Case Study: Mapping Shadow AI Without Driving It Underground
A conglomerate's official AI adoption was 12%. The real number was closer to 60% — running through personal accounts. The amnesty that surfaced it changed the whole roadmap.

Every organisation has two AI adoption numbers: the official one, and the real one1. The distance between them is where your risk lives — and, less obviously, where your best working practices live too.1A composite case, anonymised and simplified from several Fellow engagements. Numbers are representative of the pattern, not one client's audited figures.
The situation
A Thai conglomerate's transformation office reported 12% AI adoption, based on licence activations. Their readiness answers told a different story: heavy weekly usage alongside almost no visibility into which tools were involved. When we ran structured conversations across three business units, actual usage — counting personal ChatGPT accounts, free-tier tools, and browser extensions — was closer to 60%◦.By the numbers12% → ~60%official adoption versus what a three-week mapping actually found
The 12% was not a bad measurement. It was a precise measurement of the wrong thing: seats on an enterprise licence bought eighteen months earlier, activated once during onboarding and, in many cases, never opened again. Two of the three units had fewer than a dozen weekly active users on the approved tool. All three had a clear majority of staff using something.
Nobody had lied. The official number counted what the organisation had bought; people were using what worked, on their own accounts, including for material work: contract summaries, customer correspondence, financial commentary.
That last category is what made the gap urgent rather than merely embarrassing. A finance manager was pasting draft quarterly commentary into a personal account to tighten the language. A relationship manager was summarising client email threads the same way. Neither had broken a rule they knew about — the group's data-handling policy predated generative AI and said nothing about it at all.
The gap is not unique to them
A 12-to-60 gap sounds like a governance failure specific to one company. It is closer to the global default.
- Microsoft's 2024 Work Trend Index found that 78% of AI users bring their own AI tools to work, and that 52% are reluctant to admit using AI for their most important tasks1◦.SourceMicrosoft, 2024 Work Trend IndexBy the numbers78%of AI users bring their own AI tools to work, in Microsoft's 2024 Work Trend Index — shadow use is the mainstream case, not the exception
- KPMG and the University of Melbourne surveyed more than 48,000 people across 47 countries in 2025 and found that 57% of employees hide their AI use or pass AI-generated work off as their own2, and that 48% had uploaded sensitive company information into public AI tools.SourceKPMG & University of Melbourne, "Trust, attitudes and use of AI", 2025
- Cyberhaven Labs' 2026 AI Adoption and Risk Report, which monitors actual enterprise data flows rather than asking people what they do, found that 39.7% of data movements into AI tools involve sensitive data and that 32.3% of workplace ChatGPT use runs through personal accounts3◦. The same report puts the average employee at entering sensitive data into an AI tool every three days.SourceCyberhaven Labs, 2026 AI Adoption & Risk ReportBy the numbers39.7%of data moving into AI tools is sensitive, in Cyberhaven Labs' 2026 measurement of real enterprise data flows
- ISACA's 2025 AI Pulse Poll found that 83% of professionals believe employees at their organisation are using AI, while only 31% of organisations have a formal, comprehensive AI policy4.SourceISACA, 2025 AI Pulse Poll
Read together, these say something specific: the belief is nearly universal, the measurement is nearly absent, and the exposure is already running.
Samsung learned what that costs in public5. In 2023 its engineers pasted internal source code into ChatGPT — three separate leaks in roughly twenty days — and in May 2023 the company banned generative-AI chatbots on internal devices, citing data now held on external servers where it could not be retrieved or deleted. The failure was not that engineers reached for a chatbot. It was that nobody had mapped that they would, so the organisation's first real measurement of usage arrived in the form of an incident report.SourceSamsung's gen-AI ban after a source-code leak, 2023 (via Forbes)
Gartner's 2025 survey of 302 cybersecurity leaders found that 69% either suspect or have evidence that employees are using prohibited public generative-AI tools, and Gartner expects more than 40% of organisations to experience a shadow-AI security or compliance incident by 20306. Its prescribed remedy is not tighter prohibition but regular shadow-AI audits2.SourceGartner on shadow AI, 2025 (via ITPro)2We confirmed the Gartner figures through attributed secondary coverage rather than the primary release, so treat them as directional rather than exact.
