Shadow IT Statistics

Shadow IT Statistics: What Our Survey Data Revealed

Shadow IT, where employees use assets without their company’s knowledge or approval, can create visibility, cybersecurity, and compliance issues. And it happens far more frequently than you may think. 

Below, we’ll unpack some illuminating shadow IT statistics from our recent survey to put everything into perspective. Here are the key takeaways. 

  • Nearly half of software adoption falls under shadow IT classification
  • Less than half of today’s organizations have full device visibility
  • 54% of companies have already experienced a real shadow IT incident
  • 36% of IT leaders say 25% or more of their budget goes toward shadow IT-related costs
  • Rapid implementation of AI tools is fueling even more shadow IT concerns in the future

Shadow IT Data: How Much Software Flies Under IT’s Radar

Our shadow IT assets data found that 62% of IT leaders estimate that at least a quarter of their software is adopted without IT’s approval or knowledge.

Here’s the full breakdown:

  • 26% of IT leaders said 25% to 39% of software tools were adopted without IT’s approval or knowledge
  • 27% said it was 40% to 59% of software tools
  • 9% said it was 60% plus

Conversely, 17% of IT leaders reported that only 10% to 24% of software tools were adopted without IT’s approval or knowledge, and 20% of leaders said that it was under 10%.

This means that over a third of IT leaders (36%) place the number at 40% or more, which is quite high. 

Compare this with Gartner data that found shadow IT accounted for 30% to 40% of IT spending at large enterprises, and you can get a sense of the true scale of the issue. 

This shows just how widespread shadow IT activities are, and that it goes much deeper than just a few unauthorized assets eating up part of an organization’s budget. 

When this volume of software flies under the radar, it creates a ton of hidden risk and can quickly compromise sensitive data. 

Shadow IT Metrics: Device Visibility and Unmanaged Endpoints

Note that shadow IT risk doesn’t stop at software tools. Our survey found that a good portion of today’s organizations also have a device visibility problem.

In fact, nearly half of IT leaders (46%) lack complete visibility into every device with company-data access (only 54% have full transparency). Further, 85% report at least some unmanaged or unknown devices, and 49% estimate that 10% or more are unmanaged. 

This data suggests a measurable visibility gap, where the number of organizations without complete transparency rivals the number with complete visibility. Needless to say, this creates a lot of security risk with sensitive data, especially for businesses with a large remote workforce.

Therefore, many organizations could benefit from using IT asset management services and software to get a grip on transparency and get this area of IT operations under control. 

For instance, with allwhere, you can view all of your devices from a centralized dashboard, where you can see what you have on hand, which employee has what, what’s in storage, and what’s in transit to drastically reduce blind spots.

And as your IT inventory evolves, you can use allwhere’s tools to conveniently add and remove devices to ensure consistent accuracy. 

Shadow IT Risks: Real Incidents Traced Back to Shadow IT

As we mentioned earlier, one of the main problems of shadow IT is the compliance and security risk it presents. Any time an employee uses unapproved tools or devices, there’s always a risk of a sensitive information data leak. 

And here’s the thing. Our survey found that this isn’t just some theoretical security/compliance concern. It’s a real issue that a large number of organizations have already dealt with at some point. 

To quantify, 54% of organizations have experienced a security incident, data exposure, or compliance issue traced to shadow IT — the majority. 

This shows that shadow IT risks are very much real and not merely a perceived danger (we’ll discuss that in the next section). 

Therefore, this is something that each security team needs to take seriously. And modern companies need to work diligently to improve cybersecurity and cloud security, protect company data, and reduce their attack surface. 

Threat actors are definitely out there, so being intentional with each security measure is incredibly important for minimizing security risks and other issues. 

What is the Main Danger That Comes from Shadow IT?

A data breach is the number one perceived danger, with 37% of today’s organizations citing this as the single biggest IT threat in their eyes. 

After that, it’s:

  • Unauthorized access, with 19% of organizations viewing this as the single biggest danger
  • A compliance or regulatory violation - 12%
  • Permanent data loss - 9%
  • Wasted or duplicated spend - 4%
  • Loss of IT control and visibility - 15%
  • Operational and integration problems - 4%

Note that these are perceived shadow IT risks and not realized incidents (we just covered those in the previous section). 

