Skip to main content
Live

43,280 AI events recorded on our own engineering fleet in the last 30 days.

Tracelet / State of Shadow AI report

The AI attack surface nobody approved.

Shadow AI is not one thing employees do. It is a supply chain: every unmanaged AI tool, extension, connector, model and skill is a place data can leave your control, or a place something malicious can enter it. It is growing faster than anyone can see it.

78%

of AI users bring their own AI tools to work, tools not provided or sanctioned by their employer.

Microsoft & LinkedIn, 2024 Work Trend Index
What shadow AI is

Shadow IT, with an agent attached.

ISACA defines shadow AI as the unauthorised use of AI tools and solutions to perform job tasks: chatbots, code assistants and large language models deployed without IT, security or compliance approval, a direct parallel to shadow IT (ISACA, 2025).

The parallel undersells it. Shadow IT was a spreadsheet in the wrong place. Shadow AI reads files, runs shell commands, calls MCP servers and opens pull requests, with the same access as the developer who installed it.

  • A coding assistantinstalled from a marketplace and connected to every repo on the machine.
  • A browser extensionwith an AI feature that reads the pages it is allowed to see.
  • An MCP connectoradded to a config file, reachable by any agent that reads it.
  • A model or agent skillpulled from a public hub and run locally, payload included.
  • A SaaS featurea vendor switched on, now processing your data through a model you never reviewed.
The state of shadow AI today

Adoption is personal. Governance is not keeping up.

Four independent bodies of research, one pattern: use is broad and self-directed, policy is thin, and the cost lands on the breach.

The shadow AI supply chain

Eight links. Every one is a door.

Software has a supply chain, and so does the AI an organisation runs. Each unmanaged link is a place data leaves, or a place something enters. Where JFrog’s research team measured that entry, the figure is on the link (JFrog, 2025 State of the Software Supply Chain Report).

Figures on links 03, 05, 06 and 07 are from JFrog’s 2025 report.The other links are described, not measured; no figure has been added where the source has none.
Where the gaps are

Visibility, guardrails, accountability.

The three things an organisation needs and, on the evidence, mostly does not have. The same three words are in Tracelet’s reason for existing.

Visibility

78%

of AI users bring their own AI tools to work.

Microsoft & LinkedIn, 2024 Work Trend Index

Adoption is personal before it is organisational. A tool that was never procured is never in the inventory, so the first governance question, what is running, has no answer.

ISACA recommendations 01 and 04

AI tool discovery and an inventory, then a catalogue of approved and tested tools.

Guardrails

63%

of organisations have no AI governance policy at all.

IBM, 2025 Cost of a Data Breach Report
ISACA recommendations 02 and 03

A written policy, and identity and access controls that apply to AI tools.

Accountability

$670,000

more, on average, when shadow AI contributes to a breach.

IBM, 2025 Cost of a Data Breach Report

Without a record of who did what through which tool, the post-incident question is unanswerable.

ISACA recommendation 05

Cross-functional governance, with IT, legal, HR and security in the same review.

ISACA’s five recommendations map one to one onto what a control plane does.ISACA, 2025

  1. 01Discovery and inventoryInventory
  2. 02A written policyPolicy verdicts
  3. 03Identity and access controlsIdentity
  4. 04A catalogue of approved toolsAn approved route for tools
  5. 05Cross-functional governanceA decision record every team can review
Sources
  1. Microsoft & LinkedIn, 2024 Work Trend Index“AI at Work Is Here. Now Comes the Hard Part”, May 2024. 31,000 people surveyed across 31 countries.
  2. ISACA, 2025“The Rise of Shadow AI: Auditing Unauthorized AI Tools in the Enterprise”, 2025.
  3. ISACA, 2025“From Shadow IT to Shadow AI: Navigating the New Frontier of Enterprise Risk”, @ISACA volume 19, 2025.
  4. IBM, 2025 Cost of a Data Breach ReportResearch conducted by the Ponemon Institute across 600 organisations.
  5. Deloitte, The State of AI in the EnterpriseSurvey of 3,235 senior leaders, IT and line-of-business, across 24 countries, fielded August to September 2025.
  6. JFrog, 2025 State of the Software Supply Chain ReportJFrog’s security research team scanning public model and package registries.
Self-assessment

Where does your organisation stand?

Ten questions across visibility, policy, identity and access, and accountability. Scored in your browser; nothing is sent or stored.

Take the self-assessment
Design partners

Start the conversation. One call to establish fit and how we would work together.

Become a design partner