Shadow AI is the use of artificial-intelligence tools for work without an organization’s approval or governance. ITPro reported in January 2025 that Harness’ State of Software Delivery Report found 52% of developers said they did not use IT-approved tools. That is a warning about visibility and controls—not proof that 52% leaked code or caused security incidents.
What does the 52% developer figure actually say?
In a 17 January 2025 article, ITPro reported Harness’ finding that 52% of developers “don’t use IT-approved tools.” The inspected article does not provide the survey sample, field dates, or a detailed definition of “IT-approved,” and the underlying Harness report’s full methodology is not established here. Treat the figure as a reported survey result in that context, not a current universal rate or a precise measure of unauthorized AI use.
The distinction matters: an unapproved tool is not necessarily an AI tool used to process sensitive information, and using an AI coding tool is not automatically unauthorized. Approval can depend on the organization’s policy, the tool’s account and configuration, the data involved, and the task.
How widespread is AI coding—and how is that different from shadow AI?
Two older adoption figures illustrate why general use should not be confused with unapproved use. Georgetown’s Center for Security and Emerging Technology (CSET) cited a June 2023 survey in which 92% of surveyed U.S.-based developers said they used AI coding tools in or out of work. CSET also cited a November 2023 industry survey in which 96% of surveyed developers reported using such tools, with more than half using them most of the time; the cited passage does not identify the original survey publisher. Neither statistic measures whether use was approved.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
Separate, broader evidence suggests approval gaps are not limited to developers. In its 2026 report, Okta said 52% of surveyed knowledge workers used AI tools at work without approval, and 24% said they did so regularly. The population is knowledge workers, not software developers alone, so this result cannot confirm or replace Harness’ developer-specific figure.
Why do developers turn to tools that may not be approved?
In Okta’s 2026 survey, among respondents who used unapproved AI, 80% said using their own account because it was easier was a reason. Respondents also cited team norms (78%), slow or difficult approval (57%), and approved tools that did not meet their needs (49%). These answers point to convenience, workplace culture, and access friction as issues governance has to address; they do not show that any single policy change will resolve unapproved use.
For development teams, the practical question is whether staff can obtain a suitable tool and a timely decision through an approved route. If the approved option is hard to access or fails to support real work, policy alone may not make unofficial alternatives disappear.
What risks can unapproved AI create for software teams?
Code and confidential data may cross boundaries
ITPro’s account of the Harness report identifies exposure of sensitive code snippets to third-party services as a concern. Whether a service retains prompts, how it uses submitted data, and what contractual or technical protections apply are tool- and configuration-specific questions. The risk is a potential exposure pathway, not evidence that every developer using an unapproved service has leaked code.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
Okta’s 2026 report offers broader context on data handling: among workers using unapproved AI, respondents said they had shared internal messages or emails (54%), HR-related information (45%), and confidential company documents (39%). These are self-reported behaviors in that survey subgroup, not breach rates, and they do not describe developers alone.
Generated code still needs security and quality review
CSET explains that code-generation systems can produce insecure code. If teams incorporate that output without appropriate review, vulnerabilities can enter products; insecure code may also make its way into open-source repositories and contribute to downstream software supply-chain risk. AI tools can also assist with productivity, vulnerability discovery, and patching, so the relevant control is disciplined use and review—not an assumption that all AI-generated code is unsafe.
Rank #4
Weak provenance and inconsistent rules make incidents harder to manage
ITPro’s summary of Harness points to a lack of governance, difficulty tracing generated code’s origin, and inconsistent security standards. When teams cannot tell which tool produced a change or under what rules it was used, investigating a defect or vulnerability can be harder. These are governance and traceability concerns, not proof that a particular incident has occurred.
No incident count or causal estimate for security events arising specifically from the developer behavior in the headline is established by the cited evidence. Survey responses about tool use and data sharing should not be read as a tally of confirmed incidents.
Recommended Free Tools
Best Value
What should a company’s AI coding policy cover?
A useful policy should make safe, approved work practical while preserving visibility and review. ITPro reported that three-fifths of engineering leaders in the Harness report said organizations need policies prescribing processes for assessing code for vulnerabilities or errors; 58% said policies should outline specific use cases where AI is safe or unsafe. Those reported views underscore the value of concrete rules rather than a blanket statement that AI is allowed or prohibited.
- Visibility: Identify which AI tools and account types are permitted, and establish how the organization can understand what tools are being used.
- Data and access boundaries: State what code, confidential information, repositories, and systems may be supplied to a tool, and limit tool access to what its approved task requires.
- Approved use cases: Give developers examples of permitted and restricted work, such as which coding tasks are acceptable and which data or production systems are off limits.
- Code review: Require generated changes to follow the organization’s usual checks for correctness, security vulnerabilities, and licensing. AI-generated output should not bypass review simply because it appears plausible.
- Developer access and approval: Offer a workable way to request tools or exceptions, with a decision process that does not create avoidable delays.
- Training and accountability: Explain the policy in practical terms, train staff to recognize sensitive data and risky output, and apply the rules consistently.
How should developers use AI coding tools responsibly?
- Check approval before using a tool for work. Confirm that both the tool and the account or configuration are permitted for the task; a personal account may not have the same protections as an approved work service.
- Keep sensitive material out unless explicitly permitted. Follow company rules for source code, credentials, customer information, internal communications, and other confidential data.
- Review generated code as code. Verify behavior, test it, and use the same security and quality checks required for human-written changes. Do not treat an AI response as evidence that a change is correct or safe.
- Preserve traceability. Follow team practices for documenting AI assistance where required, so reviewers can understand and assess the change.
- Raise unmet needs through an approved channel. If sanctioned tools do not support the work, request a review or an alternative rather than quietly moving data to an unapproved service.
What the evidence supports—and what it does not
The evidence supports a measured conclusion: AI coding is broadly used, and surveys indicate that some workers use AI without approval. For software organizations, the resulting concerns include data boundaries, code review, traceability, and governance. The cited figures do not establish that all unapproved use is unsafe, that a specific share of developers exposed sensitive code, or how many real security incidents have resulted.
Harness’ 52% figure is secondary reporting by ITPro, and its inspected article does not provide detailed methodology. The 2023 CSET-cited figures concern general adoption, while Okta’s 2026 findings cover knowledge workers broadly. Keeping those populations and measures separate is essential to interpreting the numbers accurately.
Quick Recap
Sources
- ITPro: Harness finding and reported developer-governance concerns
- Georgetown CSET: Cybersecurity Risks of AI-Generated Code
- Okta: 2026 report on AI use at work
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors




