WalkMe Report: 45% of Professionals Use Unsanctioned AI Tools, Raising EU AI Act Compliance Risks

·
·
3 min read
·
AI-assisted
Author Profile
by Albert SchaperUpdated: Sep 9, 2026
Share
WalkMe Report: 45% of Professionals Use Unsanctioned AI Tools, Raising EU AI Act Compliance Risks

A global survey by WalkMe reveals that 45% of professionals used unsanctioned "shadow AI" tools in the past 30 days, with 36% inputting confidential company data into these services, posing significant governance and data leakage risks for organizations. For broader context, explore our AI News. For broader context, explore our Top 100 AI Tools.

The Rise of Shadow AI in the Workplace

The term "shadow AI" refers to the use of artificial intelligence tools by employees without official company approval or oversight. WalkMe's research, based on a survey of 3,750 professionals globally, indicates that this phenomenon is not primarily driven by malicious intent. Instead, it often stems from employees finding sanctioned internal tools difficult to use or inadequate for their specific workflows. This gap in usability and functionality pushes professionals to seek external, unvetted AI solutions to enhance productivity.

Data Security and Regulatory Risks

The practice of using unsanctioned AI tools, particularly when handling sensitive information, creates considerable data security vulnerabilities. The survey found that 36% of professionals have entered confidential data into these services, exposing companies to potential data breaches and intellectual property loss. Furthermore, only 21% of professionals reported receiving warnings about their employer's AI policies, indicating a significant lack of awareness and communication regarding acceptable AI use.

These risks are compounded by evolving regulatory landscapes. The updated EU AI Act, for instance, includes provisions that can impose severe fines for non-compliance. Organizations found in violation could face penalties of up to €15 million or 3% of their global annual turnover, underscoring the financial and reputational stakes involved in managing shadow AI.

Organizational Responses to Shadow AI

In response to these challenges, some companies are actively developing strategies to mitigate the risks associated with shadow AI. Financial institutions like Chase and technology providers such as Thomson Reuters are reportedly building sanctioned AI channels. The goal is to provide employees with approved, secure AI tools that meet their needs, thereby preventing the routing of company intellectual property to unvetted third-party services. Gill Haus of Chase and Kirsty Roth of Thomson Reuters have been noted in discussions surrounding these efforts.

Tal Carmi, a figure associated with WalkMe's research, emphasizes the need for organizations to understand why employees turn to shadow AI and to address those underlying needs with better internal solutions and clearer policies.

Addressing the Challenge: Policy and Usability

Effectively managing shadow AI requires a two-pronged approach: establishing clear policies and ensuring the usability of sanctioned tools. Companies must clearly communicate their AI usage guidelines and provide training to ensure employees understand the risks and approved practices. Simultaneously, investing in user-friendly, officially sanctioned AI tools that integrate seamlessly into existing workflows can reduce the incentive for employees to seek external alternatives. This approach can help organizations maintain control over their data while still leveraging the benefits of AI for productivity.

Conclusion

The prevalence of shadow AI, with 45% of professionals using unsanctioned tools, presents a critical challenge for organizations regarding data security and regulatory compliance. As the EU AI Act introduces significant penalties, companies must prioritize both robust AI governance policies and the provision of effective, user-friendly internal AI solutions. Addressing the root causes of shadow AI — often related to tool usability and workflow integration, will be key to safeguarding confidential data and avoiding substantial fines in the evolving digital landscape.

Sources

About the Author

Albert Schaper avatar

Written by

Albert Schaper

Albert Schaper is a co-founder of Best-AI.org. He focuses on product strategy, AI adoption, practical tool selection, and educational content that helps users compare AI products with clearer context.

More from Albert

Was this article helpful?

Found outdated info or have suggestions? Send us a note.

Discover more insights and stay updated with related articles

Discover AI Tools

Find your perfect AI solution from our curated directory of top-rated tools

Less noise. More results.

One monthly email with the industry news tools that matter - and why.

No spam. Unsubscribe anytime. We never sell your data. See our Privacy Policy.

What's Next?

Continue your AI journey with our tools and resources. Whether you're looking to compare AI tools, learn about artificial intelligence fundamentals, or stay updated with the latest AI news and trends, see what fits your needs. Explore our curated content to find the right AI tools for your workflow.