No items found.
  • Platform
  • Pricing
  • About
  • Resource Hub
  • News
  • Blog
  • Help
  • Login
  • Book Now

Solutions

Explore everything you need to protect your workforce.

Ai security

Shadow SaaS
Data Leakage
Real-Time User Guidance
Phishing Protection

Browser security

Browser Observability
Authentication Governance
Back to Blog
Security

Shadow AI Doesn't Need a New App. It Just Needs Your Browser.

IBM's 2025 Cost of a Data Breach Report found 20% of organizations had identified unauthorized AI tools in their environment. Neon recently asked employees to report their shadow AI use. And we found 54.6% of knowledge workers said they were definitely or possibly using AI tools their company hasn't approved.

Mary Yang
Published on: 
Jul 6, 2026
On This Page
TOC Element
Share:

It's 11:00 PM. A Priority 1 incident just hit production, and the SLA clock is running. A senior engineer — let’s call him Marcus — does the fast thing.

He’s at home, so he opens a new tab in the browser he already has open, the one signed into his personal Gmail alongside his corporate Jira and Confluence accounts and pastes the error logs and architecture notes into a ChatGPT prompt. It's quicker than logging into the corporate-approved AI tool. He's trying to meet his SLA target.

The company's monitoring tool doesn’t register anything unusual that night besides the production outage. Marcus didn't install a new app, log in from a new device, or trip a single alert. He just used the tools he already had access to.

What is shadow AI, and why does it keep slipping past security teams?

Shadow AI is the use of AI tools at work without corporate approval, security review, or IT oversight — the AI-era version of shadow IT, and harder to catch because it rarely shows up as a new application. A recent CNET story put this plainly: shadow AI can live inside a browser extension, an email plug-in, a meeting recorder, or — as with Marcus — a second tab in a session someone was already using for work.

Dropzone AI CEO Edward Wu, quoted in the piece, made the point that matters most to security teams: once sensitive data leaves through one of these tools, an organization loses the ability to track it or retrieve it. The CNET piece cited IBM's 2025 Cost of a Data Breach Report, which found 20% of organizations had identified unauthorized AI tools in their environment, and 63% had no AI governance policy, or were still building one. That 20% figure measures something specific: the share of organizations whose security teams found unauthorized AI activity.

Neon Cyber recently asked a complementary question — not what security teams discovered, but what employees themselves report doing. And that finding was substantially higher than 20%. Among more than 200 U.S. knowledge workers surveyed in May 2026, 54.6% said they're definitely or possibly using AI tools their company hasn't approved.

The gap between those two numbers is critical.

The truth is most shadow AI activity was never in a position to be found by legacy security tools looking for unauthorized applications. That’s because the tooling that security teams use to flag new applications rarely trips wit shadow AI; it’s not designed to catch behavior inside applications that the company has already approved for use. This is even more true when that application is the browser.

Why can't my DLP or SSO catch this?

DLP, SSO logs, and EDR are built to flag something new: a new device, a new login, a new application requesting access. Shadow AI in the browser routinely skips all three signals, because it's the same authenticated profile, the same open tab, the same session an employee was already using for approved work.

Neon Cyber's research shows how routine this blurring has become:

None of this requires an employee to go looking for something new. It requires them to keep working the way they already work, in the browser they already have open, and reach for whatever gets the task done faster. Marcus didn't install anything. He didn't need to.

Key takeaway: Shadow AI in the browser exploits a blind spot in security architecture. Tools built to flag new applications can't see behavior that hides inside the ones your company already trusts.

Does banning AI tools reduce shadow AI risk?

No. CNET's reporting makes the same observation: outright bans tend to push usage further out of view rather than end it. Data from Neon Cyber shows exactly how that plays out. Asked what they'd do if their preferred AI tool wasn't approved, 49.3% of respondents said they'd use a different, unapproved tool anyway. Another 41.9% said they'd copy work data into a personal tool "just this once." A ban removes the sanctioned option. It doesn't remove the incident, the deadline, or the manager expecting results by morning — so employees route around it, often onto a personal account where visibility drops even further than it already was.

Approval timelines make the gap worse. 41.4% of respondents expected getting a new AI tool approved to take more than two weeks. 20.3% expected more than a month. A production outage doesn't wait two weeks. Every day that approval takes longer than the task in front of an employee is a day they spend choosing between missing a deadline and working around the policy — and the data says which one they pick.

The fix has to operate at the point of click: a control that can tell the difference between a low-risk prompt and a paste that includes a database credential or a customer record, in the moment it happens, not in a quarterly audit.

How do you monitor workforce AI use without slowing teams down?

Neon Cyber’s platform gives security teams visibility into AI and SaaS activity inside the browser session itself, as it happens. It doesn't require employees to switch tools, and it doesn't require IT to pre-approve every new AI feature that shows up. It analyzes browser activity in real time and intervenes at the moment of risk — a sensitive paste, an unsanctioned tool, an unmanaged account mixing personal and work activity in the same tab.

With Neon, Marcus still gets to move fast at 11 PM. But now the organization gets to see it happen.

See the full picture

CNET's reporting confirms what we already know: Employees are moving fast, doing their jobs, and reaching for whatever tool is closest at hand. Even more, the tools built to detect unauthorized activity or identify new applications were never designed to see this happening in the browser.

The Neon Cyber research report, Quantifying Shadow AI Risk in the Browser, goes deeper into how this shows up across 227 U.S. knowledge workers — including how AI use, tool sprawl, and personal-professional account blur play out in the data. Download the full report with our 5 key findings.

And here's the full infographic on Marcus, in case you don't want the full report.

Infographic showing Marcus, a senior engineer, using AI on his personal computer to debug production code.

Protect the people that power your business

Subscribe to the Neon Glow-Up

Subscribe
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Follow Us

Company

Platform
About us
News
Blog

Platform

Browser Observability for SecOps & GRC
AI & Shadow SaaS Visibility and Control
AI Data Leakage & Insider Risk
AI Guardrails & Real-time User Guidance
AI-Powered Phishing & Social Engineering Defense
Authentication & Identity Hygiene
© {{year}} Copyright. All Rights Reserved.
Privacy Policy
Terms and Conditions