Somewhere in your organization right now, someone is pasting a customer list into a public chatbot to draft an email. A team is running a browser extension that summarizes every document it touches. An analyst has built a small pipeline that fine-tunes a model on internal data, and nobody in security knows it exists. None of these people are acting in bad faith. They are trying to get work done. Together, though, they make up one of the fastest-growing risks in the enterprise: shadow AI.
Shadow AI is the use of AI tools, and the building of AI systems, outside any governance, review, or oversight. It is quiet, widespread, and often invisible to the people accountable for risk. This guide explains what it is, why it keeps happening, what it actually costs, and the practical sequence for bringing it under control. The order matters: you cannot govern what you cannot see, so discovery comes first.
What shadow AI is (and how it differs from shadow IT)
Shadow AI is the AI your organization is using and building that governance never approved, never assessed, and often cannot see.
Most security teams already know shadow IT: the unsanctioned apps, cloud accounts, and devices that employees adopt without going through procurement or security review. Shadow AI is its close relative, but it behaves differently in three ways that make it harder to manage.
First, the barrier to entry is almost zero: adopting shadow AI takes a browser tab, not a signup. Second, the sensitive part flows outward. A rogue file-sharing app is a risk mostly because of what attackers might pull out; a public chatbot is a risk because of what employees willingly put in, often the exact data you are obligated to protect. Third, some shadow AI is not a tool at all but a system your own people build: a fine-tuned model, a retrieval pipeline, an agent wired into internal APIs. That is shadow development, and it carries model risk, not just usage risk.
Shadow AI takes several recognizable forms. Knowing them makes discovery concrete rather than abstract.
1. Public chatbots with company data
Employees paste source code, contracts, customer records, or strategy documents into consumer AI assistants to summarize, rewrite, or debug. The data leaves your control the moment it is submitted.
2. Browser extensions and plugins
AI-powered extensions that read, summarize, or auto-complete across every page and document a user opens. Many request broad permissions and route content through third-party servers.
3. Unsanctioned copilots
Coding assistants, meeting note-takers, and writing tools adopted per team or per person, outside any license, data-processing agreement, or security review.
4. Teams fine-tuning models
Data scientists and engineers training or fine-tuning models on internal data in personal or unmanaged cloud accounts, with no model documentation, evaluation, or approval.
5. Ungoverned agents
Autonomous agents and scripted workflows that call tools, read systems, and take actions using shared credentials, with no identity, permission scoping, or audit log behind them.
6. Embedded AI features
AI quietly switched on inside SaaS tools your teams already use. The vendor added a model; nobody assessed what data it processes or where it goes.
The definition test. If an AI tool or system is processing company data or making decisions, and no inventory record, owner, or risk assessment exists for it, it is shadow AI. The label is not about intent. It is about visibility and control.
Why it happens
Shadow AI is rarely rebellion. It is what people do when the approved path is slower than the work in front of them.
It helps to treat shadow AI as a signal rather than a violation. When two-thirds of employees reach for tools nobody sanctioned, the tooling and the process, not the people, are usually the problem. Three forces drive it.
- Speed and pressure. AI removes hours from real tasks: drafting, coding, analysis, research. When a tool makes someone visibly faster, waiting weeks for approval feels like a penalty for being productive.
- Friction in official channels. If the sanctioned route means a ticket, a security questionnaire, a procurement cycle, and a two-month wait, employees route around it. Governance that is slower than the risk it manages gets bypassed.
- No approved alternative. This is the one organizations most often miss. If there is no vetted internal assistant, telling people not to use public ones just pushes the same behavior further out of sight. A ban without a substitute does not remove the demand; it hides it.
There is a compounding effect that makes shadow AI worse than shadow IT ever was: people hide it. Microsoft found that 52% of employees who use AI at work are reluctant to admit using it for their most important tasks. Fear of looking replaceable, or of breaking an unclear rule, keeps usage underground, which is exactly where you least want it.
The real risks
The danger of shadow AI is not the tool. It is that risk accumulates with no owner, no record, and no way to answer a regulator or an auditor when they ask.
