IA
7 min read

Shadow AI in 2026: 64% of your employees are already using AI the company hasn't approved

Jorge García

Tecnea

Shadow AI in 2026: 64% of your employees are already using AI the company hasn't approved

64% of employees at small and medium-sized businesses admit to using AI tools their company hasn't authorized. That's not an estimate: it's what they report themselves, anonymously, in the industry's latest major digital hygiene survey. It comes with an even more uncomfortable figure attached: fewer than 30% of those companies believe they have an accurate inventory of the software running inside their own organization.

We previously covered how a significant share of real AI use in Spanish SMEs happens without the company knowing — the phenomenon known as shadow AI or BYOAI ("bring your own AI"). This new study doesn't change that conclusion: it confirms it with a different sample, a different methodology, and places it inside a broader digital control problem that many companies haven't started to address yet.

What the report says, and who's behind it

WatchGuard Technologies' 2026 Cybersecurity Hygiene Report, published July 14, 2026, surveyed 684 employees at companies with 50 to 500 employees across eight countries — the US, UK, Germany, France, Spain, Australia, Mexico and Brazil — all within the size range where much of Spain's business fabric sits. The study doesn't offer a country-by-country breakdown, so the 64% figure is the combined average across all eight markets, not a Spain-exclusive number — worth keeping in mind before citing it as such.

Objectivity note: WatchGuard is a cybersecurity company that sells, among other things, tools to detect exactly this kind of unauthorized application and AI use on a company's network. It has a direct commercial interest in this problem being perceived as serious. That doesn't invalidate the figure — the methodology (independent survey, 684-person sample) is public and reasonable — but it's the kind of detail we prefer to make explicit, as we do with every study we cite on this blog.

What sets this report apart from others we've cited isn't just the AI figure, but the context it appears in. This isn't an AI-focused study: it's a general digital hygiene study, and unauthorized AI use shows up as one more piece of a broader behavioral problem:

  • 76% of employees reuse passwords across accounts; 30% share them outright.
  • 70% work while connected to public wifi networks; 50% access corporate resources without a VPN.
  • 55% use work devices for personal activities.
  • Fewer than 30% of companies believe they have an accurate inventory of the software in use; nearly 40% admit they lack full visibility into which applications their employees use.

Person working on a personal laptop in a coworking space, connected via public wifi Much of unauthorized AI use happens outside IT's view: on public networks, on personal devices, leaving no record at all.

As Marc Laliberte, WatchGuard's Director of Security Operations, puts it: "managing human behavior is becoming a core cybersecurity requirement." AI isn't the exception to that pattern — it's the latest example of it.

The distinction that actually matters: not "do they use AI", but "who controls it"

This is where it helps to separate two questions that easily get conflated: is your company using AI? and does your company know how it's being used? We already answered the first question in July, with contradictory adoption figures. The second is what actually determines whether that AI adds value or just adds risk — and here there's a recent figure that draws a fairly clear line between who's getting it right and who isn't.

A study by Fundación Cotec together with research center ISEAK, published in October 2025 using official INE data, finds that companies using at least one AI technology report 27% higher productivity than those that don't. That's not a minor figure. But the same study explains why most companies haven't reached that point yet: nearly eight in ten companies that don't use AI cite a lack of internal knowledge as their main barrier — not cost, not a lack of use cases, but simply not knowing where to start or by what criteria.

That combination — real benefit for those who do it well, a knowledge barrier for those who don't know how to start — is exactly the gap where shadow AI appears. An employee who sees the benefit (faster, better results) but has no official path or company guidance to get there doesn't wait. They solve it on their own, with whatever tool is at hand, with whatever data is in front of them. The same Cotec study confirms the other side of the underlying problem we flagged in July: there's a 44.9-point adoption gap between large companies (58.2%) and microenterprises (13.4%) — and it's precisely in the smallest companies, without an in-house IT team, where that guidance gap is hardest to close.

What this means for a Spanish SME, specifically

Put these two studies together and the message for any mid-sized Spanish company is fairly direct: if it hasn't actively decided how AI is used inside the organization, it's probably already being used anyway — without anyone knowing with what data, or with what guarantees.

That's not just an efficiency problem. It carries concrete regulatory implications:

  • GDPR requires knowing what processing personal data of customers and employees undergoes. If that data enters a public AI tool without the company's knowledge, that control no longer exists.
  • The EU AI Act, in full application since August 2nd, expands transparency and documentation obligations around the AI systems a company uses — something materially impossible to comply with if, as WatchGuard's own report states, fewer than 30% of companies know what software is actually running in their organization.
  • AI literacy training for staff who use it has been mandatory since February 2025. Training a team on a tool the company doesn't know is being used is, in practice, impossible.

What to do about it

Solving this doesn't require slowing down AI adoption — in fact, according to Cotec's own figure, slowing it down has a real productivity cost. What it requires is treating it less like a spontaneous phenomenon and more like any other work tool:

  1. Ask, without hunting for blame, what's already in use. It's the only way to start from reality instead of what the company assumes is happening.
  2. Decide what data can leave the company toward a public AI tool, and what should never leave it: customer data, case files, employee data.
  3. Offer an official path that's better than the unofficial one. If the company's alternative is worse than what an employee already uses on their own, they'll keep choosing the latter — it's the most repeated conclusion in this kind of study, and the most ignored.
  4. For what actually matters to the business, build on your own data. A custom application, with data in a controlled environment, solves both the productivity problem (the 27% improvement already on the table) and the compliance one, instead of leaving each employee to decide on their own which tool to use and with what data.

Team reviewing an AI usage policy together next to a laptop Managing AI use like any other work tool doesn't slow productivity down — it puts it in order.

Frequently asked questions

What is "shadow AI"? It's the use of artificial intelligence tools (like ChatGPT, Claude or others) by a company's employees without the company having authorized, supervised, or having any visibility into it — a specific case of the broader "shadow IT" phenomenon.

Is it legal for an employee to use AI on their own at work? Using AI isn't illegal in itself, but it can breach GDPR if that data includes personal information about customers or employees that leaves the company's control without legal basis or safeguards. Responsibility for the processing remains with the company, whether it's aware of it or not.

How do I know if my company has a shadow AI problem? According to WatchGuard's report, fewer than 30% of companies believe they have an accurate software inventory — the realistic first step isn't assuming there's no unauthorized use, but asking the team directly what they use and for what, without framing it as a disciplinary matter.

Is banning consumer AI tools at work enough? The studies cited here and in our previous article agree it isn't: if the company's official alternative is worse than what the employee already uses, a ban simply pushes the use underground without solving the underlying problem.

This is exactly the kind of order we help put in place at Tecnea: knowing which AI tools are actually in use, deciding what data can leave the company, and building on that a private AI that complies with the law, instead of leaving it up to each employee. If you want to see how it would fit your case, find out how we guarantee it.

This article is informational and does not constitute legal advice. We have tried to indicate the source of each figure, the sample size where known, and whether whoever published it has a commercial interest in the outcome.

Sources

  1. WatchGuard Technologies — 2026 Cybersecurity Hygiene Report (Jul 14, 2026)
  2. Fundación Cotec + ISEAK — AI Use in Companies, based on INE data (Oct 22, 2025)
  3. Related Tecnea article: Does Spain really lead AI adoption among SMEs?

¿Te ha resultado útil este artículo?

Publicamos análisis sobre IA y tecnología empresarial. Sin spam — solo cuando escribamos algo que valga la pena leer.

Ready to transform your business?

Let's talk about how we can help you implement these solutions in your company.

Contact us

Related articles