57% of workers hide their AI use and the habit starts at school
57%. That is the share of workers who hide their use of artificial intelligence and present machine-made work as their own, according to the global study by KPMG and the University of Melbourne covering more than 48,000 people in 47 countries. Almost half admit using it in ways that breach their own company rules. This is not a technology problem and, in the end, it is not really an honesty problem either. It is learned behaviour, and the place where it is learned has a precise name.
It is learned at school. The EduNext 2026 report by the Look4ward Observatory (Luiss and Intesa Sanpaolo) puts it in a formula worth reading twice, namely that school bans on AI produce a cultural habitus which transfers unchanged into the workplace. The student who has learned to hide does not develop skills of critical use, they develop practices of concealment. And those travel with them to the office.
What shadow AI is
The technical term comes from organisational research. Mario Silic, Dario Silic and Kathrin Kind-Trüller defined it in 2025 in the journal Strategic Change as the unsanctioned use of AI systems outside approved governance frameworks. The study combines a survey of 140 professionals with in-depth interviews of 10 executives, and its most uncomfortable conclusion is that the phenomenon is not a matter of individual discipline but a sociotechnical governance failure. The rules exist, they simply never touch the ground.
The authors call that space a governance drift zone, the gap where formal policies stay on paper while real practice runs somewhere else. The most serious consequence is not the use itself, it is the responsibility gaps that open up in the most delicate functions, such as those handling people and legal matters, where machine-generated content can reach its destination without anyone ever checking it.

The chain that carries a school ban into an organisation. Source EduNext 2026 and Silic et al. 2025.
This is not old shadow IT under a new name
The root is the same and it is eleven years old. In 2014 Mario Silic, with Andrea Back, defined shadow IT in Computers & Security as all hardware, software or any other solutions used by employees inside the organisational ecosystem which have not received any formal IT department approval. The employee installing a file sharing tool because the corporate one was slow was doing shadow IT.
The difference is that shadow IT left traces. An unauthorised application shows up in the network logs, it can be inventoried, it can be blocked. Shadow AI does not. It is generative, opaque and autonomous, so it adds risks the older phenomenon never had, namely personal data leaking into a prompt, algorithmic bias nobody checks, a hallucination presented as fact. Above all it lives inside a conversation, which is a place no firewall can look into.

Same organisational root, risks of a different nature. Source Silic and Back 2014 and Silic et al. 2025.
The numbers show how large the grey zone is. According to the 2024 Work Trend Index by Microsoft and LinkedIn, covering 31,000 people in 31 countries, 78% of those who use AI at work bring their own tools, chosen by themselves and not provided by the organisation. IBM's Cost of a Data Breach 2025 report, run on 600 organisations, adds the bill, namely that 63% of firms have no AI governance policy at all, and where shadow AI is involved in a breach the average cost of the incident rises by roughly 670,000 dollars.
Banning does not reduce use, it reduces visibility
Here comes the point closest to our own work, because it is the one we meet in every classroom. A ban looks like the cautious answer, and it is instead the answer that produces exactly the behaviour it meant to prevent.
On 2 September 2026 the New York City school system, the largest in the United States, introduced a one-year moratorium on student-facing generative AI from pre-kindergarten through eighth grade, close to 600,000 children. Assistive tools, tools for multilingual learners and career readiness programmes remain allowed, and teachers can keep using AI to plan their lessons. It is a serious decision taken for serious reasons, namely protecting human connection and children's curiosity. It is also a large-scale experiment whose outcome we already know from elsewhere, given that in 2023 the same city banned ChatGPT in its schools and reversed course a few months later.
Meanwhile students use it anyway. The Indire national survey presented on 4 September 2026, covering 5,342 lower and upper secondary students, reports that 94% use AI tools, 84% use them to study, 62% say they check answers against other sources and 53% have used a chatbot to talk about personal problems. In the United Kingdom the picture is identical, since the HEPI 2026 survey of 1,054 undergraduates records 95% of users while only 38% are given the tools by their institution.

