May 16, 2026 · Joos Luteijn · 8-minute read
Many employers ban ChatGPT, Copilot, or Claude, or set up proxies around them. The arguments are valid: privacy, security, and the EU AI Act. No one wants customer data or source code to end up in a free chatbot with big tech in the USA. The concerns are justified.
And yet, it doesn't work.
After all, a ban does not stop the use. It only makes it invisible. A global study by KPMG and the University of Melbourne among 48,000 employees in 47 countries shows that 571,33T of employees hide their AI use at work and present AI-generated work as their own. It is a combined figure: hiding and claiming it as one's own work go hand in hand. For the shadow AI issue, hiding is particularly relevant. We call this hidden use shadow AI.
My proposition: an AI ban says more about the organization than about the employee.
That shadow AI percentage says nothing in itself. High is no cause for alarm, low is no reassurance. It is about the combination, the dynamic between the employer's policy and the employee's behavior.
Just think about it: if the organization facilitates safe and usable AI, and employees are aware of that offering, the logical reason to switch to personal subscriptions disappears. The percentage drops. Not due to bans, but simply because the alternative is better.
At the same time, it holds true that if employees do not feel a need for AI in their work, no shadow usage will occur. Not because of control, but because of a lack of motivation.
A low percentage can therefore go two ways. It could be because the organization has arranged things properly, or because the workforce is asleep at the wheel.
If you plot policy and behavior against each other, four recognizable situations emerge. I call this the Shadow AI Matrix.
On the horizontal axis: employer's AI policy (absent or restrictive versus present and appropriate). On the vertical axis: shadow AI usage by employees (low versus high). Four quadrants.
No shadow AI in sight. But also no internal adoption, no experience, no learning effect. No one is taking the first step, no one feels the urgency. It looks like calm, but it is a delay. Someday…
Nothing is coming from the top, so people are managing it themselves. Their own accounts, their own prompts, their own risks. The energy is there. The direction isn't. Extremely dangerous. Exciting for IT, uncomfortable for compliance. Customer data ends up in public models, knowledge remains with individuals, and AI literacy (Article 4 EU AI Act) is not demonstrably guaranteed. It is also a signal that there is energy on the shop floor; the only question is whether management is ahead of that energy or is definitely lagging behind.
Perhaps the most painful situation. The licenses have been purchased, the policy has been written, and there is a central AI environment. And yet, employees keep resorting to private subscriptions. The official offering does not align with reality. People choose the workaround; adoption fails. Not a failure of governance, but a gap between what has been rolled out and what is needed on the shop floor. Often, a proper dialogue between employees and policymakers is lacking; the policy is perceived as a brake, not a support.
Here, the shadow AI percentage drops naturally. Not because employees stop using AI, but because they do so through official channels. Policy and usage evolve together. The workplace and governance meet in a feedback loop. Privacy, security, GDPR, and the EU AI Act are embedded within the workflow. Adoption and governance scale up together. Valhalla.
At the same time, it holds true that if employees do not feel a need for AI in their work, no shadow usage will occur. Not because of control, but because of a lack of motivation.
A low Shadow AI percentage can therefore go two ways. It could be because the organization has arranged things properly, or because the workforce is asleep.
The Shadow AI Matrix shows two things at the same time.
The top row (Uncontrolled Growth and Mismatch) shows immediate risk. High levels of shadow AI mean that customer data, source code, and strategic information end up somewhere you have no visibility into. Compliance, security, and privacy are under pressure.
The right column (Mismatch and Balance) shows growth potential. Policy and infrastructure are the foundation upon which AI can scale, gain experience, and develop.
Mismatch has both: risk and building blocks for growth. It can be improved if the organization dares to bridge the gap between policy and practice. Balance has only growth, no risk; that is what you want to achieve.
And then there is Stagnation.
A low shadow AI percentage might seem reassuring. But Stagnation is actually the highest risk quadrant.
No policy, no experience, no learning effect. Competitors are building a lead that will be difficult to catch up with later. Talent wanting to work with AI is seeking an environment elsewhere. And when external pressure arises—legislation, customers, the market—the organization will be left without building blocks.
