Since 2008 · Next open Train the Trainer workshops: 18–21 Nov, Mumbai · 9–12 Dec, Bengaluru
Soft skills & communication

Shadow AI: Your Team Is Already Using Tools You Never Approved

It is 9:40 on a Tuesday night. Rohan, a finance manager at a Hyderabad manufacturer, has a board note due at 8 a.m. He pastes the quarter's supplier-wise margin table into a free AI chatbot on his personal phone, asks for a summary, and watches a clean paragraph appear. He is done in ten minutes and goes to bed relieved.

In brief

Roughly half of employees use AI their company never approved, while few have real training. Why bans fail and what actually makes AI use safe in Indian teams.

Key takeaways

  • India's employees are early and eager adopters. Slack's Workforce Index (December 2024, 1,029 Indian desk workers) found 61% already using AI at work, with 94% feeling urgency to master it, yet 40% had spent under five hours learning it.
  • The enablement gap is wide: a Udemy and YouGov report (November 2025) found only about three in ten India-based professionals felt confident in their AI skills, and 61% said employers did not give clear ways to use AI in daily tasks.
  • People rarely misuse AI out of defiance. They do it because they are under time pressure and have no approved route and no clear rule.
  • Bans push use further underground. Training, clear "green-amber-red" rules and manager habits reduce risk far more reliably.

Last updated · Bodhih Insights team

Shadow AI: Your Team Is Already Using Tools You Never Approved

Nobody approved that tool. Nobody told Rohan not to use it. Nobody told him what he could use, either. His company's AI policy is a two-page PDF that he has never opened.

Multiply Rohan by every team in your organisation and you have shadow AI: the AI tools employees use at work without approval or oversight. It is probably the largest unmanaged change in how work gets done today, and most leaders only find out about it when something goes wrong.

01

Why "Shadow" AI Is Different From Shadow IT

Companies have dealt with unapproved software before. But AI tools differ in one important way: the risk is in the prompt, not the install. No one has to download anything. A browser tab, a phone app or a personal account is enough, and the thing leaving the building is not a file; it is a pasted paragraph, a customer list, a contract clause, a line of source code.

That makes the risk invisible to the usual controls. It also makes it deeply personal. Each decision is small, well-intentioned and made in a few seconds by a person who is trying to do their job faster.

Add the second difference: unlike a rogue spreadsheet tool, AI output looks authoritative. A confident, fluent answer can carry an invented figure into a client deck without anyone noticing, which is the same pattern we described in our post on workslop.

02

The Training Gap Behind the Risk

Look at the numbers side by side. Large shares of employees use AI. Surveys of shadow-AI behaviour consistently find that formal governance and training lag well behind. One vendor study (WalkMe) reported that although most employees used unapproved AI, only a small single-digit percentage had received extensive AI training. Exact figures vary from report to report, but the shape does not: usage is racing ahead of skill.

In India this shows up as an enthusiasm-without-guidance pattern. People are keen, they believe learning AI is their own responsibility, and they teach themselves from social media and trial and error. Self-taught habits then spread through a team by imitation, including the unsafe ones.

03

Why Bans and Policies Alone Don't Work

The instinctive response is a firm email: "Do not use external AI tools." It rarely works, for three reasons.

The work still has to get done. If the approved route is slower than the unapproved one, people take the faster one and stay quiet about it.

Silence replaces learning. A ban turns every mistake into something to hide. The very conversations that would let a team learn what is safe never happen.

Policies are written for lawyers, used by humans. A person at 9:40 p.m. does not consult a policy; they rely on judgement. Judgement is something you can train.

04

What Actually Works: Build Judgement, Not Just Rules

Organisations that handle shadow AI well tend to do four things.

