19/03/2026
In March 2025, ChatGPT became the most downloaded app in the world. It was the first time in twelve years that the download ranking was not led by a social networking application. Specifically, it had not happened since 2013, when the Candy Crush game led this ranking.
In that month alone, the app registered 46 million downloads. Today, although there are no official figures, specialized websites put the number of weekly active users of ChatGPT at 800 million, a number that has been growing exponentially since its launch in November 2022.

Today, the massive adoption of this and other similar tools (Google Gemini was the sixth most downloaded app in Spain in September 2025) opens up a range of possibilities for users, insofar as they serve as a gateway to generative artificial intelligence, but also poses serious problems for companies and organizations. This is known as Shadow IA.
It consists of the unauthorized use of IAG tools by employees. Although institutions implement security policies to protect their documents, many employees install the ChatGPT app (or similar) on their cell phones and use it secretly, with the risks that this entails.

Image created with AI
According to the report Cloud and Threat Report: Shadow AI and AI with Agents 2025. According to Netskope, 89% of companies use at least one generative AI application, often without formal approval. The same source reveals that the number of users interacting with these tools has increased by more than 50% in recent months.
Even more revealing is the MIT report State of AI in Business 2025. Although 40 % of the companies surveyed have purchased licenses for generative AI solutions, more than 90 % of them use AI tools with personal accounts, in more than 90 % of them, employees use AI tools with personal accounts.
Cisco’s findings confirm this lack of oversight. Their report 2025 Cybersecurity Readiness Index highlights that 60% of companies are unable to monitor prompts or requests made by their employees in generative AI tools, and the same percentage acknowledge that they lack the ability to detect the use of unapproved AI tools in their environments.
8.2 GB per month per company
A very relevant fact clarifies the magnitude of the problem. Companies share, on average, 8.2 GB of information per month with generative artificial intelligence models. Nothing more productive when the documents are public and of general interest, but what happens When it comes to confidential documents that may jeopardize a company’s privacy or competitiveness?
The greatest danger of Shadow AI lies in its lack of visibility and governance. When an unauthorized AI tool accesses sensitive information – such as strategic documents, credentials, customer data or internal algorithms – that information can be processed on external servers, stored, shared or even reused for model training, leaving a trail that the company no longer controls.

In addition, this practice exponentially increases the risks of data leakage. Tools without corporate controls do not guarantee encryption or compliance with standards such as the General Data Protection Regulation (GDPR) or the new European regulations on AI (AI Act), which can result in million-dollar penalties and loss of trust from customers and suppliers.
Another critical issue is the quality of decision making: unaudited AI models can produce results that are biased, erroneous or incompatible with internal policies, affecting everything from financial analysis to public communications.
Spain and the risk of governance
In the Spanish context, Shadow AI is particularly relevant due to the combination of rapid digital adoption and a demanding regulatory environment. Many Spanish companies still lack clear frameworks to manage the use of AI, creating compliance and security gaps in sectors as diverse as finance, healthcare or public administration.
In particular, and according to data collected in the report Artificial Intelligence and Cybersecurity prepared by DigitalES and presented last December, only 5% of organizations in Spain are prepared to deal with AI securely.
Cyberattacks targeting AI models have increased fivefold in the last year, reinforcing the need to integrate cybersecurity and governance by design (security by design); the role of training and organizational culture as the first line of defense; and the importance of clear frameworks, standards and best practices for responsible implementation.
In addition, the proximity of legislative frameworks such as the European AI Act means that companies in Spain must take special care to document, audit and monitor any AI-based tools. The absence of these measures not only increases the risk of fines for non-compliance, but can also trigger litigation or lawsuits for personal data leakage.
At the end of the day, and this is important to note, AI cybersecurity is not just an extension of traditional security: it also involves issues of human rights, bias, social impact and protection of the individual.It also involves issues of human rights, bias, social impact and protection of the individual.
How to combat Shadow AI in 2026
Combating Shadow AI requires a strategic rather than a purely technical approach. Among the practices recommended by specialists are:
- Visibility and continuous auditing: establish automatic mechanisms to identify any AI tools in use within the corporate network.
- Clear usage policies: define what types of AI are allowed, under what conditions and with what security controls.
- Education and awareness: Train employees on the risks of unauthorized AI and its impact on the company.
- Secure corporate tools: Provide validated corporate AI alternatives with data protection and compliance mechanisms.
Shadow AI is not going to disappear by decree. But if companies manage it proactively, they can transform this risk into an opportunity to consolidate AI governance that drives secure and sustainable innovation in 2026 and all the years to come.









