Senior decision-makers are more than twice as likely to use unapproved AI tools as the employees they manage: 65% versus 31%, according to original TrustedTech research conducted with Censuswide across 2,001 UK and US employees in March 2026. The governance risk most IT and security teams are watching for is running directly from the offices of the people setting the policy.
Shadow AI is typically framed as a frontline problem: junior employees sneaking ChatGPT past IT, digital natives routing around policy. That framing shapes how most organizations respond, with stricter controls, tighter enforcement, and policies aimed at the bottom of the org chart. As a top 1% global Microsoft Direct Cloud Solution Provider working with thousands of organizations on AI readiness, TrustedTech sees this dynamic regularly, and the real exposure almost never starts where IT teams are looking.
What Is Shadow AI?
Shadow AI is any AI tool an employer hasn’t approved, vetted, or integrated into its official technology environment: consumer ChatGPT accounts, free-tier AI writing tools, personal Gemini or Perplexity subscriptions, anything running outside the organization’s data governance controls and IT visibility. It is sometimes called BYOAI (Bring Your Own AI), a term that reflects how easily personal AI tools move from a home device into a work context. For a fuller breakdown of how Shadow AI and BYOAI differ and why both matter for your security posture, TrustedTech has covered the distinction in depth.

The TrustedTech/Censuswide survey, fielded March 19–24, 2026, asked 2,001 full- and part-time employees (split evenly across the UK and US) about their AI tool usage habits, confidence levels, training history, and attitudes toward AI policy. The sample was split evenly between the decision-maker level and levels above and below it. All figures in this article are from that survey unless otherwise noted.
The headline finding: 48% of employees across both markets use unapproved AI tools at work. But the seniority breakdown is what actually changes the governance picture.
Why Senior Leaders Are the Biggest Shadow AI Risk
Ask any IT security lead which employees worry them most about Shadow AI, and the answer is usually something like “the ones who grew up with it.” The assumption is that digital-native junior employees are the main source of unsanctioned AI behavior.
They are not.
Senior decision-makers are more than twice as likely to use unapproved AI tools as the employees they manage: 65% versus 31%. At the C-suite level, the figure reaches 73%. Among entry-level employees, it’s 36%. Shadow AI use rises almost perfectly with seniority across every level measured.
What makes this finding genuinely uncomfortable is the awareness sitting alongside it. These same senior leaders are also the group most likely to say they’re worried about Shadow AI in their organization; 56% of decision-makers express concern, compared to 31% of those below them. And 42% of decision-makers believe their employer monitors their AI tool usage, more than double the rate among junior staff (23%).
Senior leaders know Shadow AI is a governance problem. They believe they may be monitored. They do it anyway.
In TrustedTech’s experience working with organizations on AI governance, this pattern aligns with what we observe in practice. The executives most concerned about AI risk in their organization are often the same people generating it, not out of recklessness, but because the approved tools haven’t been set up to serve how they actually work.
The Real Reasons Executives Bypass Approved Tools
The reasons decision-makers give for using unapproved tools further complicate the story. Their top responses aren’t really about preference or convenience. They’re about control, visibility, and the fear of being watched.
The top five reasons decision-makers cited for using Shadow AI:
- Limitations in access to employer-approved AI tools (29%)
- Finding unapproved tools more efficient than sanctioned ones (28%)
- Worry that their organization will see how often they use AI, which could affect their career (24%)
- Concern that increased AI use could raise doubts about their abilities (23%)
- Concerns over being monitored by their manager (23%)
Reasons three and four deserve attention. A significant share of senior-level Shadow AI use isn’t driven by tool preference. It’s driven by reputational anxiety. For executives whose professional standing depends on projecting competence, knowing that every Copilot query is logged against their name creates a real disincentive to use sanctioned tools at all. Shadow AI gives them something the formal tooling currently doesn’t: an off-the-record productivity boost.
The organizational consequence is predictable and serious. When senior leaders avoid sanctioned tools out of surveillance anxiety, they push their most sensitive work through unvetted, consumer-grade AI: strategy conversations, draft board materials, M&A-adjacent research. The people holding the most valuable data end up operating in the least controlled environment. The real-world Shadow AI examples from Fortune 500 companies TrustedTech has documented show a consistent pattern: the most consequential data exposures involve senior employees, not junior ones, and happen through tools that IT never knew were in use.