  1. 1. Give people a simple traffic-light rule. Green: public or non-sensitive content, such as rewriting a generic email. Amber: internal material, only on approved tools. Red: customer data, personal data, financial results, source code and anything under NDA, never into an unapproved tool. A rule that fits on a sticky note gets used. Because India's Digital Personal Data Protection Act places obligations on how personal data is handled, the red category deserves particular care; check specifics with your legal team.
  2. 2. Provide an approved option that is good enough. Most shadow use disappears when a sanctioned tool exists, works well and is easy to reach. Pair the tool with role-specific examples so people know how to use it on real work.
  3. 3. Train the skill underneath: verified, responsible use. Spotting a hallucinated number, knowing what not to paste, and rewriting an AI draft until it is actually yours are teachable skills. Hands-on practice in AI Literacy Training builds exactly this, and Critical Thinking Training strengthens the habit of questioning a smooth answer before sending it on.
  4. 4. Equip leaders to set the tone. Teams copy what their managers do and reward. Leaders who openly discuss how they use AI, and where they draw the line, make it safe for others to ask. AI for Leaders helps senior people frame governance, risk and opportunity together, and Change Management Training helps them bring a team along instead of issuing a rule and hoping.
05

A Two-Week Audit Anyone Can Run

You do not need monitoring software to begin. Try this with your own team.

  1. Ask, without blame. In a team meeting, say: "I assume most of us use AI for something. What do you use it for, and what do you wish you were allowed to do?"
  2. List the top five use cases and sort them green, amber or red together.
  3. Name one approved tool for each green and amber use case, and one clear "never paste" list for red.
  4. Run a 90-minute practice session where people apply the rules to their real tasks, including catching a planted error in an AI draft.
  5. Revisit in a month. Ask what got easier and what still pushes people to the shadows.

Most teams are surprised by the first answer. Honest disclosure is the single best predictor that the rest will work.

06

The Bigger Idea

Shadow AI is often described as a security problem. It is better understood as a signal: a map of where your people feel slowed down and where they have decided the official route is not good enough. Leaders who read that signal and answer it with clarity, tools and training will find that risk falls and productivity rises together. Leaders who answer with a ban will simply stop seeing it.

07

Frequently asked questions

What is shadow AI?

Shadow AI is the use of AI tools at work without the employer's approval or oversight, for example pasting work content into a personal chatbot account. It is the AI-era version of shadow IT, with the difference that the risk lies in what employees type into the tool.

How common is shadow AI?

Surveys suggest it is widespread. A January 2026 BlackFog survey of 2,000 UK and US employees found 49% used AI tools their employer had not approved, and a June 2026 PagerDuty survey found 66% of office professionals had used AI at work in ways they believed were not permitted. Figures differ by survey, and most come from technology vendors, so treat them as indicative.

Is shadow AI common in India?

Indian desk workers are among the fastest AI adopters. Slack's Workforce Index found 61% already using AI at work in late 2024, and Udemy's 2025 research found many Indian professionals felt employers gave them no clear way to use AI in daily tasks. Specific shadow-AI rates for India are not well measured, so organisations should find out through their own teams.

Should companies ban public AI tools?

A blanket ban tends to push use out of sight without removing the demand. A more effective approach combines a clear green-amber-red rule, an approved tool that is good enough for daily work, and practical training on what is safe to share and how to verify output.

What data should never be pasted into an unapproved AI tool?

Customer or employee personal data, confidential financials, source code, legal or contract text and anything covered by an NDA. Your legal and security teams should define the exact list, including obligations under India's Digital Personal Data Protection Act.

What training reduces shadow AI risk?

Hands-on training in responsible, verified AI use for all staff, plus leadership training on AI governance and change. Bodhih offers AI Literacy Training, AI for Leaders and Critical Thinking Training, each customisable for corporate batches.

Where do the statistics in this article come from?

The BlackFog (January 2026) and PagerDuty (June 2026) figures are vendor-run surveys of workers in the US and UK. The India figures are from Slack's Workforce Index (December 2024) and a Udemy and YouGov report (November 2025). All are self-reported and should be read as directional.

Let’s talk

Ready to grow your people? Let’s design it together.

Since 2008, Bodhih has designed learning for 2,000+ organisations across 7 regions. Tell us what you need.

Get a tailored proposal Call +91 99000 11601solutions@bodhih.com · Reply within one business day