Shadow AI use is widespread in healthcare as staff seek faster workflows, survey finds

57% of healthcare professionals have encountered or used unauthorized AI at work, with nearly 20% admitting personal use.

Categorized in: AI News Healthcare
Published on: Sep 16, 2026
Shadow AI use is widespread in healthcare as staff seek faster workflows, survey finds

More than half of healthcare professionals have encountered or used unauthorized AI tools at work, according to a January 2026 Wolters Kluwer Health survey of over 500 clinicians and administrators. That gap between workforce behavior and IT oversight introduces direct risks to patient safety, data privacy, and regulatory compliance - and it signals an urgent need for governance rather than outright bans.

The survey found that 57% of respondents had personally used or witnessed shadow AI in their organizations. Nearly 20% admitted to using an unsanctioned tool themselves, and more than 40% were aware of colleagues doing so. These figures track with broader trends: Microsoft's 2025 Work Trend Index reported that 78% of AI users bring their own tools to work outside IT approval, and UpGuard's State of Shadow AI Report found that more than 80% of workers use unapproved AI, with a quarter considering AI their most trusted source of information.

Why healthcare workers turn to unapproved AI

The motivations are practical, not reckless. Over 50% of administrators and 45% of providers cited faster workflows. Nearly 40% of administrators and 27% of providers pointed to better functionality or the absence of approved alternatives. Another 26% of providers said simple curiosity and experimentation drove their use. In short, shadow AI fills a vacuum left by organizations that have not yet provided governed, fit-for-purpose tools.

Employees are using these tools for documentation, literature reviews, coding assistance, and administrative tasks - work that consumes hours of clinical time. When the sanctioned toolkit offers no relief, staff will find their own solutions. The behavior is a signal about unmet needs, not a discipline problem.

The patient safety and compliance stakes

ECRI named misuse of AI chatbots the number one health technology hazard for 2026, ahead of cybersecurity threats and surgical device failures. Its analysis documented chatbots suggesting incorrect diagnoses, recommending unnecessary testing, promoting subpar medical supplies, and inventing body parts - all while sounding authoritative. These are not regulated medical devices and have not been validated for clinical use.

Specific risks multiply quickly. Staff entering protected health information into consumer-grade AI tools without a signed Business Associate Agreement creates clear HIPAA violations, regardless of intent. AI hallucinations - confidently stated but factually wrong outputs - can influence clinical decisions. Data breach exposure occurs when sensitive information leaves organizational control and enters third-party systems with unknown retention and security practices. Bias in AI outputs may disproportionately harm vulnerable patient populations, and the "black box" problem of opaque decision-making undermines clinical accountability.

Governance, not prohibition

Banning AI outright will push usage further underground, increasing risk while forfeiting real productivity gains. The alternative is governed adoption - channeling workforce demand into safe, compliant pathways. A practical roadmap starts with a non-punitive inventory. Amnesty-style surveys and confidential interviews surface the true landscape of shadow AI and identify the unmet needs driving it. Frame this as a learning exercise, not a disciplinary one.

Organizations need a multidisciplinary AI governance committee with perspectives from clinical leadership, IT, compliance, legal, privacy, and frontline staff. That committee should own the ongoing process of evaluating, approving, and monitoring AI tools. Clear, accessible policies must tell staff which tools are approved, which uses are prohibited - such as entering PHI into consumer chatbots - and how to request evaluation of new tools. Complexity and ambiguity are the enemies of compliance.

Providing sanctioned alternatives is the most direct risk mitigation. If staff turn to shadow AI for documentation or coding help, give them BAA-covered, vetted tools that actually work. Remove the incentive for workarounds. Legal counsel should be involved early in procurement to address data ownership, security obligations, BAA requirements, liability allocation, and what happens to organizational data when the contract ends. Pay particular attention to whether vendor data is used to train models.

Training programs must explicitly address shadow AI. HIPAA's Security Rule already requires security awareness training for all workforce members. Update those programs to cover the consequences of entering PHI into unapproved systems, the limits of AI-generated clinical information, and the process for reporting and requesting AI tools. Technical guardrails - network-level controls, data loss prevention tools, endpoint monitoring - can detect and prevent unauthorized access. HHS's proposed strengthened HIPAA Security Rule includes mandatory asset inventories and network mapping requirements directly relevant to shadow AI identification.

Organizations can accelerate their efforts by aligning with emerging frameworks. The Joint Commission's Responsible Use of AI in Healthcare framework and the Coalition for Health AI governance playbooks, both released in May 2026, provide structured approaches. The NIST AI Risk Management Framework offers a technology-agnostic structure for identifying and mitigating AI-related risks. Governance must be treated as ongoing - a policy written today may be outdated in six months. Build review cycles, incident response processes, and feedback loops from the start.

Why this matters for healthcare professionals

Shadow AI is not a future problem - it is already inside your organization. The Wolters Kluwer data makes that unambiguous. For clinical staff, the immediate takeaway is that entering PHI into an unapproved chatbot is a regulatory breach with personal and institutional consequences, no matter how helpful the tool seems. For administrators and IT leaders, the workforce is sending a clear signal about where approved tools fall short. Organizations that treat shadow AI as intelligence about unmet needs - and respond with governed AI for healthcare adoption rather than prohibition - will reduce risk while capturing the efficiency gains their staff are already chasing on their own.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)