Every health system has an AI policy. Many of them are being quietly ignored. In a December 2025 Wolters Kluwer Health survey of 518 providers and administrators, 17% admitted to using unapproved AI tools in their clinical workflow. More than 40% said they knew a colleague doing the same. And when researchers asked those providers why, 45% gave the same answer: the sanctioned tools are too slow.
That is shadow AI in healthcare. It is not a story about rule-breaking clinicians. It is a story about workflow friction, and it was one of the sharper threads running through Offcall's recent AI Morbidity and Mortality webinar with Dr. Graham Walker, Dr. Michael Hobbs, and Dr. Kai Romero of Evidently. The overview article from that session touched on the compliance question briefly. The problem deserves its own treatment, because it is quietly becoming one of the most consequential governance issues in medicine.
On/Offcall is the weekly dose of information and inspiration that every physician needs.
The headline statistics are striking on their own:
These numbers are self-reported, which means the real figures are almost certainly higher. People do not volunteer policy violations in surveys at a rate greater than the actual violation rate.
The temptation when a compliance officer sees these numbers is to assume the problem is clinician discipline. The data says otherwise. Nearly half of the providers using shadow AI identified speed as the driver, which means the sanctioned alternative existed, they knew about it, and they chose a different tool because the approved one got in the way of patient care.
That is a design problem, not a character problem. A clinician staring down a 40-patient day who has to choose between a slow approved tool and a fast consumer tool is going to make the predictable choice some percentage of the time. The question for every health system is whether that percentage is 2% or 25%, and whether the leaders know which it is.
Dr. Kai Romero made a comparison in the webinar that reframes how to think about this. She described working with LLMs as not dissimilar from working with an early trainee:
"It's not dissimilar in my mind from working with like an early trainee where they really want to make you happy. There's a lot on the line, like they want to do as best as they possibly can and they don't know where the pitfalls are." — Dr. Kai Romero
The same framing applies to the clinicians reaching for consumer AI tools. They are not trying to breach HIPAA. They are trying to finish their notes before their kid's bedtime. The tool that lets them do that wins, every time, unless the approved alternative is genuinely competitive on speed and ergonomics.
An intern who takes shortcuts because the approved workflow is broken is a signal about the workflow, not the intern. The right response is to fix the workflow. The same logic applies to shadow AI. If 45% of your clinicians using unapproved tools are doing it for speed, the sanctioned tool is the problem.
The old shadow AI risk was straightforward: a clinician pastes identifiable patient information into ChatGPT. The data leaks at the moment of the paste. Agents change the surface area entirely. A clinician who connects their email, their calendar, or their EHR to an agentic AI tool is no longer leaking what they paste. They are leaking what they connect. As the webinar slide put it bluntly:
"With chatbots, PHI leaks when you paste it. With agents, it leaks when you connect it." — AI M&M slide deck
That shift matters because connections persist. A single approval grants ongoing access. The chance to catch the leak at the moment of the action disappears.
The webinar surfaced a simple pre-flight checklist that any clinician can run through before putting PHI anywhere near an AI tool. These are not legal advice. They are the questions that would have prevented most of the shadow AI incidents that have made the news in the last 18 months.
A business associate agreement governs how the vendor handles your data. Critically, the BAA sits with the account, not the model. A ChatGPT Enterprise seat may have one. A personal ChatGPT Plus subscription does not. The model behind both is the same. The compliance posture is not. The account matters more than the model.
De-identification is harder than it sounds in pediatrics and rare disease work. A birth date, a school, and a rare diagnosis can collectively identify a single child. Stripping the name is not sufficient. The question to ask is whether the combination of fields you are entering could narrow the universe of possible patients to a small enough group to re-identify.
If the tool is connected to your email or your calendar, it can read all of it. If it is an agent with EHR access, it can touch everything that account can touch. The question is not what you intend to show the tool. The question is what the tool can see once you grant it access.
If there is one, use it. If it is too slow, tell the people who run it. Dr. Graham Walker made this point directly during the session:
"Don't put real data into any of these models." — Dr. Graham Walker
Clinicians who silently route around the approved tool guarantee that the next version of that approved tool will not be any better, because nobody with budget authority knows there is a problem.
For individual clinicians and for the people responsible for AI governance, the response to shadow AI should look less like enforcement and more like product management.
The 17% is a leading indicator, not a trailing one. The number will rise as AI tools get better, faster, and more deeply embedded in the apps clinicians already use. Health systems that treat shadow AI as a workflow problem will reduce it. Health systems that treat it as a discipline problem will drive it underground and lose the ability to see what is actually happening on the ground.
The clinicians doing this are not villains. They are telling you something about your sanctioned tools. The question is whether you are listening.

Send and receive referrals, build wealth, and grow your physician community with Offcall.
Offcall Team is the official Offcall account.
See what your colleagues are saying and add your opinion.