AI?
The public numbers
These are industry figures, not Ballet scores.
| Source | Number | What it measures |
|---|---|---|
| IBM / Ponemon, Cost of a Data Breach 2026 | 43% of breached orgs had a shadow AI incident (was 20%) | Unapproved AI in the breach path |
| IBM / Ponemon, 2026 | $5.39 million average cost when shadow AI was involved (was $4.63 million) | Breach cost, not a model fee |
| IBM / Ponemon, 2026 | 49% data loss, 42% disrupted operations; about 1 in 5 paid a regulatory fine | Consequences of those incidents |
| IBM / Ponemon, 2026 | 68% of breached orgs lacked AI governance | Access, inventory, and oversight |
| IBM / Ponemon, Cost of a Data Breach 2025 | 13% had an AI model or application breach; 97% of those lacked proper AI access controls | First year IBM treated this as its own category |
| IBM / Ponemon, 2025 | High shadow AI added about $670,000 and a median 247 days to detect | Extra cost and dwell time |
| PagerDuty / Wakefield, 2026 (n=1,250) | 66% used AI at work believing it was not permitted | Policy vs behavior |
| PagerDuty / Wakefield, 2026 | 88% shared work information with ChatGPT, Claude, or Gemini | What left the building |
| PagerDuty / Wakefield, 2026 | 43% emails, 40% meeting notes, 34% customer data, 31% financial or confidential files | The paste list |
| Microsoft UK / Censuswide, Oct 2025 (n=2,003) | 71% used unapproved consumer AI at work; 51% did so weekly | UK office workers |
| Cloud Security Alliance, May 2026 | 80% of employees use unapproved AI; 37% of enterprises have an AI governance policy; 89% of enterprise AI use is invisible to security | Visibility gap |
| Gartner (cited 2026) | By 2030, more than 40% of enterprises will have a security or compliance incident tied to unauthorized shadow AI | Forecast, not a 2026 count |
PagerDuty's write-up: Shadow AI is already inside your organization. IBM 2026 press: one in four malicious breaches are AI-enabled. IBM 2025 press: 13% reported AI model or application breaches.
Why Claude is in the same bucket as ChatGPT
Ops teams often treat Claude as the "safer" chat. Anthropic's commercial terms are stricter than its consumer terms. That gap is the risk.
In August 2025 Anthropic updated consumer terms. On Claude Free, Pro, and Max, chats and coding sessions can be used to train new models when the "Help improve Claude" setting is on. The in-app prompt defaulted that setting on. Users who accept training also move from roughly 30-day retention to up to five years. Users who turn the setting off stay on the shorter retention window. Wired walked through the opt-out: Anthropic will use Claude chats for training.
Claude for Work (Team and Enterprise) and the Anthropic API sit under commercial terms. Anthropic says it does not train on those chats or coding sessions unless the customer joins the Development Partner Program. For those products Anthropic acts as a data processor and the company is the controller. See How do you use personal data in model training? and Does Anthropic act as a processor or controller?.
The same split exists at the other providers:
| Plan | Typical training default | Who is the customer | Shadow AI if used for work? |
|---|---|---|---|
| Claude Free / Pro / Max | On unless the user opts out | The individual | Yes |
| Claude Team / Enterprise / API | Off unless the org joins a partner program | The company | No, if IT issued the seat |
| ChatGPT Free / Plus / Pro | On unless the user opts out | The individual | Yes |
| ChatGPT Enterprise / API | Off for customer content | The company | No, if IT issued the seat |
| Gemini consumer | Can train; longer retention on some plans | The individual | Yes |
| Gemini for Workspace | Off for customer content under Workspace terms | The company | No, if IT issued the seat |
| Personal Copilot / consumer GitHub | Varies by product and setting | The individual | Yes |
| Microsoft 365 Copilot / GitHub Copilot Business | Tenant controls and a company DPA | The company | No, if IT issued the seat |
A seller on a personal Claude Pro plan who pastes a Salesforce opportunity export is not "using Salesforce in Claude." They are uploading customer records to a consumer product. The official path is the Claudeforce plugin: per-user OAuth, mcp_api scope, ask-before-write. Details: Salesforce in Claude.
What actually leaves the building
Most incidents are not a hacker. They are a paste.
Customer records. A support or RevOps person dumps a CRM view into chat to draft an email or a QBR. Names, emails, deal amounts, and complaint history now sit with a consumer vendor. PagerDuty put customer data at 34%.
Credentials. API keys, VPN passwords, and Snowflake tokens get pasted inside a "debug this" snippet. IBM's 97% figure was among organizations that already had an AI-related breach: almost none had proper AI access controls. Related, not the same problem: Google Threat Intelligence documented UNC6395 using stolen Salesloft Drift OAuth tokens to pull data from Salesforce orgs and search for AWS and Snowflake secrets. Ungoverned AI connectors are a cousin of shadow AI. GTIG advisory.
Source code and strategy. Samsung's 2023 ChatGPT incident (engineers pasting semiconductor source into a consumer chat) is still the template. The file never went through email DLP. It went clipboard to browser.
Meeting audio. An unsanctioned notetaker joins a customer call. The transcript includes pricing, legal positions, and personal data. Reco has reported on the order of 200 unsanctioned AI tools per 1,000 workers at mid-size firms (Business Insider, May 2026).
Why DLP misses it. Traditional DLP watches file shares, email, and known SaaS uploads. Shadow AI is a browser paste. There is often no file, no ticket, and no vendor in the inventory. CSA reported generative AI as the largest channel for corporate-to-personal data movement in the datasets they reviewed.