Real uptake compared with the rules and the training that go with it. Sources Indire 2026, Microsoft and LinkedIn 2024, KPMG and University of Melbourne 2025.
The distance between the first bar and the last one is all the shadow AI you need. It is used almost universally, fewer than half get any training, a written rule exists in four cases out of ten. The space left in between is not empty, it is filled with people deciding on their own and telling nobody.
«If a young person has the shadow AI mindset because at school they were afraid to use it, in the organisation they will be afraid to use it. We end up with a widespread but submerged use that we can neither govern nor put to work.»
Fear is the mechanism, and research confirms it on a small scale too. A 2026 study in Frontiers in Education measured, on a group of Canadian undergraduates, the link between fear of the teacher's judgment and the intention to hide AI use. The two travel together clearly, and those who fear most tend to share only with peers or to say nothing at all. You do not need a whole university to work that out, but it is worth saying, because a set of rules that threatens without teaching is building precisely that fear.
The school that adopts AI in order to govern it
There is a finding in the EduNext report that should give pause to anyone drafting a school AI policy in these weeks. Many teachers do not bring AI into the classroom out of enthusiasm. They bring it in because it is the only way they have to act on a use that is already happening and that nobody is steering. A coordinator at a Rome upper secondary school interviewed in the research puts it this way, namely that the reason it is worth opening up to this possibility is to change the type of use, which must not be delegating the task to the machine, whatever that task is.
Adopting AI in order to govern it rather than to innovate. Put like that it sounds like surrender, and instead it is the most realistic posture we have come across, because it starts from where students actually are and not from where the rulebook wishes they were.
The same body of interviews carries the opposite warning too, namely that imposing use from above does not work either. One interviewee recounts that forcing a tool ended badly, since in the end people did not use it, or used it badly and caused damage, so they stopped. Banning and mandating fail for the same reason, they skip the step where competence is built.
What actually works
Organisational research and school research arrive, from two different directions, at the same conclusion. Silic and colleagues call it the move from restriction to controlled enablement, and they point to four concrete levers. We set them out here translated for a school, but they work identically in a company or a professional practice.

The levers the research points to, translated for the school context. Source Silic et al. 2025, adapted by Retoria.
The tool register is the living list of what is allowed, for which task and with which data. It is the point we most often see missing when we review a school's AI policy, because a school will make a white list binding and then fail to attach it, so the document is unenforceable from day one. Role specific training recognises that teaching, studying and administering carry different risks and therefore need different paths. The periodic review checks how AI is actually being used, not how it was expected to be used. The channel for grey areas gives a teacher or a student a clear way to ask before acting, so that doubt does not get resolved in secret.
To these the EduNext report adds a proposal it calls radical in its simplicity, namely allowing AI tools during assessment and moving the object of assessment from the answer to the process. From memory to judgment. If what you assess is the reasoning, hiding stops being useful, because the advantage disappears.
The order of the steps
Interviews with schools that experimented successfully converge on one sequence, and it is worth respecting. Teachers first, students after. Every successful case documents an initial phase in which teachers used and understood the tools for their own professional work before taking them into the classroom. This is not bureaucratic caution, it is the practical condition for a teacher to exercise professional autonomy over a tool instead of being subjected to it.
Right after that comes the piece public policy keeps forgetting. A great deal is invested in training teachers and very little in training students as informed users. A teacher interviewed in the report says it in a way that leaves no room for manoeuvre.
«We cannot leave young people alone with these tools and hope they learn to use them by themselves.»
There is one last reason, and it concerns wellbeing before it concerns teaching. The fact that more than half of Italian students have used a chatbot to talk about personal matters has to be read together with the fact that these systems tend to always agree with you. A young person left alone in front of a tool that never contradicts them is not learning to think, and a ban that pushes them to use it in secret leaves them exactly there, alone.