How Shadow AI at the Top Shapes Culture Below
The seniority gap in Shadow AI use also creates a cultural dynamic that quietly undermines governance efforts, regardless of what the policy actually says.
When leaders bypass the rules they set, they send an implicit message to everyone watching: these rules are for other people. That message doesn’t need to be stated. It shows up in the data. Among decision-makers, 51% say AI use is celebrated and encouraged in their workplace. Among junior employees, only 25% say the same thing. Meanwhile, 24% of all employees report actively reducing their AI use at work because of how colleagues or management might perceive it.
Senior leaders are the heaviest users of Shadow AI and also the people whose behavior defines what’s “normal” for the rest of the workforce. The result is an organization where AI use is a legitimate productivity advantage at the top and a potentially career-risky behavior further down; a dynamic that pushes usage into the shadows at every level, for reasons unrelated to the policy wording.
This is the governance gap that no policy document alone can close. Until sanctioned tools feel as usable and as private as the consumer alternatives, and until AI usage is decoupled from performance judgment, organizations will keep losing the adoption battle to free tools their IT teams can’t see.

What CIOs and IT Leaders Should Do Instead
The governance instinct when Shadow AI surfaces tends toward enforcement: restrict access, tighten policy, issue warnings. The TrustedTech research suggests this will fail, not because employees can’t be deterred, but because the employees most likely to comply are not the ones creating the most risk.
When asked whether they would keep using AI tools even if their workplace banned them and they faced disciplinary action, 37% of decision-makers said yes, compared to just 19% of those below the decision-maker level. A ban aimed at junior employees would largely hold. A ban aimed at the C-suite largely wouldn’t.
A more effective response means addressing the actual drivers of Shadow AI at the leadership level. Based on both this research and TrustedTech’s direct work with organizations navigating AI governance, four actions have the most impact.
Make sanctioned tools genuinely competitive. Twenty-eight percent of decision-makers use Shadow AI because they find unapproved tools more efficient. If Microsoft Copilot and other M365 AI features are the approved path, they need to be properly configured, internally championed, and positioned as tools worth using, not deployed as IT projects and left to compete on their own against free consumer alternatives. Copilot’s value depends heavily on how it’s configured within your tenant, and whether it’s integrated into the workflows people actually use. An out-of-the-box deployment rarely wins on its own.
Decouple AI usage from performance surveillance. Nearly a quarter of Shadow AI users cite career anxiety as a motivating factor. Until organizations explicitly and credibly commit, in writing, to not using AI tool logs as performance signals, sanctioned platforms will carry a trust penalty that free consumer tools simply don’t have. This commitment needs to come from the same senior leaders who are currently bypassing the tools; it won’t be credible from IT alone.
Audit Shadow AI before banning it. Any enforcement action taken without a baseline of current Shadow AI usage will punish the wrong employees and miss the biggest offenders. Understanding the actual scale, through network traffic analysis, SaaS spend review, and direct conversations with senior leaders, is the prerequisite for any meaningful governance response. TrustedTech’s approach to Shadow AI governance covers the audit methodology and the Microsoft tools available to surface unsanctioned usage before it becomes a compliance event.
Microsoft’s M365 price increase for AI features creates a new pressure point. The TrustedTech research found that 47% of decision-makers would likely turn to personal, unapproved AI tools if their employer restricted access due to cost. Organizations that wait until renewal to decide who gets which AI features risk triggering the Shadow AI surge they’re trying to prevent. The Microsoft Copilot Readiness Assessment is built for this moment: mapping current AI usage, right-sizing licensing, and building a governance structure before the pricing change forces the conversation.
The Governance Problem Starts at the Top
The TrustedTech research doesn’t frame Shadow AI as a leadership failing in any simple moral sense. Executives use unapproved AI tools for the same reason everyone else does: the tools work, the productivity gains are real (54% of all AI users save three or more hours per week), and the sanctioned alternatives often aren’t good enough. The difference is the consequence. Senior leaders hold the most sensitive organizational data, set the cultural norms others follow, and are the least likely to comply with policies they disagree with.
That combination makes leadership the highest-risk Shadow AI cohort in most organizations, and the one most governance strategies are least equipped to address.
The question isn’t whether to manage Shadow AI. It’s whether to manage it now, while the risk is still recoverable, or after the next breach confirms what the data already shows.



