ManageEngine report reveals shadow AI as both threat and business asset

A new ManageEngine report finds nearly all IT leaders see serious risks in unauthorized Artificial Intelligence, while most employees embrace the potential rewards.

ManageEngine, a division of Zoho Corporation, has released a report titled ´The Shadow AI Surge in Enterprises: Insights from the U.S. and Canadian Workplace´ that uncovers a growing divide between IT decision makers (ITDMs) and employees regarding shadow AI: the use of unauthorized artificial intelligence tools at work. The survey, involving 350 ITDMs and 350 employees in the U.S. and Canada, reveals that 97% of IT leaders perceive significant risks associated with shadow AI, chiefly the threat of data leakage or exposure. In sharp contrast, 91% of employees believe that shadow AI is not risky, only minimally risky, or that its benefits outweigh any risk.

The report highlights that 60% of employees are using unapproved artificial intelligence tools more often than a year ago, and 93% admit to entering work-related information without official approval. Notably, the most common uses for shadow AI include summarizing meeting notes or calls (55%), brainstorming (55%), and analyzing data or reports (47%). While organizations are beginning to approve some generative artificial intelligence tools, including writing and coding assistants, a significant gap in perspective persists between IT governance and employee usage habits. The proliferation of shadow AI has accelerated faster than IT teams can assess and secure these tools: 85% of ITDMs say employees are outpacing security assessments, and over half point to the use of personal devices as a major blind spot.

This rapid growth has exposed glaring gaps in education, visibility, and governance. Many employees have entered confidential or internal data into artificial intelligence tools without proper confirmation of company approval, raising genuine security and privacy concerns. Only 54% of ITDMs report actively enforced and monitored artificial intelligence governance policies in their organizations, despite 91% indicating that at least some policies are present. Strategic recommendations from both IT leaders and employees include integrating approved tools into routine workflows, establishing clear and practical policies, and increasing education around the risks and best practices of artificial intelligence.

ManageEngine executives urge organizations to pivot from a defensive posture to collaborative, proactive management of artificial intelligence adoption. By reframing shadow AI as a sign of genuine business needs rather than mere risk, IT and business teams can develop transparent ecosystems where innovation thrives securely. The report concludes that mastering this balance will separate leaders from laggards as Artificial Intelligence is woven deeper into daily business operations.

66

Impact Score

EU Artificial Intelligence Act omnibus deal delays high-risk rules

A provisional EU agreement would push back key high-risk Artificial Intelligence Act deadlines while keeping major transparency duties on track for 2 August 2026. The deal also adds a new ban on non-consensual intimate imagery and child sexual abuse material generated by Artificial Intelligence systems.

UK and EU Artificial Intelligence regulatory outlook for May 2026

The UK is moving ahead with targeted Artificial Intelligence measures in policing, online safety, cyber security and copyright policy, while the EU is refining how the EU Artificial Intelligence Act will apply in practice. Consultations, new offences and implementation deadlines are shaping the next phase of compliance on both sides.

Germany sets out national implementation of the Artificial Intelligence Act

Germany has published a draft law to implement the European Artificial Intelligence Act through new supervisory structures, clearer institutional responsibilities, and measures designed to support innovation. The proposal puts the Federal Network Agency at the center of enforcement while preserving sector-specific oversight in sensitive fields.

Contact Us

Got questions? Use the form to contact us.

Contact Form

Clicking next sends a verification code to your email. After verifying, you can enter your message.