What the law actually asks for
Anyone worried that enabling means lowering the guard can relax, because the legal framework points the same way. The guidelines of the Italian Ministry of Education and Merit, annexed to ministerial decree no. 166 of 9 August 2025, ask schools to act as informed deployers of AI systems, namely involving the data protection officer in assessing new tools, choosing suppliers with verifiable guarantees and updating privacy notices. Italian law 132 of 23 September 2025, article 4 paragraph 4, requires the consent of those exercising parental responsibility for AI access by children under fourteen. And article 4 of the European AI Act, in force since 2 February 2025, requires a sufficient level of AI literacy from those who put these tools into people's hands.
None of these rules says to ban. All of them ask you to know what you are doing, which is the exact opposite of submerged use.
The bill we pay later
Back to the 57% we started with. That number does not describe dishonest workers, it describes an education system that for years answered a new technology with the only instrument it already had to hand, the ban. The result is a whole generation that knows how to use AI and cannot say so, and an organisation that can neither govern nor put to work what it cannot see.
The cost is paid twice. Once at school, as learning that does not happen because the delegation stays invisible and nobody corrects it. Once at work, as risk that nobody is watching. In between there is a habit that could have been taught differently, and this is why training is not a compliance box but the real safety measure.
If your school or your organisation is drafting its AI policy right now, or suspects that real use is far wider than declared use, write to us for an AI readiness assessment. You can also discover the Retoria method, or read why studying with AI can make you learn less and why value is shifting from memory to judgment.
Methodological note
This article is not legal advice. The figures on shadow AI in organisations come from Silic, Silic and Kind-Trüller (2025), a mixed-methods study based on a survey of 140 professionals and 10 executive interviews, so the results should be read as exploratory and not as estimates representative of a population. The percentages on hiding AI use come from the KPMG and University of Melbourne study run between November 2024 and January 2025 on more than 48,000 people in 47 countries, and they are self-reported. The 78% figure on own tools brought to work comes from the 2024 Work Trend Index by Microsoft and LinkedIn, covering 31,000 people in 31 countries. The breach cost figures come from the 2025 IBM and Ponemon Institute report on 600 organisations and describe an association between shadow AI and average incident cost, not a demonstrated cause and effect. The Italian student data come from the Indire survey of 5,342 students collected between March and June 2026 and presented on 4 September 2026. Quotations from executives and teachers are anonymised and come from the interview corpus of the EduNext 2026 report, chapters 2.2 and 5. The study on fear of judgment and concealment (Frontiers in Education, 2026) has a small sample, namely 78 undergraduates at a single Canadian university, and should be read as an indication rather than a generalisable measure.
Sources
- Silic, M., Silic, D. & Kind-Trüller, K. (2025). From Shadow IT to Shadow AI – Threats, Risks and Opportunities for Organizations. Strategic Change.
- Silic, M. & Back, A. (2014). Shadow IT – A view from behind the curtain. Computers & Security, 45, 274-283.
- Osservatorio Look4ward, Luiss Research Center for Strategic Change "Franco Fontana" & Intesa Sanpaolo (2026). EDUNext: Nuovi scenari per l'Education e le competenze nell'era dell'IA (CC BY 4.0).
- KPMG & University of Melbourne — Trust, attitudes and use of artificial intelligence, a global study (2025).
- Microsoft & LinkedIn — 2024 Work Trend Index Annual Report (2024).
- IBM & Ponemon Institute — Cost of a Data Breach Report 2025.
- Indire — National survey on students' use of artificial intelligence (2026).
- HEPI — Student Generative AI Survey 2026.
- Chang, D. H., Lin, M. P.-C., Huang, J.-Y. & Ryoo, J. (2026). Should I tell my teacher? Student AI disclosure practices, stigma, and self-regulated learning in higher education. Frontiers in Education.
- New York City Public Schools — Generative AI moratorium, 2 September 2026.
- Italian Ministry of Education and Merit — Guidelines for the introduction of Artificial Intelligence in schools, annexed to ministerial decree no. 166 of 9 August 2025.
- Bourdieu, P. (1990). The Logic of Practice. Stanford University Press.