Shadow AI Is Inside 70% of Companies, and Banned Tools Keep Coming Back
A new data report from security compliance company Vanta reveals that shadow AI has become a widespread and largely unmanaged reality inside businesses of all sizes. Drawing on anonymized data from more than 15,000 companies, the report found that 70% of organizations now have AI tools operating inside their environment that were never approved by IT or security teams.
The findings are part of a new research series called Trust Signals. Shadow IT overall grew 36% year over year, and companies discovered an average of around 140 unapproved tools within 90 days of connecting to Vanta's Third-Party Risk Management platform.
Key Takeaways
- 70% of companies have shadow AI operating with access to company data, never vetted by security teams
- Employees reinstall banned AI tools more than 100 times per month and around 1,000 times per year
- LLM vendors are 52% more likely to be flagged as "high risk" than traditional software vendors
- Only 2% of shadow IT vendors ever undergo a formal security review; 55% of the average company's vendor footprint is now shadow IT
The most-reinstalled tools include those from Anthropic, OpenAI, and Cursor. When workers depend on a tool for daily output, they find workarounds around access blocks. Vanta's research suggests the traditional block-and-revoke approach isn't holding up: a tool banned on Friday tends to be back in use by Monday.
The report argues that speed of review, not strictness of blocking, is the more realistic path forward. Building faster vendor assessment processes that still evaluate risk seriously is what keeps security oversight relevant in an era of AI-accelerated workflows.
Stay in Rhythm
Subscribe for insights that resonate • from strategic leadership to AI-fueled growth. The kind of content that makes your work thrum.
More from Thrum
Additional pieces exploring adjacent ideas