Once the text is in a consumer training corpus or a five-year retention bucket, you cannot recall it. Deleting the chat does not untrain a model that already started.
Compliance, not only security
The legal problem is unauthorized processing, even when nobody "steals" the file.
GDPR. An employee who sends EU customer data to a consumer chatbot has used a processor with no Article 28 data processing agreement and no record of processing. Fines for serious infringements can reach €20 million or 4% of worldwide annual turnover. IBM listed GDPR in its shadow AI explainer for this reason.
SOC 2. Sending customer data to a vendor that is not in the inventory and has no review fails the usual reading of CC6.1 (logical access) and CC9.2 (vendor risk). Auditors have started asking which AI tools process customer data.
HIPAA and PCI. PHI or card data in a personal Claude or ChatGPT prompt is a disclosure to a party that is not a business associate or a PCI service provider.
EU AI Act. Deployer duties and transparency rules still attach to the organization when staff use AI on work data, including tools nobody approved. Colorado's AI Act became enforceable 30 June 2026. Policy-only bans do not create evidence.
A commercial Claude, ChatGPT, or Copilot seat with a signed DPA, SSO, and an acceptable-use policy is the minimum that makes the vendor conversation possible. It does not by itself stop someone pasting an admin password.
Why a ban makes it worse
PagerDuty found 77% of office professionals said AI restrictions limited their career, and 75% would look for a job with better AI access. Microsoft's UK number (71% using unapproved tools) is what a ban looks like in the wild: usage moves to a personal phone.
CSA cited research that unauthorized use dropped sharply when a sanctioned alternative existed. The working pattern is a three-tier list, not a wall:
- Approved. Company Claude, ChatGPT Enterprise, or Copilot. SSO. No customer data in consumer plans.
- Limited. Drafting and brainstorming on public information only. Named data types that must never be pasted.
- Prohibited. Unknown extensions, personal MCP servers into the CRM, credentials in any chat.
If the approved tool cannot do the job, people will open a personal tab. That is how shadow AI starts.
What to do this quarter
- Inventory who already uses Claude, ChatGPT, Gemini, Copilot, and notetakers. SSO logs and a one-question survey beat guessing.
- Issue commercial seats for the jobs people are already doing. Consumer Pro is not a company license.
- Write a one-page AI acceptable use policy and actually send it. CSA noted surveys where few employees knew a policy existed.
- Ban credentials, production data, and regulated fields from any prompt. Say it in the tool, not only in a wiki.
- Prefer official connectors (Salesforce-hosted MCP, HubSpot Agent CLI) over a homemade bridge. Start read-only.
- Keep secrets in a workspace vault. Never in chat history.
- For work that must be the same every time (refund, stage change, lead route), save the path. Do not re-decide it in a personal chat. See How to automate lead routing with AI.
Gartner's cancellation forecast names "inadequate risk controls" as a reason agent projects die. Shadow AI is that control gap showing up before the official pilot. Why 40% of agentic AI projects get canceled.
Where Ballet fits
Ballet does not replace Claude. It stops the company from treating a personal chat as the runtime.
- Claude (on a company plan) writes the playbook.
- The playbook runs as compiled steps. The same refund or route does not depend on whoever opened a Free tab that morning.
- Workspace secrets stay out of the prompt. The model is not a keyring.
- A named person can run a process without permission to rewrite it.
- The run log shows who ran what, on which version, with which approval.
That is governance, security, and predictable output for the work you already know. Longer argument: Claude writes the playbook. Ballet runs it..
FAQ
What is shadow AI? Staff using an AI tool for work without IT approval, a company account, or a data processing agreement. Personal Claude, ChatGPT, Gemini, and Copilot are the usual examples.
Is using Claude at work shadow AI? Personal Free, Pro, or Max used for company data: yes. Claude Team, Enterprise, or API issued by IT: no. The product name is the same. The contract is not.
Does Anthropic train on my work chats? On consumer plans, yes if the training setting is on (the 2025 default). On Claude for Work and the API, Anthropic says no, unless the customer joins a partner program.
Why is shadow AI a business risk? Customer data and secrets leave for a vendor you did not assess. You cannot untrain a model. IBM now measures this as extra breach cost, longer detection, and in about one in five cases a fine.
Should we ban ChatGPT and Claude? No. Issue a commercial seat and name the data that must not be pasted. Bans move the same paste to a personal phone.
How do we keep CRM data out of chat? Use the official Salesforce or HubSpot connector with the signed-in user's permissions. Do not export a list into a personal prompt. Put repeated updates on a playbook.
Related articles
- Salesforce in Claude: what shipped, what it can write, what it cannot govern
- Why 40% of agentic AI projects get canceled
- Claude writes the playbook. Ballet runs it.
- n8n vs Zapier vs Ballet for AI agents (2026)
- Why Ballet
Sources
- IBM, What is shadow AI?
- IBM / Ponemon, Cost of a Data Breach Report 2026 (29 July 2026; 602 organizations, March 2025 to February 2026)
- IBM / Ponemon, Cost of a Data Breach Report 2025
- PagerDuty / Wakefield Research, 2026 Shadow AI Survey (1,250 office professionals, companies at or above $500 million revenue)
- Anthropic, Updates to consumer terms and privacy policy (August 2025)
- Anthropic Privacy Center, Personal data in model training
- Wired, Anthropic will use Claude chats for training
- Cloud Security Alliance, Shadow AI apps: the enterprise attack surface (30 May 2026)
- Business Insider, The sneaky rise of shadow AI (Microsoft UK / Censuswide and Reco figures)
- Google Threat Intelligence, Salesloft Drift / Salesforce data theft