But when strictly asked what makes IT leaders the most nervous, a data breach, unauthorized access, and loss of control and transparency were the biggest sources of stress, with compliance issues not far behind. 

With over half of organizations having already experienced an actual shadow IT-related security incident, data exposure, or compliance issue, it’s fair to say that these concerns are justified. 

Shadow IT Trends: Rapid Growth and the Rise of Shadow AI

There are two parts to this trend story. 

First, 59% of organizations say that shadow IT has grown in the past two years, with 30% saying it’s been significant growth. 

And within the last 12 months, 46% say they’ve had an employee put company data at risk through unsanctioned AI tools (such as a public chatbot), with another 8% unsure. 

This data suggests that AI usage is the fastest-moving sub-trend in shadow AI. And it’s not difficult to see why. AI use has exploded recently, with 2026 data finding that “77% of companies are either using or exploring the use of AI deployment.”

And with rapid generative AI adoption across countless industries, it’s extremely easy for sensitive data to be put at risk, even if an employee has good intentions. 

Say, for instance, an employee wants to quickly install an application or build a simple software tool, and they use agentic AI such as ChatGPT Codex to do it for them. 

Along the way, they may attach internal resources or company information to AI applications, which can quickly create a large attack surface and a significant cybersecurity risk. 

So even though an employee is simply using AI tools to streamline their daily tasks, this presents a ton of hidden risks boiling just beneath the surface. 

This is why organizations that use AI in any capacity need strong AI governance and a well-fleshed-out AI policy for managing shadow AI moving forward. 

The Hidden Cost of Shadow IT

When asked, “What share of your software budget do you estimate goes to duplicate, redundant, or unused tools, including shadow purchases?” 69% of IT leaders estimated that it was at least 10%. 

32% of leaders estimated that it was 25% to 39%, and 4% placed it at 40% plus. 

Less than a third (29%) of respondents estimated that the number was under 10%. 

This goes back to what we were talking about earlier with the visibility gap. 

You can’t cut what you can’t see. So if you’re dealing with a substantial amount of shadow IT, where there’s a lack of knowledge or approval of IT assets, it’s almost guaranteed to cost you. 

Whether it’s overlapping shadow IT applications, unnecessary cloud service subscriptions, or buying new laptops when you already have several sitting in storage, it can come back to haunt you financially. 

So, on top of cyber security risks, this is yet another big reason to prioritize maximizing your IT visibility, as this is an essential part of IT asset management best practices.

Shadow IT Best Practices: Closing the Gap

Understanding the causes is always the precursor to initiating an effective response for shadow IT. Here’s what our survey data found about causes. 

The number-one reason employees bypass IT is that the approval process is too slow (28%). The second is that they didn’t think it was a risk at all (22%). 

Besides that:

  • 19% of employees thought that using an unapproved tool was better than an approved one
  • 18% didn’t know a policy existed
  • 13% said it was due to cost or budget workarounds 

And while the reasons can vary from company to company, it’s safe to say that these are great starting points when managing your own shadow IT risks to reduce the attack surface. 

When it comes to human risk management, a shadow SaaS discovery tool is the most common control (33%), then training (23%), and MDM/UEM (17%).

After that, there’s employee training at 23% and periodic audits at 6%. Finally, only 4% of companies rely on offboarding access reviews, which is a clear blind spot for many organizations. 

Methodology

The goal of our survey was to determine the scale of shadow IT for modern organizations, including hardware, software, and cloud assets. 

We also wanted to analyze perceived risk versus the actual number of incidents, along with how AI factors in, costs, and what companies are doing to initiate effective shadow AI management. 

To accomplish this, we surveyed 100 respondents who worked in IT — 79% of whom were primary decision-makers and 21% had significant influence. 

If you’re interested in creating a far more transparent ITAM lifecycle, consider using allwhere. 

We’ve been rated as one of the best IT asset management companies and can help you get procurement, deployment, storage, inventory management, and retrieval under control. 

Illustration of three U.S. cities and the animated shipping box running through all three.

Ready to simplify your entire device lifecycle?

Eliminate manual work, gain real-time visibility, and keep costs predictable — all in one platform. Let allwhere handle the logistics so your team can focus on what matters.

Book a custom demo