Shadow IT in hybrid work isn’t disappearing. Honestly, it’s getting worse. Most of the time, though, the issue isn’t that employees actively want to sabotage companies, opening back doors for hackers through unsanctioned tools. They’re just sick of being banned from the solutions they prefer.
Shadow IT isn’t about saboteurs. It’s about smart, capable people trying to do their jobs in ways that feel faster, simpler, or more familiar than the tools IT handed them. In hybrid setups, where policies are fuzzy, helpdesks are remote, and time is short, that instinct gets amplified.
According to one report, over 50 percent of the apps used in the enterprise are unsanctioned. It’s more than team members using WhatsApp instead of Slack, or Google Workspace instead of Microsoft Teams these days.
One Fortune 500 financial services firm revealed that over 60 percent of the sales team routinely fed client meeting recordings into unsanctioned AI tools. That’s a problem for consistency, cohesion, and compliance. The only way to fix it? Start making secure work the path of least resistance.
What Shadow IT in Hybrid Work Really Costs Enterprises
It’s tempting to think of shadow IT as a minor nuisance. A few duplicate tools, an app subscription here or there. But that’s the same logic that let Zoom spread like wildfire during the pandemic, right under the noses of IT teams who were still trying to get Skype working.
Shadow IT in hybrid work costs you money, time, security, compliance, and often your employees’ trust. The results?
Higher Costs, More Waste
Around 53 percent of the apps and tools companies pay for go unutilized, because employees just use the solutions they prefer instead. Sales teams stick to their own CRMs; project teams use a handful of different productivity apps, most with overlapping features.
This isn’t just “waste.” It’s fragmentation, disconnected workflows, and data living in places you can’t see or secure.
Security Gaps Multiply Fast
Most shadow tools bypass SSO. They live outside your endpoint protection, and they’re not built with enterprise-grade security. You’ve got users uploading sensitive files into tools that don’t meet your minimum compliance standards, often without realizing it. Many even end up using the same credentials across multiple platforms, increasing your attack surface.
Compliance Issues Add Up
If you work in government, law, or healthcare, you know how strict GDPR, HIPAA, and public sector procurement rules can be. Now, imagine a breach traced back to an app IT never approved. Regulators won’t care that it was “just a PDF tool” or “a productivity hack.” They’ll ask why your governance didn’t account for it.
AI Has Supercharged the Problem
A year ago, “Shadow IT” mostly meant rogue SaaS. Today, it includes AI tools that absorb sensitive context without offering any guardrails. According to one report, around half of all knowledge workers use personal AI tools (without telling their IT teams). Most say they wouldn’t stop either, even if the tool was banned.
Why Shadow IT in Hybrid Work Is a Cultural Problem
Shadow IT in hybrid work is rarely about rebellion. It’s about friction.
When people bypass IT tools, they’re not usually trying to break rules; they’re trying to bypass inefficiency. Tools feel clunky. Procurement takes months. Training is unclear. When your meeting starts in 90 seconds, Outlook’s broken, and you just need to share a file, you find a workaround.
Platforms like Slack, Notion, Trello, Grammarly, ChatGPT, and Google Forms? These aren’t evil tools. They’re frictionless. That’s the point. People go around IT because consumer-grade UX beats enterprise red tape every time.
Shadow IT is an indicator of where the business is failing to meet the needs of its people.
This is especially true in high-regulation, high-pressure sectors like healthcare, law, and government. When a clinician needs to update patient notes across three platforms, none of which talk to each other, they’re going to open Notepad or WhatsApp a colleague because the actual sanctioned route is exhausting.
What’s more, remote and hybrid models have diluted team accountability. There’s less peer oversight. Less “is this okay to use?” questioning. Everyone’s making do. Which is precisely how data leaks happen.
How to Regain Control of Shadow IT in Hybrid Work
Managing shadow IT isn’t as easy as just being more aggressive about punishing people who use unsanctioned tools or blocking access to certain apps. Most companies need to rebuild their tech stack with a user-centric approach. Here’s how to begin.
Discover the Shadow Stack
You can’t fix an issue you can’t see. Sending out anonymous user surveys asking teams to tell you what they’re using will only work so well. Fortunately, some tools can help shine a light on your tech stack.




