Report: Shadow AI Poses an Increasing Risk to Organizations

KnowBe4 Team | Sep 10, 2025

Dark-Side-of-AI-WEBThe use of “shadow AI” is an increasing security risk within organizations, according to a new report from Netskope.

Shadow AI is a newer variant of shadow IT, in which employees use unauthorized technology without the knowledge of the IT department. This is generally driven by a desire for increased productivity rather than malicious motives, but employees are often unaware of the risks introduced by unauthorized tools.

“Netskope now tracks over 1,550 distinct genAI SaaS apps, up from 317 in February 2025, with organizations using an average of 15 apps (up from 13),” the report says. “Monthly data uploads to these apps increased from 7.7 GB to 8.2 GB. Enterprises are consolidating around purpose-built tools like Google Gemini and Microsoft Copilot, which saw significant adoption gains. ChatGPT, despite remaining the most popular app (used by 84% of organizations), saw its first enterprise usage decline since 2023.

“Other apps, including Anthropic Claude, Perplexity AI, Grammarly, and Gamma, grew, while Grok entered the top 10 most-used apps, though it remains among the most-blocked, with blockage rates declining as organizations adopt granular controls.”

The researchers note that the use of generative AI platforms will grow as these tools increase in sophistication. Organizations and employees need to learn how to deal with these tools safely.

“GenAI platforms, which are foundational infrastructure tools that enable organizations to build custom AI apps and AI agents, represent the fastest-growing category of shadow AI, given their simplicity and flexibility for users,” Netskope says.

“In the three months ended May 2025, users of these platforms increased by 50%. GenAI platforms expedite direct connection of enterprise data stores to AI applications, with the popularity in usage creating new enterprise data security risks that place added importance on data loss prevention (DLP) and continuous monitoring and awareness.”

AI-powered security awareness training can teach your employees about evolving security risks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 HRM+ platform to strengthen their security culture and reduce human risk.

Netskope has the story.


AI-Powered Security Awareness Training Demo

KnowBe4 AIDA — Artificial Intelligence Defense Agents: a suite of agents that up-levels your approach to human risk management.

AIDA Logo

With AIDA you can:

  • Ensure your SAT is consistent with your organization’s broader security initiatives by aligning with the NIST Phish Scale Framework
  • Dramatically free up your security team's time by reducing how long it takes your admins to create remedial training
  • Improve relationships between your security team and other departments by ensuring users are aligned with security objectives
  • Ensure flexibility in your security budget to invest in other key initiatives by actively managing human risk
  • Maximize the value of your existing security tech stack with AIDA’s seamless integrations

Request A Demo

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/products/aida-demo



Subscribe to Our Blog


Gartner Magic Quadrant




Get the latest insights, trends and security news. Subscribe to CyberheistNews.