Anyone who reads the shadow AI figure without taking those two axes into account is reading it incorrectly.
When I mention AI policy, it is not just about which tools you facilitate or which proxies you set up. It is also about what you do with the people who work with those tools.
Since February 2025, the EU AI Act requires demonstrable AI literacy (Article 4). Employees must understand what AI does and does not do, what dangers are associated with it, and how to deal with it. This is not tool training. It is the ability to critically assess what AI delivers, what you can entrust to AI, and when AI is deceiving you.
The most significant effect lies at the heart of the shadow AI issue. An employee who is unaware that a free chatbot might reuse their input for training, or that outputs without verification lead to reputational damage, does not see why they are prohibited from uploading customer data or source code. A formal prohibition then remains a rule lacking understanding, and rules lacking understanding are ignored in the shadows. An employee who <em>does</em> understand the dangers is more likely to choose the responsible route themselves, even without IT monitoring.
AI literacy is therefore the silent foundation beneath the Shadow AI Matrix. It makes the difference between policy that looks good on paper and policy that works in the workplace. An organization that wants to direct rather than prohibit cannot do without it.
In our work, we see this relationship in every organization we look inside. And the picture only becomes complete when we measure it from two sides.
On the one hand, there is the Team Scan. It examines what employees actually do with AI. Which tools, in which contexts (private, work, both), how often, and what impact they experience. What are their training needs? Which prerequisites are they lacking? And yes, how significant is shadow usage? The Team Scan maps the workplace along nine dimensions, based on validated scientific models for technology acceptance.
On the other hand, there is the Maturity Scan. It does not look at what employees do, but at where the organization stands as a whole. Is there an AI strategy? Is governance in place? Is there an AI literacy program running that aligns with Article 4 of the EU AI Act? Is the data infrastructure in order? Are roles and responsibilities clear?
Together, these two tell the story behind the Shadow AI score. The Team Scan shows the willingness of employees and where the need for AI actually clashes. The Maturity Scan shows how well the organization accommodates that willingness. The difference between the two determines which quadrant of the Shadow AI Matrix you fall into.
An organization might score well on governance on the Maturity Scan, while simultaneously seeing on the Team Scan that a third of its consultants use their own tools. This is not a failure of governance, but a mismatch signal: the governance does not align with the actual work. Another organization might see on the Team Scan that employees are eager to get started, while the Maturity Scan reveals that there is no framework yet. This is not a problem of the shop floor, but a difference in pace between practice and management.
It doesn't work. It shifts usage to personal accounts and thereby out of sight. The figure drops to zero in your proxy logs, but the reality remains.
Passive acceptance. It offers peace of mind compared to prohibition, but solves nothing. The risks remain, but the building blocks are missing.
Offering a central, secure AI environment that actually improves work. The best alternative to private tools is a better internal offering. This is the direction many organizations are now moving in.
Taking it a step further. Not just enabling, but actively shaping. Policy that keeps pace with the workplace. A feedback loop between IT, policy, and employees. AI literacy as part of the policy, so that employees recognize the dangers of working with sensitive customer information themselves and identify the responsible course of action. Adoption and governance scale up together.
My plea: go for directing. Not because it sounds fashionable. But because the other three options assume control over AI usage. Directing is about giving direction to what is already happening. It acknowledges that employees will always win, and converts that energy into something that moves the organization forward.
Gillespie, N., Lockey, S., Ward, T., Macdade, A., & Hassed, G. (2025). Trust, attitudes and use of artificial intelligence: A global study 2025. University of Melbourne and KPMG. Global study of 48,000 employees in 47 countries. The figure refers to the combined measurement that 571,33T of employees hide their AI use and present AI-generated work as their own.
Joos Luteijn has worked in strategy, technology, and organizational development for over 20 years, with teams of up to 45 professionals. Through Transforming the Dots, he helps organizations get a grip on AI adoption via research, advice, and coaching. He is a guest expert on the Studio Beeckestijn podcast about AI adoption.