Every IT team knows employees are using AI tools nobody approved. Most have accepted it as a cost of doing business. Our new research shows that cost is already being paid in security incidents.
In June 2026, DNSFilter and CensusWide surveyed 400 IT and cybersecurity professionals across the US and Canada for The Visibility Deficit: The 2026 AI Cybersecurity Report. AI adoption is effectively universal: 99.75% of respondents say someone in their organization uses AI tools at work, and 55% run three to five of them. Nearly half of organizations (46%) have had an employee connect an unauthorized AI tool directly to corporate systems. For one in five (20.1%), that connection caused a security incident. Another 14.8% suspect it happened but can't confirm it.
The incidents are already here. The bigger problem is how few organizations see them coming.
Shadow AI is any AI tool, model, browser extension, or agent that employees use or connect to corporate systems without IT's approval or knowledge. It includes chatbots used through personal accounts, AI features inside approved SaaS apps that were never reviewed, and AI tools granted OAuth or API access to company email, files, or code repositories.
This increased risk comes from access. Once a tool holds a token to corporate data, it can read, store, and move that data without anyone reviewing each step. An employee pasting text into a chatbot exposes what they paste. An AI tool connected through OAuth can reach everything the employee can.
Most organizations already have rules for AI. 81% have a formal AI tool policy in place, and 55.75% say it's consistently enforced. The gap is that a policy only works when someone can see it being broken.
When a new AI tool requests OAuth or API access to corporate systems, 43% of organizations let employees grant it themselves. IT either hears about it after the fact or, for 6.5% of organizations, never hears about it at all. Leadership and practitioners also disagree on how tight that gate is: 73.9% of executives surveyed believe new AI tools require admin approval, while only 58% to 60% of practitioners say that approval actually happens.
Detection leans on the same weak link. Asked how they identify incidents involving third-party SaaS or AI tools, 41.5% of respondents rely on user reporting, nearly the same share that use CASB or SaaS security tools (41.75%). In other words, a large share of shadow AI surfaces only when someone happens to mention it. Yet 91.5% are confident they would detect a breach within six hours.
The 20.1% incident rate is also likely an undercount. 37.75% of respondents say their organization has had a security incident that was never formally reported, and 43.5% say their organization has, at times, downplayed the severity of an incident because it lacked the resources to fix it.
Company size also doesn't solve it. The largest organizations surveyed (2,500 to 5,000 employees) that have the most mature AI governance in the study still report the highest shadow AI incident rate: 32.5% say an unauthorized AI tool caused a security incident. At the smallest organizations (150 to 499 employees), half have already had unauthorized AI tool connections, and 24% say those connections have caused an incident.
Shadow AI rarely looks like a new, unknown application. It usually arrives through one of three routes:
Each route has the same starting point: A tool connects before anyone checks it.
Every AI tool, sanctioned or not, has to resolve a domain before it can do anything. That makes the DNS layer the earliest place to see shadow AI, at the moment a tool arrives instead of the moment it causes a problem. DNSFilter provides DNS-level visibility into the AI tools and agents communicating from your network, secure access for the AI your teams have sanctioned, and governance for the autonomous agents arriving next.
With that visibility, your team can answer three questions that most organizations in our survey can't:
For existing DNSFilter customers, this visibility lives in the dashboard you already use. For MSPs, shadow AI is a client conversation worth having now, especially with SMB clients that carry the heaviest exposure and the least governance. "We have an AI policy" is a different conversation than "we can show you every AI tool talking to your network."
The Visibility Deficit: The 2026 AI Cybersecurity Report covers the complete findings, including the gap between what executives believe and what practitioners see, and how autonomous AI agents raise the stakes. Download the report, or start a free trial to see what's running on your network today.
Shadow AI is any AI tool, model, extension, or agent used or connected to corporate systems without IT's approval or knowledge. The biggest risk comes from unapproved AI tools granted OAuth or API access to corporate data.
Very common. In DNSFilter's 2026 survey of 400 IT and cybersecurity professionals, 46% said an employee had connected an unauthorized AI tool to corporate systems, and another 14.8% suspected it had happened but couldn't confirm it.
Yes. 20.1% of respondents said an unauthorized AI tool connection caused a security incident at their organization. Among the largest organizations surveyed, that figure rose to 32.5%.
Most organizations combine SIEM, CASB or SaaS security tools, audits, and user reporting, and 41.5% of respondents in DNSFilter's 2026 survey rely on user reporting. Monitoring at the DNS layer shows AI tools when they first connect, before they are granted access to data. DNS filtering is an optimal way to detect unauthorized AI usage on the corporate network, while also providing a way to control that AI usage.
Not on its own. 81% of organizations surveyed have a formal AI tool policy, yet 43% still let employees grant AI tools OAuth or API access without prior approval. A policy needs visibility behind it to be enforced. DNSFilter gives you the ability to create an enforceable policy, allowing sanctioned AI tooling and blocking tools that you do not want your employees to access.
Between June 15 and 26, 2026, DNSFilter partnered with CensusWide to survey 400 IT and cybersecurity professionals across the US and Canada. Respondents were manager-level and above at companies with 150 to 5,000 employees, across all industries.