Why people hide usage
Shadow usage is not rebellion — it is a rational response to incentives◦. The approved tools were worse than the free ones. Asking for permission took weeks. And admitting AI use invited two fears at once: being told to stop, and quietly suggesting your job could be automated. Given those incentives, hiding is what a sensible person does.DefinitionShadow AI AI use running through personal accounts and unapproved tools, invisible to the organisation that carries its risk
The fear is measurable rather than anecdotal. Slack's Fall 2024 Workforce Index found that 48% of desk workers would be uncomfortable telling their manager they had used AI — most often because it feels like cheating, or invites the impression that they are less competent or simply lazy7. The same index found that workers who are comfortable disclosing are 67% more likely to use AI at all◦. Silence is not a harmless side effect of adoption. It suppresses adoption.SourceSlack (Salesforce), Fall 2024 Workforce IndexBy the numbers48%of desk workers would be uncomfortable telling their manager they used AI, in Slack's Fall 2024 Workforce Index — those who are comfortable are 67% more likely to use it
That framing matters, because the standard corporate response — a usage survey, a stern reminder of policy — reads as a threat and drives the practice deeper underground. You cannot audit your way to visibility here.
BCG's AI at Work studies supply the other half of the mechanism, and the 2026 edition makes it sharper than the 2025 one did. In 2025, across more than 10,600 employees in 11 countries, regular generative-AI use among frontline staff sat at 51% against more than 75% for leaders and managers8; by the 2026 edition, of 11,749 workers in 14 markets, the frontline had reached 74%9. More than half of employees say they will find their own tools if the organisation does not give them what they need — and now that roughly three in four are regular users, that sentence covers far more people than it did a year ago8. Prohibition does not remove the demand. It only removes your view of it.SourceBCG, "AI at Work 2025"SourceBCG, "AI at Work 2026: Strategy Matters More Than Tools", June 2026 (via BCG press release)SourceBCG, "AI at Work 2025"
The amnesty
We ran the mapping as a show-and-tell, with three explicit rules announced by the business-unit heads themselves: nothing disclosed would be punished; anything disclosed that worked would get proper tooling; and the goal was to find practices worth keeping, not people to correct.
The rules were the easy part. Getting the business-unit heads to say them out loud was not. Two of the three wanted the invitation to come from the transformation office, which would have been fatal — a note from a central function reads as data collection, and data collection reads as evidence gathering. What changed their minds was a rehearsal. We asked each of them to say the amnesty sentence in their own words in a room with four of their own managers, and watched the room change when a head said, "if you have been doing this, I want to see it, and nothing happens to you."
Legal and risk pushed back harder, and with a fair point: an amnesty that surfaced a genuine breach would leave the company knowingly holding an unreported incident. We settled it before the first session with a written carve-out — the amnesty covered the person, not the practice. Nobody would be disciplined for disclosing, and anything that turned out to be a reportable data exposure would still go through the normal incident process. Everyone was told this beforehand rather than afterwards, which is the only version that survives contact with reality. One disclosure did trigger the incident process. The person who raised it was thanked by name in the next session, and disclosure rates went up afterwards rather than down.
The effort was neither trivial nor enormous: three weeks of elapsed time, twenty-two group sessions of forty-five minutes each, roughly five person-weeks across the Fellow team and the internal programme lead, and about ninety minutes of each business-unit head's time in preparation and framing. The largest hidden cost was the twelve follow-up conversations with people who would not speak in a group and asked to show us privately — and those private sessions, not the group ones, are where the sensitive workflows appeared.
