A Wolters Kluwer survey of more than 500 hospital and health-system staff found that unsanctioned AI use is already widespread: over 40% were aware of colleagues using shadow AI, and nearly 20% said they had used an unauthorized AI tool themselves. The risk is concrete. When a clinician pastes patient notes into a free public chatbot, that data can leave the protected environment, and the average healthcare data breach now runs about $7.42 million. Shadow AI is the gap between what a governance committee believes is deployed and what is actually in use on the floor. Closing it starts with knowing it exists.

