News

Shadow AI and what it is really telling you

Part 3 of a 5-part series: The human AI system.

The AI use happening off the books is one of the most honest readings of your culture you will get this year. Most leaders are treating it as a compliance failure. Read it properly and it will tell you more in an afternoon than your last engagement survey did in a quarter.

Kerry, a CMO, receives a market summary from Rhoda, a senior analyst on her team on Thursday afternoon. It is good - noticeably better than her usual work, and two days early. Kerrie tells her so. She says thank you.

Neither Kerrie nor her senior analyst mention something Kerrie suspect. Rhoda did not write it alone.

Rhoda used a personal account on her phone over lunch. She will not tell Kerrie this. She has done nothing particularly wrong, but she cannot work out what happens if she says it out loud. Will it turn into a data incident, or a conversation about whether the analysis was really hers? Might it quietly change what you think she is capable of? So she says nothing.

Meanwhile Kerrie’s organisation has an AI adoption programme, with a policy, a licensed tool, a training module and a dashboard reporting seat utilisation at thirty-four per cent.

Let me give you my conclusion up front. Shadow AI is a trust and psychological safety reading with a security side effect, and the right response is to measure the gap between AI use and AI disclosure, then work to close it.

Three reasons follow. Your adoption number only counts the use people are willing to show you. People hide the rest because of what they expect honesty to cost them, and policy has surprisingly little to do with it. Once you read the hidden use as a signal, it will show you exactly where to act, in practical steps a team leader can run inside a fortnight.

1. Your adoption number counts only what people will let you see

Most organisations measure AI adoption as a rate - active licences, how often, for what. It is a tidy metric and it misses most of the behaviour, because the behaviour is largely unsanctioned and unspoken. The evidence on this is now consistent across independent sources.

  • Fifty-seven per cent of employees say they hide their AI use and present AI-generated work as their own, in a study of over 48,000 people across 47 countries (Gillespie et al., 2025).
  • Forty-eight per cent of desk workers would be uncomfortable telling their manager they had used AI for common tasks (Slack, 2024).
  • Seventy-eight per cent of AI users bring their own tools to work, and fifty-two per cent are reluctant to admit using AI on their most important tasks - the ones where judgement matters most (Microsoft & LinkedIn, 2024).

Put those together and the picture is a workforce that has embraced AI and would rather not say so. The distance between those two facts is the most valuable diagnostic your organisation owns, and almost nobody is measuring it.

2. People hide AI use because of the expected social cost

When Slack asked workers who felt uncomfortable disclosing AI use why, the top answers were that it feels like cheating (47%), fear of being seen as less competent (46%) and fear of being seen as lazy (46%). The least common reason, at 21%, was that company policy discouraged or prohibited it. Policy came last, by a distance.

That finding maps almost line for line onto what organisational psychology has understood for twenty-five years. Edmondson’s original work on psychological safety identified the image risks people manage at work by staying quiet - being seen as ignorant, incompetent, negative or disruptive (Edmondson, 1999). Milliken and colleagues found the same thing in how employees decide what to withhold from managers: silence is rarely about the rule and almost always about the anticipated reaction (Milliken et al., 2003). Detert and Edmondson later showed that these calculations run on unwritten rules people have never been taught and often cannot articulate (Detert & Edmondson, 2011). Cheating, incompetent, lazy is the same image-risk list reappearing thirty years on with a new trigger.

This matters because it decides what will work. If you believe the cause is unclear policy, you write a better policy. Organisations have been doing that for two years and the concealment numbers have not moved. If you believe the cause is anticipated social cost, you work on the social cost, which is a different intervention run by different people on a different timescale.

Why it concentrates in the middle

In Part Two of this series, I argued that AI adoption is most often decided, and most often lost, in the middle management layer, because we ask managers to steady a team through a change they have not yet absorbed themselves. Shadow AI is where that squeeze becomes visible.

Microsoft’s 2026 Work Trend Index found leaders were far more likely than employees to say they feel safe suggesting new ways of working with AI (81% versus 67%), and more likely to say their managers make room for experimentation (78% versus 59%). Only around one in eight AI users said reinventing work with AI is rewarded when the results are not guaranteed. The same research found that organisational factors such as culture and manager support carried roughly twice the impact of individual effort.

Senior leaders are assessing the climate from the warmest room in the building and concluding it is temperate. The people two layers down are making a colder calculation and acting on it, privately and rationally. The manager in between holds both readings and is appraised on the dashboard. That is why “be more transparent about AI”, issued from the top, fails. It is heard as an invitation to volunteer for exposure in a climate the person asking has never had to survive.

3. Read as a signal, the shadow tells you where to act

Once you stop treating covert use as noise to be eliminated, it becomes one of the most reliable instruments you have. Every pocket of shadow AI is broadcasting three things at once.

Where the work is hard

People rarely take personal risks to automate something they did not mind doing. People reach for unsanctioned tools exactly where the work is tedious or cognitively expensive, so your shadow AI map is a free, continuously updated heat map of friction, assembled by the people who do the work. Most organisations pay six figures for a worse version of it and call it a process review.

Where your formal channel is too slow

Shadow AI use also measures the gap between how fast people need a capability and how fast you can approve one. When that gap is longer than a deadline, people route around it out of ordinary conscientiousness. If procurement takes nine months and delivery takes nine days, shadow AI is arithmetic, not indiscipline.

Where professional identity feels threatened

This is the one that matters most and gets the least attention. Concealment concentrates on the tasks people believe define their value, and the Microsoft data makes that precise: reluctance to disclose peaks on the most important work. The analyst will happily say AI tidied her formatting. She will not say it helped her structure the argument, because the argument is what she believes she is paid for. The distribution of silence across your organisation maps where people feel their worth is up for renegotiation, which is why it deserves a place on the workforce risk register.

