Chances are that your teams are already using AI tools you have not approved. So are your executives.
According to UpGuard's 2025 report, more than 80% of employees now use unapproved AI tools at work. That number alone is striking. But here is what should really get your attention: a Cybernews survey found that 93% of senior managers and executives admitted to using unapproved AI tools on the job.
A 2025 Nitro study found that 68% of C-suite leaders bypass the very tools their companies have invested millions in. They are sending the same message as everyone else in the organization: the approved path is too slow.
The truth is that shadow IT has always existed. Departments buying their own SaaS subscriptions, teams spinning up tools without telling IT; that has been going on for years. But AI has accelerated it massively.
What used to be a slow drift of unapproved apps has become an organization-wide shift, happening in real time, across every function.
The question is not whether shadow IT exists in your company. It does. The question is what you do about it.
And to answer that, it helps to understand why people go around IT in the first place.
Why people go around IT in the first place
It is rarely about defiance. A Gartner survey found that 69% of employees have intentionally bypassed cybersecurity guidance, specifically when those rules slowed them down. In the same research, 74% said they would do it again if it helped their team achieve a business objective.
This is not reckless behavior. It is a rational response to a real gap.
Consider the capacity problem: only 12% of IT departments can keep pace with incoming technology requests. That means for 88% of organizations, there is a growing backlog between what teams need and what IT can deliver. When a business unit needs a workflow tool this week and the IT queue says "three months," they find another way.
And the tools people are given are not always helping. 61% of employees say their company-provided technologies are buggy, unreliable, or poorly integrated. A January 2026 BlackFog study found that 63% of employees believe it is acceptable to use AI tools without IT oversight if no approved alternative exists.
People are not going rogue. They are filling a gap that the organization has not filled yet.
But here is where it gets expensive.
Also read: Reduce IT Backlogs with Citizen Development
The real cost of shadow AI
The danger is not that people are using AI. The danger is that nobody knows where the data is going.
75% of employees using shadow AI tools admit to sharing sensitive information such as customer data, employee records, and internal documents with those tools. And most of the time, IT has zero visibility into it.
IBM's 2025 Cost of a Data Breach Report puts hard numbers on this:
- 1 in 5 organizations experienced a breach directly linked to shadow AI.
- Those breaches cost $670,000 more than the average breach.
- Customer PII was compromised in 65% of shadow AI incidents, compared to 53% globally.
- 97% of organizations that suffered an AI-related breach lacked proper access controls.
- 63% had no AI governance policy at all.
The data volume is growing too.
Netskope reports that the average organization now uploads 8.2 GB of data monthly to AI apps, up from 5 GB just a few months earlier.
Why blocking AI tools does not work
The CTO's instinct, understandably, is to lock things down. Block the tools. Tighten the policies. Restrict access.
But blocking does not work. It just makes the problem invisible.
70% of employees using ChatGPT at work already hide it from their employers. Gartner has been direct on this: banning AI outright leads to employees concealing their usage from IT entirely. The tool use does not disappear. Your ability to see it does.
Forrester analyst Michele Goetz puts it simply: the Pandora's box has been opened, and it is better to partner with your employees than to force them into hiding.
There is even a paradox at play. UpGuard found that the more employees learn about AI risks, the more confident they become in making their own judgment calls, even at the expense of company policy. Security training increases awareness, but it also increases the belief that "I can handle this myself."
I have seen enterprises spend months building an AI usage policy only to discover that most of the organization had already moved on.
Also read: Can Low-Code CRM Clean Up Your IT Mess?
The smarter choice: make the approved path faster
Instead of asking "how do we stop people from using unapproved tools?", ask "how do we make the approved path so fast and useful that nobody needs to go around it?"
Gartner's recommendation to CIOs is clear: define enterprise-wide policies for AI usage, but back them with tools that match what employees actually need. The Nitro study's conclusion was similar: IT leaders should focus on guardrails rather than roadblocks.
What this looks like in practice is a governed environment where business teams can build what they need without stepping outside IT's visibility. IT sets the boundaries. Users move fast within them.
When this happens, AI governance becomes structural, not aspirational. And that is exactly what GenAI Low-Code No-Code Platforms make possible.
This is the problem we built Amoga to solve.
How Amoga marries speed and control
Amoga is a GenAI low-code no-code platform that lets business users describe a process in plain language and generates the complete application. Data model, UI pages, workflows, automations, user roles. What used to take months of development time takes hours.
But speed without governance is just shadow IT with a faster engine. So the critical piece is what IT gets:
- IAM, SSO, MFA: built in from day one.
- Durable execution: fault tolerance guaranteed.
- Full audit trails and compliance layers: not bolted on after launch.
- Complete visibility: what is being built, what data is being used, and how workflows operate.
- Deployment flexibility: cloud, private cloud, on-prem, or hybrid, so data stays where it needs to stay.
Enterprises across BFSI, healthcare, and manufacturing already run production workloads on Amoga. With 90% faster delivery and a Zero Tech Debt Architecture that evolves with the platform, there are no rewrite cycles, no migration headaches.
As a low-code no-code platform, Amoga gives employees the speed and flexibility they were looking for in unapproved tools, while giving IT the visibility and control it needs to stay in front of risk.
That is the practical role of GenAI Low-Code No-Code Platforms: they let teams move at AI speed without turning every new app into another blind spot.
That is not a compromise. That is how it should have worked from the start.
For more on the operating model, explore the Amoga platform, Amoga security, and Amoga compliance.
Make shadow IT irrelevant by design
You do not fix shadow IT by stopping people. You fix it by giving them a better way to move fast inside the system, not around it.
With Amoga, you have a system that makes shadow IT irrelevant by design.
Build enterprise applications at the speed of intent
See how Amoga helps teams ship governed enterprise software in days, not quarters.
Book a personalized demo