Shadow AI is your people using AI your company never approved: a personal ChatGPT tab, a desktop agent, an AI feature inside software you already pay for. It is now the third most common non-malicious insider action in Verizon's 2026 breach report, a fourfold rise in a year, and IBM found one in five organisations had already been attacked through it, at $670,000 more per breach than companies with little or none. The standard response is detection: find the app, block the app. That reads the behaviour backwards. Nobody opens a consumer chatbot to break a rule. They open it because a question needed answering and their own company was slower than a stranger's chat box. Detection tells you which app was opened. It never tells you which question drove someone there, so blocking the app leaves the question standing, and the question finds another door. The fix sits on the supply side: make the company answerable, in the channels people already use, with permissions enforced inside retrieval.
The scale, and the bill
Verizon's 2026 Data Breach Investigations Report, published in May, puts shadow AI third on the list of non-malicious insider actions, up fourfold in twelve months. Two figures from it matter more than the ranking. Forty-five percent of employees are now regular AI users on corporate devices, approved or not. And 67% of users reach AI services through non-corporate accounts on those same corporate devices.
Sit with the second one. The activity is happening on your hardware under someone else's login. Your identity provider does not see it. Your audit trail has no row for it. The most common thing being handed over, in Verizon's data, is company source code.
Then the bill. IBM's Cost of a Data Breach report found one in five organisations had experienced an attack tied to shadow AI security issues. Those breaches ran $670,000 above companies with little or no shadow AI. In 60% of cases the attackers moved on to other data stores, and 31% caused operational disruption.
None of that is a story about reckless employees. It is a story about a door nobody knew was open.

Nobody does this to break a rule
The Thomson Reuters Future of Professionals report, a survey of 1,816 professionals across 62 countries in March and April 2026, found 34% using AI their organisation has not sanctioned. The same survey found 91% saying their organisation falls short of what the technology could already deliver.
Read those two numbers together and the motive stops being mysterious. A third of people are going around the company, and nine in ten think the company is behind. Nobody routes around an organisation that answers them.
Picture what actually happens in the ninety seconds before a paste. Someone needs the renewal date on a contract, or the unpaid balance for a customer, or what was agreed on a call in March. The answer exists. It is inside a PDF somebody saved and nobody opened, an AI call summary nobody read, a paragraph at the bottom of a CRM comment. Reaching it means knowing which system holds it, having access to that system, and finding someone free enough to ask. Or they can paste what they already have into a chat box and have something back before the kettle boils.
That is the whole decision. It gets made hundreds of times a week in a company of thirty people, and it is not a character flaw. It is arithmetic.
So here is the part worth keeping. Every paste into a consumer chatbot is a measurement. It records a question your own systems could not answer fast enough. That makes shadow AI the most honest usage research your company will ever get, and almost nobody reads it that way.

What blocking actually reaches
Microsoft now ships a Shadow AI page in the Microsoft 365 admin centre, and their own documentation is refreshingly plain about its reach. As of this month it is a public preview, opt-in through the Frontier programme. Viewing it needs a Microsoft 365 E5 licence. Devices have to be enrolled in Intune, and blocking applies only to managed Windows machines. Seeing who used what, and how much traffic went where, needs Global Secure Access switched on as well.
It detects seven agents today: OpenClaw, ChatGPT Desktop, Ollama Desktop, Poe Desktop, Claw and ZeroClaw, OpenCode, and Claude Desktop. It can block exactly one of them. For ChatGPT Desktop, detection is available and blocking is not.
That is the largest software vendor on earth, building the most advanced control of its kind, and being straight about the edges. The preview will grow, and the list will get longer. But the shape of the limit is structural, not a gap waiting to be patched. The tooling reads managed Windows devices. Remember that 67% figure: the accounts are personal ones. A personal phone is not enrolled in Intune. A browser tab is not an installed agent. Neither is the AI feature that appeared last Tuesday in a tool you already approved.
Run it perfectly and you remove the most convenient door. The question is still standing in the corridor, and it will try the next handle.

The finding everyone skipped
Buried in IBM's numbers is the sentence that should change what you do next. Of the organisations breached through shadow AI, 97% lacked proper AI access controls.
Not "lacked a policy". Access controls.
This is the trap waiting on the other side of the decision, and it catches companies that did the responsible thing. The day you connect an AI to your own files, the risk quietly changes shape. It stops being company data walking out and becomes everyone inside seeing everything. If retrieval does not know who is asking and what that person is allowed to see, a fully sanctioned tool will hand the salary spreadsheet to whoever phrases the question well, at machine speed, with your blessing and a full audit log proving you approved it.
The part that took longest to get right while building Naxis was exactly this, and it is not a setting. Permissions are enforced inside retrieval itself, so a document that a person may not see cannot reach the answer that person gets. There is no permissions screen to configure and no filter to forget, because the filter is not a layer that can be bypassed. We wrote up the full threat model we build against separately.
How to read your own shadow AI, whatever you buy
This part is worth doing next week regardless of vendors, and it costs nothing.
- Record the question, not the tool. Which app someone opened is trivia. What they were trying to find out is your roadmap.
- Sort by repetition. Any question asked twice by two people is a system failure, never a user failure. Asked ten times, it is a chokepoint with a name.
- Time your official path. Take one real question and answer it the approved way, with a stopwatch. If that takes longer than pasting, you already know which one your team will choose tomorrow.
- Never punish whoever tells you. The moment reporting costs someone anything, your data goes dark and the behaviour does not.
Companies that run this exercise usually find the same thing. The recurring questions are not exotic. They are status, totals, what was agreed, who handles this, and every one of them has an answer sitting in a system the asker either cannot reach or does not know exists.

Make the sanctioned path the shortest path
Google's own AI answer for "shadow AI" currently leads with the advice to give people official, secure options so they do not feel forced to use risky public ones. That is correct, and it is where most attempts fall over, because a sanctioned tool that is harder to reach than a phone in a pocket loses to the phone. Convenience is not a nice-to-have here. It is the entire mechanism.
Which is why Naxis is not an app anyone opens. It is a private knowledge engine that connects the tools you already run, including the custom ones no connector list covers, and then answers in the channels people are already typing in: WhatsApp, Telegram, Slack, Teams, email, your website, your own API. Under your company's name, not ours. There is nothing to adopt, no rollout, no tab to remember. The approved path cannot lose on convenience when it is already inside the window where the question was going to be typed anyway.
Everyone gets direct answers from everything the company knows, and only ever from what they are allowed to see. It runs single-tenant, and if policy says the data never leaves your building, the identical product installs on your own server.
Shadow AI is not your team going rogue. It is your team telling you, hundreds of times a week and in the only language that gets a response, that the company is hard to ask. You can spend the next year trying to make that harder. Or you can make asking work, and watch the reason disappear.

Ask it something you would normally have to chase a person for. The demo is the real application, with a real corpus behind it.
Plans and the self-hosting add-on: /pricing.