Gartner says 40% of enterprises will experience ‘shadow AI’ breaches by 2030 — educating staff is the key to avoiding disaster
Staff need to be educated on the risks of shadow AI to prevent costly breaches
Nearly half of enterprises could face serious security or compliance-related incidents as a result of Shadow AI by 2030, prompting calls for more robust governance practices.
Analysis from Gartner shows 40% of businesses could fall foul of unauthorized AI usage as employees continue to use tools not monitored or cleared by security teams.
The findings from Gartner come in the wake of a survey of cybersecurity leaders which underlined growing concerns about the rise of shadow AI. More than two-thirds (69%) of respondents said their organization either suspects – or has evidence to prove – that employees are using prohibited tools.
These tools, the consultancy said, can increase the risk of IP loss and data exposure, as well as causing other security and compliance issues.
Gartner said the trend will require a concerted effort to educate staff on the use of these tools, clearer guidelines, and more detailed monitoring.
“To address these risks, CIOs should define clear enterprise-wide policies for AI tool usage, conduct regular audits for shadow AI activity and incorporate GenAI risk evaluation into their SaaS assessment processes,” said Arun Chandrasekaran, distinguished VP analyst at Gartner.
How to tackle shadow AI
The Gartner report is the latest in a string of industry studies warning about the use of unauthorized AI solutions.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
A recent Microsoft study, for example, found nearly three-quarters (71%) of UK-based workers admitted to using shadow AI tools rather than those offered by their employer.
Notably, the report found that 22% of workers had used unauthorized tools for risky finance-related tasks, placing their employer at huge risk.
Guidance from the British Computer Society (BCS) on shadow AI aligns closely with the advice from Gartner. The organisation said organisations should adopt a comprehensive approach to tackling the problem which combines policy development, employee education, and technological oversight.
Policies should cover all aspects of AI use, from data input to output, and be flexible enough to respond to advancements in AI technology and regulatory changes.
Similarly, reviews should be carried out regularly while blacklists of websites and tools that organizations don't want their employees to use can help, along with continuous monitoring.
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
AMD talks up sustainability efforts with rack-scale energy efficiency gainsNews The company says it can help deliver more AI performance without increasing power, improve cost of ownership, and help customers scale faster
-
Vantage and Nebius move first in South Wales AI Growth Zone deploymentNews Nebius is to lease high-density, NVIDIA-powered capacity at Vantage's CWL1 campus for AI workloads
-
“Enterprises are becoming much more rigorous about the economics of AI”: Snowflake wants to help you cut AI costs by choosing the right model for the right taskNews New dynamic model routing capabilities aim to help customers box clever when it comes to their AI model choice
-
Can AI fight AI? Where the security gap still exists in cybersecurity, and how MSPs can help.Industry Insights Why AI security is failing and how MSPs can close the gap
-
Microsoft has joined the growing list of companies cracking down on ‘tokenmaxxing’News The company is updating internal guidance to reduce rising costs
-
After OpenAI-Hugging Face, how do IT leaders need to change the way they think about AI?In depth The OpenAI-Hugging Face incident and Anthropic admission soon after have opened up new conversations about controls around AI. How should IT leaders change their thinking about the technology?
-
Taking the myths out of Mythos - the role for the channel around AI and securityIndustry Insights Agentic security and vulnerability management must be a proactive priority rather than a reactive response to a problem already there
-
The OpenAI and Anthropic containment breaches are a bit spooky, but also quite sillyOpinion An AI leaving notes to future versions of itself is pure sci-fi; forgetting to lock down an environment is prosaic
-
‘AI cost management has the same problems that cloud had’: Enterprises are still facing huge AI bills thanks to ‘tokenmaxxing’ – that means FinOps practices are more important than everNews With firms facing surging AI bills, FinOps techniques are more important than ever
-
‘We are now seeing MAI models outperform general-purpose frontier models’: Microsoft CEO Satya Nadella touts in-house models to cut spiralling AI costs – and reduce growing reliance on frontier labsNews The Microsoft chief says pricey frontier models don't have to be used for every task, and its own in-house MAI models could be the key to reducing costs.