Shadow AI: Adoption Outpaces Policy and Governance

Goering Center Blog

2026

Shadow AI: Adoption Outpaces Policy and Governance

Shadow AI: Adoption Outpaces Policy and Governance

More than half of small businesses in the United States are now actively using generative AI tools, according to the U.S. Chamber of Commerce’s 2025 data. That number is accelerating. What is not accelerating at the same rate is policy.

CybSafe and the National Cybersecurity Alliance found in late 2025 that 58% of employees using AI tools have received no training on the security or privacy risks involved. For most organizations, that absence of guidance is itself a policy decision: anything goes.

The consequences of that gap are no longer theoretical. IBM’s 2025 Cost of a Data Breach Report found that organizations with high levels of unsanctioned AI use paid an average of $670,000 more per breach than organizations with structured AI governance. When an employee pastes a client contract into a public AI tool for a quick summary, that data does not remain in the conversation. It enters the vendor’s training data. It cannot be recalled.

This is Shadow AI: employees using AI tools that IT and leadership have never reviewed or approved. Microsoft’s internal data shows that 82% of employees who use AI are using tools their employer never sanctioned. Varonis’s telemetry across 1,000 real IT environments confirms that 98% of organizations have some form of Shadow AI operating inside their networks right now. The National Cybersecurity Alliance adds that 43% of employees have explicitly admitted to sharing sensitive workplace information with AI tools without permission.

The instinctive response from many leaders is to ban it. That approach is both futile and counterproductive. Employees who need to keep pace with their workloads will find a way, on personal devices and personal networks, outside any corporate visibility. You lose the productivity benefit while retaining all the risk.

The organizations pulling ahead are doing something different. They are building governance frameworks that define what tools are approved, how different types of data must be handled, and who has the authority to expand AI use over time. The result is not a restriction. It is speed. When employees know the rules, they stop asking for permission on every task and start working. That clarity is built in weeks, not months.

For Cincinnati’s family and private businesses, this moment is a genuine opportunity. The governance gap is wide. Most competitors have not addressed it. The company that builds a clear AI policy today does not just reduce its risk. It earns a capability advantage that compounds as AI becomes more central to every business function.

The question is not whether your team is using AI. They are. The question is whether your organization has decided what that should look like, and whether you are capturing the return or absorbing the exposure.