A contract needs a quick summary before a 3 p.m. call. The person who has it open doesn't have time to route it through IT-approved channels, so it goes into a consumer AI tool instead. It's summarized in seconds, and the tab closes. It certainly doesn't seem like a security event, just the quickest way to get the job done.
Multiply that moment across a workforce, and it becomes a pattern that Nitro's new research set out to measure directly. The State of AI in Document Workflows: Navigating the Gap Between AI Promises and Productivity surveyed 1,300 enterprise leaders across the US, UK, and Canada, and asked a pointed question: are sensitive documents genuinely protected from unmanaged AI tools, or does it just look that way from the top?
Nitro has measured shadow AI before: our earlier report on enterprise AI adoption and reality found 68% of executives and 50% of employees were already using unapproved AI tools, with one in three employees having processed confidential data through unvetted AI platforms. That report framed the underlying cause as a usability gap: consumer AI was often the fastest option within reach, and the fastest option tended to win. Our latest research picks up the same story at the document layer to discover that not only is the pattern is still there, but there's now a sharper view of where in the workday the exposure sits, and how far governance has slipped behind the behavior it's meant to control.
AI document security concern runs highest in the C-suite
Worry about AI and sensitive documents is heaviest at the top of the organization. Fifty-six percent of executives say their organization's leadership is very or extremely concerned about the security risks of employees processing sensitive documents through AI tools. Among managers, asked about their organization's concern more broadly, 37% say the same. The two survey questions were framed slightly differently, so the gap doesn't read as a strict like-for-like, but both figures point to a real, elevated level of concern, weighted toward the top of the organization.
AI governance breaks down below the executive level
Concern at that level would usually be expected to produce enforced rules. That hasn't consistently happened. Seventy-one percent of executives report a clear, actively enforced policy governing how employees use AI on confidential documents. Among managers, the number drops to 43%, with 57% describing their organization's policy as inconsistent, still in development, absent, or something they're not sure about.
Two groups inside the same organization are describing two different governance environments: at the leadership level, the rules are broadly in place, while at the manager level, more than half of the people responsible for enforcing those rules day to day aren't confident that's true.
Employees are sending sensitive documents to consumer AI tools
Policy or no policy, the behavior hasn't shifted. Seventy-four percent of executives confirm that employees have used consumer AI tools like ChatGPT, Claude, or Gemini on sensitive or confidential documents, with 41% saying it happens regularly. Fifty-five percent of managers say the same, with 27% calling it routine.
A related number makes the exposure concrete. Forty-four percent of managers report, personally or through direct knowledge of their team, that work documents have been uploaded to free online tools without anyone checking who runs the site. Add in managers who think it's probably happened but aren't concerned, and the figure climbs to 56%. That translates to something specific: a contract, a claims file, or a patient record sitting on a server nobody vetted. For more than half of managers surveyed, that's either already happened or is probably happening in their department right now.
Shadow AI enters through standalone document tools
To understand where the risk originates, it helps to look at how AI is reaching employees in the first place. Elsewhere in the report, more than a third of departments using AI in document workflows say they rely on standalone AI tools running alongside their existing document software rather than anything built into it. When someone needs to summarize a contract before a 3 p.m. call, the fastest available option usually wins, and a public chatbot is often the fastest option within reach.
That's the practical shape of shadow AI inside a document stack: sensitive documents living in one system, and the AI tools employees actually reach for governed somewhere else, if at all. Closing the gap starts with making the compliant path the convenient one, so the fastest tool within reach is also the approved one.
Read the full findings in The State of AI in Document Workflows.