HIVEADVISORY GROUP
AI Risk & Governance
Briefing · September 2026

Shadow AI in the mid-market

Your AI footprint is bigger than your AI budget.

Most companies think they are deciding whether to adopt AI. They already did. They just did it without a decision, a policy, or a record of what went where.

Here is the gap. In MIT's 2025 study of enterprise AI, only 40 percent of companies said they had purchased an official LLM subscription. Workers at more than 90 percent of the companies surveyed reported regular use of personal AI tools for work.

A separate survey of 1,500 security leaders and employees by UpGuard found that more than 80 percent of workers use unapproved AI tools, and that 70 percent of respondents were aware of colleagues putting sensitive company data into them.

Read those two numbers next to each other. Your AI budget describes what you approved. Your AI footprint describes what is actually happening. For most mid-market companies the second number is several times the first, and nobody owns it.

Exhibit 1

The budget describes 40 percent. The footprint covers 90.

Share of surveyed enterprises, MIT NANDA GenAI Divide (2025). The two measures come from the same sample and answer two different questions.

What was approved and paid for What is actually happening
Bought an official LLM subscriptioncompany-approved spend
40%
Workers using personal AI tools for workreported at these same companies
90%+
0255075100%
50+ pts
The distance between the two bars is the AI footprint: real usage that no budget line, no contract and no owner accounts for.

Source: MIT NANDA, The GenAI Divide: State of AI in Business 2025. Sample drawn from conference attendees rather than a representative panel — treat the percentages as directional.

Why the usual response makes it worse

The first instinct is a policy memo. Something that says employees may not use unapproved AI tools with company data, circulated by email, acknowledged in a compliance system, filed.

That does almost nothing, and the UpGuard data shows why. Fewer than half of workers said they understood their company's AI policy. The people using unapproved tools most regularly were not junior staff cutting corners. They were executives.

A policy without an approved substitute does not stop the behavior. It moves it.

People who were using a tool openly start using it quietly, on personal accounts, on personal devices, where you have no logs at all. You have not reduced your exposure. You have reduced your visibility into it.

The work is not writing a rule. It is finding out what is already true.

Exhibit 2

The shadow layer, and the control that is supposed to cover it

UpGuard survey of 1,500 security leaders and employees. The first two bars measure exposure. The third measures whether the policy written to prevent it actually landed.

Exposure Policy comprehension Reported as an upper bound
Use unapproved AI toolsself-reported
80%+
Aware of sensitive data going incolleagues observed doing it
70%
Understand the AI policythe control meant to stop it
under 50%
0255075100%

The hatched tip marks a ceiling, not a measurement: the source reports "fewer than half," so the bar is drawn to 50 and the last segment is shown as indeterminate.
Source: UpGuard, 2024 survey of 1,500 security leaders and employees across the US, UK, Canada, Australia, New Zealand, Singapore and India.

The two-week version

You do not need a consulting engagement to start this. You need about two weeks and someone senior enough to ask uncomfortable questions.

Exhibit 3

A two-week inventory, from discovery to decision

Week one is ordered by how much each source tells you per hour spent. Week two deliberately stops at three buckets — five turns it into a project.

WEEK ONEFind it
  1. 01
    Expense reports and cards
    Twelve months of vendor names, then anything under $25 a month nobody recognizes. That price point is where most of this lives.
  2. 02
    Identity and SSO logs Highest yield
    Third-party OAuth grants in Workspace or Entra show which apps were given access to company accounts, and what scopes.
  3. 03
    Browser extensions
    The quietest exposure. An extension that summarizes a page has read the page — including the client file open in the next tab.
  4. 04
    Your existing vendors
    CRM, document platform, help desk. Eighteen months of release notes: where did a vendor start processing your data through a model?
  5. 05
    The people doing the work
    One anonymous survey with explicit amnesty. Mapping, not auditing — the useful answers are about why people reached for the tool.
WEEK TWOSort it
Approved and fine
Tools you bought, used the way you expected. Confirm the contract terms still say what you think they say, and move on.
No action
Useful and unsanctioned
Somebody found a tool, it works, no serious data exposure. Most companies handle this bucket badly by banning it.
Usually the largest bucket
Actual exposure
Client, personal or regulated data in a service with no agreement covering it. Name the tool, name the data, then contract or replace.
Short list · the only bucket that needs a decision this quarter

Ranking in week one is ordinal, as stated in the source method — no yield figures are implied. Bucket sizing is qualitative.

What lands in that third bucket depends on what business you are in, and the threshold is lower than most leaders assume.

Exhibit 4

The third bucket, by sector

None of these require a breach to become a problem. They require someone to ask the question during a renewal, an audit or a diligence process — and for you to have no answer.

SectorThe triggering actWhat it becomes
LawA document summarized in a free toolA privilege question before it is a security question
AccountingClient financial data in an unapproved serviceAn independence and confidentiality issue your peer reviewer will eventually raise
HealthcareProtected health information sent to a vendorA disclosure with no business associate agreement behind it
Financial servicesCustomer information leaving a controlled environmentA transfer with no record of where it went

What you do with the answer

Close the third bucket. Specifically, not generally. Name the tool, name the data, and either get an agreement in place or provide a replacement that does the same job. "Stop using it" only works if the sentence continues with "use this instead."

Then approve something. The fastest way to shrink shadow usage is to make the sanctioned path easier than the unsanctioned one. Pick a tool, pay for it, publish in one page what people may and may not put into it, and make sure the answer is not "nothing useful."

The part almost everyone misses

Most leaders treat this as a security exercise. It is, but that is the smaller half.

The tools your people found on their own are a map of where the friction is in your business. Nobody expenses a transcription tool because it is fun. They expense it because something in their week is slow and manual, and they got tired of waiting for it to be fixed.

Every unsanctioned tool in your inventory is an employee telling you, with their own money, where your process is broken.

That is unusually good internal research, and most companies throw it away because they walked into the exercise looking for violations.

Run the inventory. Fix the three or four things that are genuinely exposed. Then read the rest of the list again, and this time read it as a roadmap instead of a risk register. The second reading is worth more than the first.

Sources. MIT NANDA, The GenAI Divide: State of AI in Business 2025 — 52 structured interviews, 153 survey responses collected at industry conferences, and a review of 300 publicly disclosed AI initiatives, January to June 2025. Sample was drawn from conference attendees rather than a representative panel, so treat the percentages as directional.

UpGuard, 2024 survey of 1,500 security leaders and employees across the United States, United Kingdom, Canada, Australia, New Zealand, Singapore and India.

Engagement

The four-week AI Risk and Governance Review

Hive Advisory Group runs the inventory described here, reconciles it against your existing vendor contracts, and produces a board-ready governance roadmap. Fixed fee.

Request a Briefing
© 2026 Hive Advisory Group. All rights reserved.
Insights About Contact