Shadow AI: How to reduce the risks of unauthorized AI

82% of Brazilian companies are already dealing with the unauthorized use of AI by their employees, and most are still reacting in the wrong way.
Cybersecurity 5 min read By: Skyone

82% of Brazilian companies are already dealing with the unauthorized use of AI by their employees, and most are still reacting in the wrong way.

This is the data highlighted by Forbes Brazil this week, based on the study "The Value of AI: Brazil 2026," conducted by SAP in partnership with Oxford Economics. The study shows that employees use third-party artificial intelligence tools without formal approval or supervision at least occasionally in 82% of the Brazilian companies surveyed.

The number is large enough to grab attention. But what should really concern technology leaders isn't the percentage, it's what it reveals about the strategy most companies are using to deal with it: banning.

The problem isn't the tool. It's the lack of an alternative

When an employee pastes a contract, a financial report, or a client list into a public chatbot to expedite a task, they are not trying to circumvent the company's security policy. In most cases, they don't even know a policy exists. They just want to finish the job faster.

Among the Brazilian companies surveyed, 43% reported data leaks or exposure of intellectual property, 32% reported security vulnerabilities, and 31% mentioned compliance violations related to the use of unapproved tools. These are real, measurable consequences that have already occurred, not hypothetical risks of a distant future.

And most revealingly: today, 26% of tasks performed in Brazilian companies already receive support from artificial intelligence, with expectations that this percentage will reach 44% in two years. Adoption will not slow down. The remaining question is whether it will continue to happen secretly or within a controlled environment.

Read also: Does generative AI use company data? Risks, LGPD (Brazilian General Data Protection Law), and how to protect corporate information.

Governance has not kept pace with the speed of adoption

Herein lies the central discrepancy: only 15% of Brazilian organizations consider their processes and frameworks fully prepared to govern AI, and only 12% assess their capabilities as fully ready for this role.

In other words, the technology is already within the company, being used by almost everyone in some way, but the structure to govern it doesn't yet exist in most cases. This is the exact definition of an invisible liability: a risk that's already on the balance sheet, even if it doesn't appear in any reports.

The cost of this gap is not abstract. The average cost of a data breach in Brazil already exceeds R$7 million, according to recent industry surveys, and when the incident specifically involves unauthorized use of AI, this value tends to be even higher, because the source of the leak is more difficult to trace and contain in time.

You may also be interested in: Cyberattacks in Brazil: 249 billion in 2026

Banning doesn't work, and the data shows why

The most common reaction when a company discovers it has shadow AI is to block access to the tools. This makes sense at first glance: if the risk comes from an unauthorized tool, remove the tool from circulation.

The problem is that this logic ignores a simple detail: AI is just a click away, available for free, in any browser, on any personal mobile phone. Blocking corporate access doesn't eliminate the temptation; it only pushes the behavior off the company's radar, where it's even harder to monitor.

In practice, the result is usually the opposite of what was intended: less visibility, not less risk.

The real alternative: give the team a corporate option that's as good as the personal one

If banning doesn't solve the problem, what does solve it is competing with the same convenience that made shadow AI so attractive in the first place.

This means offering the employee an AI environment that is:

  • As fast and useful as the chatbot he already uses on his cell phone;
  • Protected behind the scenes, with data processed within the company's cloud infrastructure, under defined access and encryption policies;
  • Traceable, so that the security area knows exactly what is being processed, by whom, and for what purpose;
  • Integrated with company data, so that the employee does not need to leave the controlled environment to obtain a better response.

This is the point where cloud, data, and security cease to be three separate disciplines and become a single architectural decision. There is no governance without an organized database. And there is no organized and secure database without a cloud strategy designed for it from the outset.

What to do tomorrow morning

Governing shadow AI doesn't start with a policy written in a document that nobody will read. It starts with a simple diagnosis: what AI tools are already being used in your company today, even without approval?

Based on this response, the strategy shifts from "how to prohibit" to "how to offer something better"—a secure, corporate AI environment with the same agility that prompted the employee to seek an alternative on their own in the first place.

The question every technology leader should be asking this week isn't "Does my company have shadow AI?". It's almost certain that it does. The question is: what are we offering in its place?

Skyone
Written by Skyone

Start Your Digital Transformation Today

Transform Your Business with Skyone. Request a demo or schedule a call with our experts to discover how Skyone can accelerate your digital strategy.

Subscribe to our newsletter

Stay up to date with Skyone content

Contact Sales

Have a question? Talk to a specialist and get all your questions about the platform answered.