Shadow AI: What to Do About the Tools You Didn't Approve
Retool surveyed 307 CTOs, CIOs and CISOs in May 2026. Five percent are very confident they know what's running in their own production environment, and mid-market companies are the least governed of any size band. Four things to run this month, before you buy a governance tool.
- shadow AI
- governance
- implementation reality
- mid-market
- AI policy
Five percent. That's the share of CTOs, CIOs and CISOs who told Retool they're very confident they have full visibility into everything running in their own production environments. Forty-three percent said they aren't confident at all. The survey went to 307 senior technology and security leaders at companies from 50 employees up, fielded with Wynter in May 2026, and the number that should stop you isn't the 5%. It's what those leaders think is out there that they can't see.
Shadow AI used to mean an employee pasting a client brief into a personal ChatGPT account. That version is real, and it's the one most policies were written against. It's also no longer the expensive one. The expensive version is a working internal tool, built by prompt in an afternoon, connected to live data, running in production, and not written down anywhere. Ninety-three percent of the leaders Retool surveyed are at least somewhat concerned about exactly that. Twenty-two percent had a production incident caused by an AI-generated internal tool in the past twelve months. Another 51% answered the incident question with "not to my knowledge, but I can't say for certain."
That last group is the interesting one. Half the market can't distinguish between not having had an incident and not having noticed one.
There's a cross-tab in the report that matters more than the headline. Mid-market companies, 200 to 999 employees, are the least governed of any size band: 19% have no formal governance approach at all, against 8% at enterprises over 1,000 and 10% at companies of 50 to 199. That ordering isn't random. Small companies are small enough that someone still knows what everyone is building. Enterprises have a compliance function that was going to catch up eventually. The mid-market has neither, and it has the most people with the most access to the most systems, which is the exact profile of a company that's about to hire an AI partner.
If you're in that band, the honest position is that you don't currently know what's running, and any governance program you buy will be governing the subset you already knew about.
The reason policy alone hasn't worked is worth being precise about, because it isn't employee behaviour. One CISO in the Retool survey put it as well as anyone: "By the time you know something has been built and is being used, you're already too late." Traditional discovery assumes software arrives through a channel, a purchase order, an SSO integration, a deployment pipeline. A prompted tool arrives through none of them. It has no vendor, no licence, no install, and often no repository. Your MDM won't see it. Your SSO won't see it. The person who built it didn't think of it as software, because it took eleven minutes.
So the audit you can run technically is real but partial, and the gap between the partial audit and the truth is where most of your exposure lives.
Four things to do, in order, none of which require buying anything.
Pull the visible layer first. Your IT admin can export third-party app connections through SSO and installed browser extensions through MDM in an afternoon. This won't find prompted tools, and you should run it anyway, because it will find connected accounts nobody remembers authorising and it gives you a factual starting number rather than an estimate.
Then ask people, which will outperform the audit. Two questions, sent to everyone, answerable in under two minutes: what AI tools do you use for work, and what do you use them for. Say plainly in the message that nothing in the answers will be held against anyone, and mean it, because the first person who gets a talking-to will end the usefulness of every future survey you run. Expect the results to be higher than your estimate. That's the normal outcome, not a failure of your culture.
Write the one page that covers the largest share of the risk. A single document naming the data categories that never go into an AI tool, whichever tool it is: client personal data, financial records tied to named individuals, legally privileged material, health information. This takes a day. It works without an approved tool list, it works for tools you haven't discovered, and it works for tools that don't exist yet, which is why it should come before the approved list rather than after it.
Then build the path that makes the next tool visible. A request form and a stated turnaround, five business days for standard-risk tools, is the mechanism that converts shadow AI into a queue. A policy that says no to tools people depend on doesn't reduce usage, it reduces reporting. You'll know the path works when submissions come in for tools that were already in use, which is the point.
One thing this doesn't solve. Fifty-five percent of the leaders Retool surveyed think security and access controls belong in a centralized platform underneath the app, and only 7% think they belong inside each generated app. They're probably right, and that's a platform decision with a budget attached and a timeline measured in quarters. The four steps above are what you do in the meantime, and the meantime is where you are.
There's also an accountability question the survey exposes and no tool fixes: 44% of these organisations either have no default answer for who's responsible when an AI-generated tool causes an incident, or haven't decided. Decide that before the incident. It's free, it takes one meeting, and afterwards it costs a great deal more.
If you're bringing in a partner for AI work, ask them how they'll find what's already running before they govern anything. A partner who answers with a product name is proposing to inventory the tools their product can see. A partner who answers with a method, including the part where you ask people, has done this before.
Run the survey this week. The number will be higher than you think, and the conversation is easier when you can name the tools.
If you want that question answered for your specific situation, the Forge Playbook does it. Answer a few questions about your business and we'll put together a tailored outline of which workflows are worth automating and what a realistic budget looks like for each. Free, no obligation, takes about three minutes.