The sessions surfaced 40+ distinct workflows in three weeks. The best of them — a contract-clause summariser built by a junior legal analyst — became the template for the unit's first officially supported AI workflow◦.Figure
The most valuable workflow in the company was invisible until it was safe to show
What changed
The roadmap inverted. Instead of rolling out training for hypothetical use cases, the programme promoted proven underground workflows into supported, governed ones — tooling, data rules, and an owner per workflow. Within a quarter, the official and real adoption numbers converged, which meant risk was finally being carried where it could be seen◦.By the numbers40+real workflows surfaced by three weeks of amnesty mapping — each one a governance blind spot the day before
Not all forty survived triage, and that was the point. Roughly a third were duplicates: the same summarise-this-document habit reinvented in four departments, which told the programme where to build once instead of four times. A dozen were low-value personal conveniences nobody needed to govern. Six were genuinely risky — customer data or unreleased financial figures moving through consumer accounts. Five were good enough to promote immediately, and those five got the budget.
Sequencing mattered more than the count. The legal analyst's clause summariser shipped with a supported tool, a named owner and a one-page data rule within five weeks of being disclosed. The programme's credibility rested entirely on those five weeks; had it taken a quarter, the amnesty would have been remembered as a survey with better manners.
The measurement change was structural rather than cosmetic. Adoption stopped being reported as licence activations and started being reported as workflows with a named owner — a number that cannot be inflated by buying more seats◦.RelatedThe same map, built from the leader's side of the gap
The part that is harder than it sounds
Running the amnesty is the easy half. Sustaining what it starts is the hard half, and we got two things wrong.
The first was the queue. Forty-plus disclosed workflows met a programme with the capacity to properly support about five in the first quarter, which left more than thirty people who had taken a visible risk and then heard nothing for months. We had promised that anything disclosed and working would get proper tooling; we had not said when, and the silence read as the promise being quietly withdrawn. We would now state the capacity out loud at the start — we can support five this quarter, here is how we will choose, here is when we look again — and publish the shortlist rather than letting people infer it from silence.
The second was key-person risk. The clause summariser was excellent because one analyst had spent months refining it in her own time. Promoting it made the unit dependent on her before anything she knew had been written down, and she was, quite reasonably, ambivalent about a private side project becoming a corporate asset with her name on it. Turning a personal practice into something a team can run took two more months of unglamorous work, and no amount of amnesty framing shortens that.
There is also a limit worth naming plainly. Amnesty mapping tells you what people are willing to show you in a room where their manager has just promised safety. It does not tell you what moves through consumer accounts on personal devices at ten at night. For that you still need the network-side view, and the two pictures should be built together rather than one standing in for the other.
What to steal
- Assume the real number is a multiple of the official one. Budget your governance effort for the real one.
- Run the mapping as an amnesty, announced by line leaders — not by compliance. The messenger is the message.
- Separate the person from the practice, in writing, before the first session. An amnesty that cannot survive a genuine incident will not survive its first one.
- Reward disclosure visibly and fast: the first disclosed workflow that gets upgraded to proper tooling does more for visibility than any policy email.
- Say your capacity out loud. "We will properly support five workflows this quarter" is a kinder promise than "anything that works will be supported", because it is one you can keep.
- Promote, don't punish: the shadow practices are your adoption roadmap, pre-validated by the fact that people use them without being told.
If your readiness report flagged low tool visibility against real usage, this is the playbook — and the first mapping conversation is one we can help you run◦.RelatedWhat to do once usage is visible: closing the governance gap
Sources
- Microsoft, 2024 Work Trend Index
- KPMG & University of Melbourne, "Trust, attitudes and use of AI", 2025
- Cyberhaven Labs, 2026 AI Adoption & Risk Report
- ISACA, 2025 AI Pulse Poll
- Samsung's gen-AI ban after a source-code leak, 2023 (via Forbes)
- Gartner on shadow AI, 2025 (via ITPro)
- Slack (Salesforce), Fall 2024 Workforce Index
- BCG, "AI at Work 2025"
- BCG, "AI at Work 2026: Strategy Matters More Than Tools", June 2026 (via BCG press release)
Keep reading

Case Study: Turning Individual AI Wins Into Shared Capability
A capable, well-trained team where nothing compounded: every AI win stayed private. Five harvested workflows and one co-built assistant later, the median user caught up with the best.

Case Study: Putting a Defensible Number on AI Adoption
An AI programme everyone liked nearly lost its budget because nobody could prove it worked. Two baselined workflows later, it survived the cut — and earned an expansion.