Experts Warn Shadow AI Bans Increase Security Risks
Industry experts advise organizations to shift from banning unapproved AI tools to a governance strategy to prevent data leaks via personal accounts.
Security experts are warning that aggressive bans on shadow AI—the use of unapproved artificial intelligence tools by employees—are inadvertently increasing organizational security risks. By prohibiting these tools, companies drive employees to use unmonitored personal accounts, leaving security teams blind to potential data leakages.
Data from major technology providers shows widespread adoption of unapproved tools. Microsoft reported that 78% of AI-using employees brought their own tools to work in 2024, and Salesforce, Inc. found that over half of AI adopters used unapproved tools in 2023. The risks associated with this trend are evident in Cisco's 2025 index, which found that 86% of organizations experienced an AI-related security incident in the previous year.
Nidhi Jain and other experts argue that traditional security stacks, including CASB and DLP, cannot sufficiently detect AI-driven data egress. They recommend a governance strategy focused on discovery and visibility. This approach involves deploying sanctioned enterprise alternatives with built-in data boundaries before restricting personal accounts, ensuring employees do not route around security controls.