4. Four steps forward

Here are four positive leadership steps you can take progressively to build trust and close the gap between actual usage and disclosure.

i. Measure the disclosure gap, not the seat count

Across my global client and research work, I have found that this is the step organisations usually skip. They find unsanctioned use, feel the jolt of risk and go straight to control, and the pocket disappears from view without ever having been read.

Here are two anonymous questions that you could poll:

  • In the last month, have you used an AI tool for a work task?
  • Would you be comfortable telling your manager which task?

The difference between those two numbers is your disclosure gap. Segment it by team and by level and look for variance, because the average will tell you nothing. Two teams doing identical work with a thirty-point difference in disclosure is a story about two managers. Then add one free-text question - what would have to be true for you to say so? The answers will often be short and specific, and you can act on most of them within the week.

ii. Decode each pocket of shadow AI before you do anything further

For every concentration of shadow use, ask three questions before deciding anything about tooling:

What task is it attached to? The tool is interchangeable; the task is the signal.
What does the workaround reveal about the sanctioned path - speed, capability or credibility?
What is the person protecting by not telling you - time, reputation, or a judgement they are unsure they are allowed to delegate?

iii. Show evidence that disclosure is a strength before you make it mandatory

You cannot require honesty and trust into existence; you can only lower its cost until people can afford it. You could run an amnesty with a fixed end date, gather some senior champions who are prepared to disclose and reward them for it. You need to mean it - no follow-up conversation, and no quiet recalibration of anyone's reputation. A broken amnesty quickly undermines trust, so if you cannot commit, do not run one.

As a leader, you should go first, and be specific. “I use AI too” costs the speaker nothing and everyone knows it. What works is disclosure with the discomfort left in: “I did my first draft of the board paper with Claude. It gave me a better structure than I had. I rewrote the risk section because it did not know about the regulator conversation. I am still not sure whether I should have told you.” That last sentence matters most, because it admits to the calculation everyone is privately running.

Separate the two questions people are actually asking: is this safe and is this legitimate, and answer the second out loud, because in its absence people default to the ambient answer, which the Slack data shows is “it feels like cheating”. Make sure you open up the conversation and keep it going about good use at task level, in concrete examples. For instance, using AI to generate three framings of an argument is expected, while sending its first draft to a client unread is not. People cannot calibrate against a values statement.

iv. Convert the workaround into BAU

When someone surfaces a shadow workflow that is better, adopt it as the standard and credit them by name in the documentation, not just in a team meeting. This inverts the incentive. The moment the visible consequence of disclosure is credit rather than scrutiny, you are running a distributed R&D function that reports continuously and costs nothing. You will only need to do it two or three times, because people take their cue from what happened to the last person who told the truth.

A note on banning it

Bans do not reduce use; they reduce disclosure. They push the same behaviour onto personal devices and personal accounts, where you have neither visibility nor recourse, so they worsen the risk they were meant to manage. There is a subtler cost too. A ban answers the legitimacy question and answers it wrongly. It tells a workforce that already suspects AI use is cheating that they were right, and that belief will outlast the policy by years.

What to do first

Ask the two questions, anonymously, of one team, this week. If the numbers match, you have an unusually healthy team and should find out why, because whatever that manager is doing is your real adoption strategy and nobody has written it down. If they do not match - and they will not - you have just bought the most useful piece of organisational data you will see this year for the price of a two-question survey. It will show you where the work is hard, where your systems are too slow, and where people quietly believe their value is under review - none of which appears on your dashboard, and all of which the shadow has been telling you for months.

Next, in Part Four - Building the Human AI System: a practical framework for AI-ready organisations, and how the AI-LEAD™ conditions turn a disclosure gap into an adoption curve.

References
Detert, J. R., & Edmondson, A. C. (2011). Implicit voice theories: Taken-for-granted rules of self-censorship at work. Academy of Management Journal, 54(3), 461-488. https://doi.org/10.5465/amj.2011.61967925
Edmondson, A. C. (1999). Psychological safety and learning behavior in work teams. Administrative Science Quarterly, 44(2), 350-383. https://doi.org/10.2307/2666999
Gillespie, N., Lockey, S., Ward, T., Macdade, A., & Hassed, G. (2025). Trust, attitudes and use of artificial intelligence: A global study 2025. The University of Melbourne and KPMG. https://doi.org/10.26188/28822919
Microsoft. (2026). 2026 Work Trend Index annual report: Agents, human agency, and the opportunity for every organization. https://www.microsoft.com/en-us/worklab/work-trend-index/agents-human-agency-and-the-opportunity-for-every-organization
Microsoft & LinkedIn. (2024). 2024 Work Trend Index annual report: AI at work is here. Now comes the hard part. https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part
Milliken, F. J., Morrison, E. W., & Hewlin, P. F. (2003). An exploratory study of employee silence: Issues that employees don’t communicate upward and why. Journal of Management Studies, 40(6), 1453-1476. https://doi.org/10.1111/1467-6486.00387
Slack. (2024). The Fall 2024 Workforce Index: Executives and employees are investing in AI, but uncertainty is holding back adoption. https://slack.com/blog/news/the-fall-2024-workforce-index-shows-executives-and-employees-investing-in-ai-but-uncertainty-holding-back-adoption

Read next

Transform your workplace


With Enmasse, you’re not just hiring a consultancy. You’re partnering with a team dedicated to transforming your organisational culture and community for the better.

Let’s talk