Shadow IT as a symptom, not a disease. What businesses aren’t getting from the IT department

Shadow IT begins when an employee can purchase, set up, or find the tool they need faster than the company can approve it—and it is precisely this difference in pace that increasingly exposes the weakness of the traditional technology management model.

6 Min Read
Phishing, cyber security, AI, cyber attacks
Author: Rawpixel.com / Freepik

Shadow IT can easily be attributed to a lack of discipline: an employee bought an app using a company card, used a private account for work, or fed data into an unauthorised AI model. However, such a diagnosis comes a step too late.

The UK’s National Cyber Security Centre points out explicitly that shadow IT rarely stems from malicious intent. It usually arises when approved tools fail to get the job done, the required service is missing, or the company’s access approval process is too slow.

Shadow IT can therefore be seen as an indicator of the gap between the pace of business and the pace at which an organisation delivers technology.

Technology is no longer purchased exclusively by IT

This is most evident in SaaS. According to Zylo’s SaaS Management Index 2026, business units now control 81 per cent of spending on subscription software, whilst IT directly manages 15 per cent. Spending on applications billed by employees has risen by 267 per cent year-on-year, and ChatGPT has become the most commonly billed application in this way. The data covers over 40 million licences and more than $75 billion in expenditure managed by the Zylo platform.

This is not a representative sample of the entire economy, but the scale of the dataset clearly illustrates the direction of change. Technology decisions are increasingly being made outside the traditional IT procurement process.

The cost of this decentralisation does not begin with a cyberattack. Zylo estimates that, on average, 36 per cent of SaaS licences remain unused. At the same time, 78 per cent of the 218 IT leaders surveyed had encountered unexpected costs related to AI or usage-based billing in the past year, whilst 61 per cent had scaled back other projects due to such cost increases.

Shadow IT is therefore also becoming a financial problem. A company may formally restrict its technology budget, whilst at the same time funding a fragmented portfolio of tools, the usage, contracts and costs of which no one can fully see.

AI has shortened the path from need to risk

Generative AI has shifted the balance even further. Launching a new tool requires no deployment, no administrator and no integration. Often, an email address is all that is needed.

In a 2025Netskope survey, 72 per cent of users of generative AI in corporate environments were using personal accounts. Over the course of a year, the volume of data transmitted to GenAI applications increased more than thirty-fold. Content breaching security policies included source code, regulated data, intellectual property, as well as passwords and keys.

The DeepSeek case clearly illustrates the dynamics of this phenomenon. At its peak, users attempted to access the service in 91 per cent of the organisations monitored by Netskope. Three-quarters of companies blocked it entirely. At the same time, the number of actual users was small: on average, 0.16 per cent of employees attempted to access the blocked service.

This is an important distinction. The problem need not be the mass use of a single application. The problem is the speed at which a new tool can appear almost simultaneously in hundreds or thousands of companies before it undergoes an assessment of security, privacy and data processing conditions.

The lack of visibility already comes at a quantifiable cost

IBM analysed 600 organisations that experienced data breaches between March 2024 and February 2025. One in five reported an incident related to shadow AI. Organisations with high levels of uncontrolled AI use incurred, on average, a breach cost that was $670,000 higher than that of firms with low levels of, or no, shadow AI. Only 37 per cent of those surveyed had mechanisms in place to manage AI or detect its unauthorised use. The findings cannot be generalised to all businesses, as the survey covered companies that had already experienced a breach.

From 2 August 2026, the issue will also take on a more specific regulatory dimension in Europe: the European Commission has begun enforcing further provisions of the AI Act, including new transparency obligations regarding certain parts of AIsystems .

The mere use of an unapproved application does not automatically constitute a breach of the AI Act. However, an organisation that does not know which models its employees are using, for which processes and with what data, faces a much more difficult task than a company that does have this overview.

Shadow IT therefore reveals something more fundamental than user non-compliance. It highlights areas where official technology is too slow, too limited or too difficult to obtain. As long as setting up an account on a new service takes a minute, whilst obtaining an approved tool takes weeks, the problem will not be limited to security alone. It will concern the very structure of the IT model itself.

Share This Article