Allowed but Not Provided: Where Shadow AI Actually Starts
Published on 9/17/2026 · Sven Maier
The debate about shadow AI in companies usually revolves around bans. That misses the problem. Bans are rare: only 4 percent of companies in the information economy and 8 percent in manufacturing fully prohibit the use of generative AI (Source: ZEW, Information Economy Sector Report, 2026). The interesting finding sits next to it.
Discuss your next step in a free diagnosis call. Book a slot →
Contents
- The ban is not the problem
- The gap: allowed but not provided
- What happens inside that gap
- Four things that must accompany permission
- Why this is enablement, not IT
- Conclusion: whoever allows must provide
- Frequently asked questions about shadow AI
- Sources
The ban is not the problem
Following the debate about AI use at work, one might conclude that companies face a choice between prohibition and loss of control. The data tells a different story.
In March and April 2026, ZEW surveyed around 1,500 companies from the information economy and manufacturing. Full bans are the exception: 4 percent in the information economy, 8 percent in manufacturing (Source: ZEW, 2026).
So the prohibition debate describes an edge case. The actual risk sits in the middle of the distribution.
The gap: allowed but not provided
It gets interesting once permission and provision are examined separately. ZEW does just that and finds four states.
In the information economy, 58 percent of companies actively provide generative AI to their staff. In manufacturing it is 30 percent (Source: ZEW, 2026).
The remainder splits across three states, two of which are problematic. 16 percent in the information economy and 23 percent in manufacturing explicitly permit use without providing an application. A further 22 and 39 percent respectively tolerate use without clear guidance (Source: ZEW, 2026).
Added together, this means that in manufacturing, 62 percent of companies have AI in use, or permitted, without supplying a tool for it.
Permission without a tool is not governance. It delegates the risk to the workforce.
What happens inside that gap
“Allowed but not provided” sounds like freedom. In practice it produces three predictable consequences.
- Personal accounts take over. Someone expected to work faster, with no company tool available, uses their own. At that moment the task leaves the company’s contractual perimeter.
- Copy-paste becomes a data path. Tender documents, quotation calculations, customer correspondence and design specifications travel through the clipboard into systems whose processing terms nobody has reviewed.
- Nobody knows what is running. Without provided access there is no usage data. What is missing is control, and with it any basis for evaluation.
The contradiction behind this is notable. Data protection concerns are among the most common reasons for not using AI at all: 60 percent of companies without AI cite them (Source: Destatis, 2025). Yet at other companies the same concern leads not to secure provision but to no provision. The result is higher risk, not lower.
Four things that must accompany permission
The way out is not a twelve-page policy. Four decisions are enough, and they can be made in days.
- A named account. One company account per person, billed through the company’s contract. This is the only item that costs money, and the only one that actually closes the grey zone.
- Data classes instead of prohibition lists. Which data may enter an AI system, which may not? Three classes suffice: non-critical, internal, confidential. Without this split, every individual decides alone.
- A short list of approved tools. Two or three applications, not twenty. Short lists get read, long ones get ignored.
- A named contact person. Someone to ask before uploading something. Without that address, people do not ask. They act.
These four cost less effort than the debate about whether to permit AI at all. How to set up data flows cleanly is described in the article on AI and data protection.
Why this is enablement, not IT
The gap is often handed to IT. That falls short, because IT answers the wrong question.
IT can create accounts, review contracts and secure data flows. What it cannot do is decide which workflow in sales or engineering actually needs AI support. That decision belongs in the business unit.
So provision is an enablement task. It covers three things beyond technical access: a concrete use case per team, practice on a real transaction, and named accountability for the results.
That is how we build: with the team, not for the team. Why this is a question of acceptance rather than attitude is described in Built with the Team. How decision rights can be graduated is covered in Governance, Control, Autonomy.
Which workflows need provided access first is something we map out in the free diagnosis call.
Conclusion: whoever allows must provide
The ZEW figures clear up a misconception. Companies barely ban AI. They permit it and supply nothing.
That is the worst of the three possible states. A ban is at least a decision people can align to. Provision is a decision with a tool attached. Permission without a tool is neither: it pushes the decision about data paths onto every individual in the company.
The effort to change this is modest: one account, three data classes, a short tool list, one name. With those in place, shadow AI stops being a topic.
Frequently asked questions about shadow AI
What is shadow AI?
The use of AI tools at work without provided, company-managed access, usually through personal accounts. It arises from a lack of alternatives, not from bad intent.
How many companies ban AI?
Very few. 4 percent in the information economy and 8 percent in manufacturing fully prohibit the use of generative AI (Source: ZEW, 2026).
So where does shadow AI come from?
From the gap between allowing and providing. 16 percent of companies in the information economy and 23 percent in manufacturing explicitly permit use but provide no application. A further 22 and 39 percent tolerate it without clear guidance (Source: ZEW, 2026).
Is a policy enough?
No. A policy without provided access describes behaviour that is not possible in daily work. Access is what makes the rule followable.
What is the fastest first step?
A named company account for the people already using AI, plus three data classes and a contact person. Which workflows come first is something we clarify in the free diagnosis call.
Sources
- ZEW, 2026: Information Economy Sector Report, May 2026 (survey March/April 2026, around 1,500 companies)
- ZEW, 2026: Hardly Any Companies Forbid the Use of AI, 8 June 2026
- Federal Statistical Office (Destatis), 2025: Use of ICT in enterprises: reasons for not using AI, 2025 survey
How this article was produced
- Topic selection
- Source selection
- Fact-checking
- Approval
- Research
- Drafting
- Diagrams
- Publishing
This article was produced with AI support. Ideation, editorial planning, substantive review and approval rest with a human; copy-editing sits with the AI. Editorial responsibility is held by Sven Maier.
What's next
Assess AI potential
In 5 minutes: a concrete assessment of where the company stands with AI.
Start the Self-Check →Digital Impact straight to your inbox
One sign-up, three newsletters: the AI Insights Newsletter every week with the latest insights articles, the Digital Impact Longread Newsletter and the Digital Impact Update once a month each. Double opt-in, unsubscribe anytime.
AI Operations as a podcast
Experts including André Hellmann, Christina D'Ilio, Christian Sattel, Sarah Stock and regular guests from practice: all AI Operations topics as audio for on the go.
Assess the company's AI potential in 5 minutes
Start the Self-Check →Discuss the next step with an expert
Book a call →