You did this properly. Permission audit before activation. Staged rollout, one agent at a time. Vendor questions in writing.
Meanwhile, a manager pasted three direct reports' performance reviews into a free chatbot to "make the tone more constructive." Someone in finance uploaded the comp planning sheet to get a chart out of it. A recruiter has been running resumes through a consumer AI tool since March, which — depending on your states — may have quietly created notice obligations nobody knew to meet.
None of it touched your HRIS's AI features. None of it shows up in your governance program. All of it is your data, outside your control, on terms you never reviewed.
That's shadow AI, and the honest starting point is this: it isn't a future risk you're preventing. It's a current practice you're discovering.
The numbers say it's already happened
Verizon's 2026 breach report found that roughly two-thirds of employees who use generative AI on work devices do it through personal accounts — outside any enterprise agreement, invisible to any control you own. The same report ranks shadow AI as the third most common non-malicious insider data-loss event, a fourfold increase in a single year.
The governance side hasn't caught up, though it's moving. Littler's employer survey in May 2026 found 68% of employers now have formal AI use policies — up from 38% a year earlier — and 54% restrict what information can be entered into AI systems. Real progress, until you look at the quality: SHRM's research, fielded in December 2025, found that among organizations using or piloting AI, only 49% have a policy at all, and only a quarter of those consider it clear and future-proof. The same study found 57% of HR professionals in states with workplace-AI laws don't know those laws exist.
And the consequence when governance lags: IBM's 2025 breach study found 63% of organizations lacked AI governance policies, and among organizations reporting an AI-related security incident, 97% lacked proper AI access controls.
Read those together and the picture is: adoption is universal, most of it is invisible, the policies are new and vague, and the people expected to enforce them can't name the laws involved.
Why HR data is the worst case
Shadow AI in engineering leaks code. Shadow AI in sales leaks pipeline. Shadow AI in HR leaks people — and people-data carries obligations the other categories don't.
Some of it is legally required to be walled off. As we laid out in the permission audit, ADA accommodation records, genetic information, and FMLA certifications must be kept in separate confidential files by federal regulation. An employee who pastes an accommodation email thread into a consumer chatbot has moved legally-segregated medical information into a system with no wall at all.
The consumer terms are the opposite of your enterprise terms. Your HRIS vendor commits in writing that customer data isn't used to train models. A free consumer AI account makes no such promise to your company, because your company isn't the customer — your employee is. No DPA, no retention control, no deletion path, no audit right. The upload is a one-way door.
Confidentiality can be forfeited by the act itself. California employment lawyers have put this bluntly: once confidential information goes into a public AI tool, the company can lose control of it — and trade-secret protection depends on demonstrating reasonable efforts to maintain secrecy. "We had no policy and no controls" is the opposite of that demonstration.
The compliance duties don't care that the tool was unsanctioned. If a recruiter screens candidates through a consumer AI tool, the obligations that attach to automated screening — California's ADS regulations, Illinois notice duties, NYC's bias audit — attach to you, the employer. "That wasn't an approved tool" is an admission, not a defense.
And note where the pipeline starts: almost every HR shadow-AI incident begins with an export. The report download, the comp CSV, the review packet PDF. Which is why step 10 of the permission audit — who can run and schedule exports — is quietly also your shadow AI control.
Why the ban fails
The instinctive policy is prohibition. It has a fatal flaw: the two-thirds figure is the ban's failure mode, already measured. Personal accounts on work devices is what routing-around-the-rule looks like at population scale.
A ban doesn't stop the behavior. It relocates the behavior to where you can't see it, and it converts every user into someone with a reason not to tell you what happened. The org with a strict ban and no sanctioned alternative doesn't have less shadow AI than its competitors. It has the same amount, plus zero visibility, plus a workforce that's learned concealment is the safe move.
People aren't pasting the comp sheet into a chatbot to defy you. They're doing it because they have a chart to make by 2 p.m. and the chatbot is the fastest tool in reach. Shadow AI is a demand signal wearing a compliance problem's clothes.
The policy that actually gets followed
Six components. The first one does most of the work.
1. A sanctioned path that wins on convenience. The only thing that beats a free tool in reach is a better tool in reach. An enterprise-grade assistant under a real agreement for general work — and for HR questions specifically, this is precisely what your HRIS's own AI is for. A permission-aware assistant that answers "how much PTO do I have" and "draft this review" inside the system, rolled out properly, doesn't just deliver its own value. It drains the demand that feeds the shadow.
2. Input rules by data class, not by vibe. "Don't enter confidential information" fails because nobody applies a definition under deadline. Use the sensitivity map you already built for the permission audit and make it a traffic light: green (public and general content — fine in approved tools), yellow (internal business content — approved tools only), red (anything about an identifiable employee or candidate: comp, health, performance, investigation material, SSNs — never leaves the systems it lives in, any tool, any tier). One page. Examples, not abstractions.
3. Output ownership. Whoever uses AI output is accountable for its accuracy, full stop. This clause matters most in HR, where the output becomes a review, a termination letter, or a policy answer someone relies on.
4. Monitoring, disclosed. If you're watching for AI use on corporate devices — and your security stack likely now is, given where DLP tooling has gone — say so. Undisclosed monitoring discovered later costs more trust than shadow AI ever did.
5. An incident path that rewards the report. The person who tells you they pasted the wrong thing has handed you containment while it still matters. Design the response so the first mover gets help, not a write-up — or accept that you'll hear about incidents only from forensics.
6. Training aimed at managers. Managers are the heaviest shadow users in HR workflows — reviews, comp notes, sensitive letters — and they're also who employees imitate. Train the red-light list, and train the sanctioned path, to them first.
One uncomfortable mirror, while we're here: HR is usually the policy's owner and one of its likeliest violators. Review-drafting into consumer tools is the single most common HR shadow use we see. Start the enforcement conversation at home.
Where this meets the rest of your AI program
Shadow AI isn't a separate initiative. It's the missing half of the one you're already running:
- The permission audit limits what any AI — sanctioned or not — can be fed, because export rights are shadow AI's supply line.
- The sanctioned rollout is your demand-side fix; every question your HRIS AI answers well is a question that never reaches a personal account.
- The California policy piece already carries the two clauses this article operationalizes — approved-tool lists and input restrictions are items 2 and 7 of the clause set counsel asks for.
If you have the three of those, this article is one policy section and a training session. If you have none of them, shadow AI is the argument for starting: it's the version of the risk that's already live.
People Street's take
Every company we meet is somewhere on the same arc: first "our people aren't really using AI," then the DLP report that says otherwise, then a ban, then the discovery that the ban moved the problem into personal accounts, then — finally — the real fix, which was available the whole time.
Skip to the end. Give people a sanctioned tool that's actually better than the shadow one, write input rules concrete enough to follow under deadline, and make reporting a mistake cheaper than hiding it. Shadow AI shrinks when the sanctioned path wins on convenience, and not before.
The lagging indicator is the DLP alert. The leading indicator is whether your approved tool answered the question first.
If you don't know which of the two your company is measuring, book a 20-minute call.
A note on the legal points: this article touches trade-secret, privacy, and employment-law issues in passing. It is orientation, not legal advice — the policy language itself should go through your counsel, and our California piece covers why that review matters more this year than most.
Related: The permission audit your AI needs · HR AI policy for California employers · Bob Companion rollout: which agents first