Shadow AI Surge: The Growing Gap Between Employees and IT
- 82% of Spanish office workers use AI tools not provided or approved by their employers.
- Only 9% of companies have achieved full corporate integration of AI into daily workflows.
- A significant training gap exists, with only 44% of staff receiving formal company AI education.
- The trend indicates a shift where individual adoption outpaces corporate governance and security policies.

The modern office is currently witnessing a silent revolution. While C-suite executives debate the strategic roadmap for artificial intelligence and IT departments struggle to vet secure enterprise software, the workforce has already made its decision. They are not waiting for a corporate rollout; they are simply downloading the tools they need to survive an increasing workload.
This phenomenon, known as Shadow AI, has reached a critical mass. Recent data from a study conducted by OpinionWay for Cegid, titled 'The Moment of Truth for AI in the Company', paints a vivid picture of this disconnect. In Spain, a market that currently leads its neighbors in individual usage frequency, 82% of office employees use AI in their daily tasks. Crucially, the same percentage admits to using solutions that were not provided by their organizations and, perhaps more concerningly, doing so without informing their superiors.
The disconnect between usage and integration
The disparity between how employees perceive AI and how companies implement it is staggering. While the vast majority of the workforce is already leveraging generative AI to summarize documents, draft emails, or analyze data, the institutional side of the equation is lagging. According to the Cegid research, only 9% of companies claim to have fully integrated AI into their daily operations.
This gap suggests that for most businesses, AI is not a strategic pillar but a hidden utility. The adoption rate in Spain has grown by nine percentage points over the last year, with 40% of professionals now using AI habitually—a 16-point jump in just twelve months. Another 42% use it occasionally. When compared to France, Germany, and Portugal, Spanish professionals show the highest frequency of individual use, signaling a workforce that is aggressively self-optimizing in the absence of corporate guidance.
Why employees are bypassing IT protocols
The rise of Shadow AI is rarely an act of rebellion; it is an act of efficiency. Employees are facing mounting pressure to produce more in less time, and the friction of waiting for corporate procurement or security approval is often too high. By using personal accounts on public AI platforms, workers can instantly automate tedious tasks without filling out a single request form.
However, this autonomy comes with a steep price in terms of risk. When 82% of a workforce uses unauthorized tools, the company loses visibility into where its data is flowing. Every prompt entered into a non-enterprise AI tool potentially feeds proprietary company data into a public model, creating massive vulnerabilities in data protection and intellectual property security.
The failure of corporate governance and training
The prevalence of Shadow AI is a symptom of a larger failure in organizational readiness. The data shows that corporate policy is moving at a glacial pace compared to individual adoption. Only 45% of organizations have established dedicated teams or roles to manage artificial intelligence. A further 22% are considering creating such roles, while 28% have no plans to do so at all.
This lack of leadership is mirrored in the training deficit. Only 44% of employees have received specific AI training from their employers. This creates a dangerous environment where the majority of the workforce is experimenting with powerful technology without a foundational understanding of its limitations, such as hallucinations or bias, and without knowing the legal boundaries of their specific industry.
The difference between individual behavior and corporate declaration explains the shadow AI phenomenon: workers incorporate generative assistants to accelerate tasks without waiting for their companies to catch up.
Reconciling Eurostat data with employee behavior
At first glance, there appears to be a contradiction in the numbers. While the Cegid study shows an 82% adoption rate among employees, Eurostat data for 2025 placed the proportion of Spanish companies using AI technologies at 20.1%. While this was an increase from 11.2% in 2024, it remains significantly lower than the rates seen in Germany and other European leaders.
This discrepancy is exactly where the risk lies. Eurostat measures declared corporate adoption—meaning tools officially purchased, deployed, and acknowledged by the company. The Cegid study measures actual human behavior. The gap between 20.1% (official) and 82% (actual) is the 'Shadow Zone'. It is the space where employees are operating outside the perimeter of corporate security and oversight.
The regulatory pressure mounting on firms
The timing of this trend is particularly precarious. In the European Union, new rules regarding AI literacy and supervision have begun to take effect. These regulations add a legal layer to the existing training gaps. Companies are no longer just risking data leaks; they are potentially failing to meet regulatory obligations regarding how their staff is trained to use these systems.
For entrepreneurs and business owners, the lesson is clear: ignoring Shadow AI does not make it go away. It simply means the technology is being used without a safety net. The goal should not be to ban these tools—which is nearly impossible given the ubiquity of smartphones and personal laptops—but to bring them into the light through formal integration and clear policies.
Global implications for US and UK enterprises
While the specific data originates from the European market, the Shadow AI trend is a global phenomenon. For business leaders in the USA and UK, this signal is a warning about the fragility of traditional IT governance. In the US, where the regulatory environment is more fragmented and focused on sector-specific guidelines rather than a centralized act, the risk of intellectual property leakage is even more acute. US firms often rely on strict employment contracts to protect trade secrets, but these are difficult to enforce when the 'leak' is a series of prompts entered by an employee trying to be more productive.
In the UK, where the government has pursued a more 'pro-innovation' and flexible approach to AI regulation compared to the EU's AI Act, the pressure on companies to self-regulate is higher. The lack of a rigid framework means that the burden of security falls entirely on the company's internal policies. If 80% of the workforce is operating in the shadows, those policies are effectively nonexistent.
For global entrepreneurs, the strategy must shift from 'restriction' to 'enablement'. The demand for AI is organic and driven by the workers themselves. The most successful companies will be those that provide secure, enterprise-grade alternatives to public tools and invest in comprehensive literacy programs, turning a hidden security risk into a transparent competitive advantage.
FAQ
What exactly is Shadow AI?
Shadow AI refers to the use of artificial intelligence tools and applications by employees within an organization without the explicit knowledge, approval, or oversight of the IT department or company leadership.
Why is the gap between official adoption and employee use so high?
Employees often find official corporate procurement processes too slow. To maintain productivity and handle increasing workloads, they turn to free or personal versions of AI tools that they can deploy instantly.
What are the primary risks associated with Shadow AI?
The main risks include data breaches, the leakage of proprietary intellectual property into public AI training sets, lack of compliance with data protection laws, and the use of inaccurate AI-generated information without professional verification.
How can companies reduce the prevalence of Shadow AI?
Companies can reduce this risk by providing approved enterprise AI tools, creating clear and flexible usage policies, and offering formal training to employees so they understand how to use AI safely and effectively.
Sources: Computing, Laecuaciondigital, Elperiodico ·
Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.
Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.
oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email






