Most leaders who feel behind on AI picture the risk as a knowledge problem: I do not know the tools, so I am exposed. A new survey suggests the real exposure runs the other direction. Your people already know the tools. They are using them right now, at work, on company data, and most companies cannot see any of it.
On July 14, 2026, the security vendor WatchGuard released its 2026 Cybersecurity Hygiene Report. The headline number: 64% of employees admit to using unauthorized AI tools for work. WatchGuard calls this "shadow AI." In practical terms, it means AI tools employees reach for on their own that the company never sanctioned or provisioned.
Read that again as an owner. Almost two in three of your people are pasting work into AI tools nobody approved, and by the same report, fewer than a third of them think their company even keeps an accurate list of the software in use.
More than falling behind, this is a story about who is steering.
What the survey actually found
The numbers below come from a WatchGuard survey of 684 employees across eight countries (the U.S., U.K., Germany, France, Spain, Australia, Mexico, and Brazil), at organizations sized 50 to 500 employees. Fieldwork ran in April 2026. Keep in mind these are self-reported employee answers, and WatchGuard is a security vendor with a commercial interest in the finding. Treat the figures as directional signals from people describing their own habits, not measured behavior.
of employees admit to using unauthorized AI tools for work, in a WatchGuard survey of employees at companies sized 50 to 500.
Source: WatchGuard, 2026With that caveat, here is the pattern WatchGuard reported:
- 64% admit to using unauthorized AI tools for work.
- 76% reuse the same passwords across multiple accounts.
- 30% share their passwords with other people.
- 70% use public Wi-Fi for work.
- 50% access company resources without VPN protection.
- 55% use work devices for personal activities.
And the visibility side, which is the part leaders own:
- Fewer than 30% believe their organization keeps an accurate inventory of the software actually in use.
- Nearly 40% say their company is operating without full visibility into the apps its employees use.
Shadow AI is not sitting off in a corner. It rides alongside password reuse, unprotected connections, and personal use of work machines. Marc Laliberte, WatchGuard's Director of Security Operations, put the through-line plainly: "Organizations are investing in security tools, but many still lack visibility into how employees actually work."
Why smart people go around the rules
It helps to understand why this happens before deciding what to do about it.
An employee who pastes a customer email into a consumer AI tool is usually not trying to cause a problem. They are trying to finish faster. The tool works. It is on their phone. Nobody gave them an approved way to do the same thing, so they used the way that was in front of them.
That is the quiet mechanism behind a 64% number. When the sanctioned path does not exist, people build their own. Every time they do, a little more company information moves through a tool the company has no relationship with, no data agreement with, and no record of.
The behavior is a signal, not a betrayal. Your team wants to use AI. That is the raw material of an AI-capable company. The task in front of you is to give that energy a channel instead of pretending it is not there.
This is a leadership decision, not an IT ticket
It would be easy to read this survey and hand it to whoever runs your tech. Do not stop there. The three things that reduce this risk are decisions a business leader owns.
Write a plain AI acceptable-use policy. Not a legal document. One page in language your team actually speaks. What tools are approved. What kinds of information can go into them and what cannot (customer records, financials, anything covered by a client agreement). Who to ask when someone wants to try something new. The point is to replace a hidden path with a sanctioned one. People follow clear rules far more often than they follow no rules.
Get an honest inventory of what your people actually use. You cannot govern what you cannot see, and by this survey most companies cannot see it. Start simple. Ask your team directly, without penalty, what AI tools they use and what they use them for. You will learn more in an afternoon of honest conversation than in a month of assuming nothing is happening.
Decide, openly, that AI adoption is something you lead. Silence is itself a decision, and right now it is the one most companies are making by default. When a leader names AI as something the company will use on purpose, with guardrails, the shadow version loses its reason to exist.
Laliberte framed the same opportunity for the service providers who sell to these companies: "For MSPs, this is an opportunity to expand beyond technology into user risk visibility." The lesson for a leader is the same. The value is seeing clearly how your people work, then guiding it.
Where this sits on the climb
At LaunchReady we measure how ready a person or a team is to use AI well with a model called The 7 Levels of AI Proficiency. It runs from a beginner who is just becoming aware of what these tools can do, up to a leader who can direct AI across a whole organization with sound judgment.
Shadow AI is what the early part of that climb looks like when nobody is guiding it. Your people are experimenting on their own, learning by doing, and picking up habits with no one setting the guardrails. That energy is a good sign. Left unmanaged, it also produces the exact behaviors this survey measured.
A company further along the 7 Levels of AI Proficiency does not have less AI use. It has more, out in the open, on approved tools, with people who understand both what the tools can do and where the real risks live. The difference is whether someone is leading the climb.
Related reading: Level 1: The Cadet.
Sources
- Employees Drive Rising Cybersecurity Risk As Shadow AI and Unsafe Work Habits Surge, WatchGuard Global Survey Finds (GlobeNewswire)
- WatchGuard report highlights employee behavior risks for SMBs (SC Media / SC World)
- WatchGuard Research: Shadow AI and Cybersecurity (Channel Insider)
Frequently Asked Questions
What is shadow AI?
The working meaning is employees using AI tools the company never approved or provided, often consumer apps on personal accounts, applied to work. WatchGuard did not publish a formal definition in this release, so treat that as the practical sense of the term rather than an official one.
Is a 64% number believable?
It is self-reported by employees in an online survey run by a security vendor, across companies of 50 to 500 people. That means it is a useful directional signal, not a precise measurement. Even if the true figure in your company is lower, the safe assumption for any leader is that some of your people are already doing this and you cannot currently see it.
What is the single first step?
Write the one-page AI acceptable-use policy and share it with your team this month. It gives people a sanctioned path, which is the fastest way to pull activity out of the shadows.
Find your AI Proficiency level
The free 7 Levels assessment places you across seven stages of AI capability. Under ten minutes. Research-backed scoring.