The costs are measurable. IBM's 2025 Cost of a Data Breach report found that breaches involving shadow AI cost about $670,000 more on average than breaches without it, and that one in five breached organizations had an incident linked to shadow AI. Of organizations that reported an AI-related breach, 97% lacked proper AI access controls, and 63% either had no AI governance policy or were still writing one. The gap is not exotic. It is basic oversight that never got applied to AI.
| Risk | What actually goes wrong | Severity |
|---|---|---|
| Data leakage and IP exposure | Source code, customer PII, contracts, and trade secrets submitted to third-party models that may log, retain, or train on the input. In shadow AI breaches, IBM found customer PII compromised in 65% of cases and IP the most expensive record type at $178 each. | Critical |
| Compliance and regulatory exposure | Personal data sent to unvetted tools can breach GDPR (no lawful basis, no data-processing agreement, uncontrolled international transfers), with fines up to 4% of global turnover. Ungoverned high-risk uses collide with the EU AI Act, whose penalties reach €35M or 7% of turnover under Article 99. | Critical |
| Security and attack surface | Unvetted extensions and tools with broad permissions, shared credentials, and unknown data flows widen the attack surface. Agents wired into internal systems can be manipulated through prompt injection to act on data they should never reach. | High |
| Unmonitored bias and accuracy | Outputs used in hiring, lending, or customer decisions with no evaluation, no ground truth, and no human review. Hallucinated facts and skewed recommendations enter real decisions unchecked, creating discrimination and liability exposure. | High |
| Audit and accountability gaps | When AI has no inventory record and no owner, you cannot answer who used what, on which data, to make which decision. That absence of evidence fails audits, breaks incident response, and blocks any framework certification. | Medium |
The audit trap. Regulators and auditors increasingly expect a complete inventory of AI systems and uses. Under an EU AI Act inquiry or an ISO/IEC 42001 assessment, "we did not know that was running" is not a defense. It is the finding.
How to bring it under control
The instinct is to write a policy first. That is backwards. You cannot govern what you cannot see, so the sequence starts with discovery and inventory, and ends with monitoring that never stops.
Bans fail because they treat a visibility problem as a discipline problem. The programs that actually reduce shadow AI follow a sequence: find what is in use, record it, give people a better sanctioned option, set a policy they can actually follow, then watch continuously as new tools appear. Run these roughly in order, but expect to loop.
-
Discover what AI is actually in use
Before any policy, get an honest picture of reality. Combine technical signals with human ones. Manual surveys alone miss most of it, because people underreport.
- Analyze network and proxy logs, SSO and OAuth grants, and expense data to surface AI tools and extensions in use.
- Scan cloud accounts and code repositories for model calls, API keys, and fine-tuning jobs.
- Run an amnesty: ask teams what they use, with no blame, so hidden usage surfaces voluntarily.
-
Build an inventory
Turn discovery into a living record. An AI inventory is the foundation of every governance framework, and it is the single control that makes the rest possible.
- Record each AI system and use case: owner, purpose, data touched, tool or model, and vendor.
- Classify risk against the EU AI Act tiers and internal thresholds, so high-risk uses route to review.
- Keep it live, not a one-time spreadsheet. New tools appear weekly; a static list is stale on arrival.
-
Offer sanctioned alternatives
Discovery tells you what people need. Meet that demand with vetted options, or the behavior simply moves back into the dark.
- Stand up an approved enterprise assistant with data protections, so employees have a fast, safe default.
- Provide a clear, quick path to request and approve new tools, measured in days, not months.
- Make the sanctioned route the easy route. Convenience, not compliance language, is what wins adoption.
-
Set a usable policy
Write rules people can follow without a lawyer. A policy that is clear and specific gets obeyed; one that is vague or absolute gets ignored.
- State plainly what data may go into which tools, with concrete examples of green, amber, and red uses.
- Tie the policy to the inventory and to named owners, so it triggers assessment and approval, not just a signature.
- Pair it with the EU AI Act Article 4 AI-literacy duty: people who understand the risk make better choices.
-
Monitor continuously
Shadow AI is not a project you close. New tools, features, and agents appear constantly, so oversight has to run continuously.
- Keep discovery running so newly adopted tools land in the inventory automatically, not at the next audit.
- Monitor sanctioned systems for drift, accuracy, and misuse, and log agent actions for audit.
- Maintain audit-ready evidence and map one control set to many frameworks (EU AI Act, NIST AI RMF, ISO 42001) so a single record answers every reviewer.
From policy to practice. Spreadsheets and ticket queues rarely keep up with how fast AI spreads across an enterprise, which is exactly why shadow AI stays invisible. Dedicated AI governance platforms automate discovery of AI in use, including shadow AI, and maintain a live inventory of every model, use case, and agent, giving governance teams one place to discover, assess, monitor, and evidence them against frameworks like the EU AI Act, NIST AI RMF, and ISO 42001.
Key Takeaways
- Shadow AI is AI used or built with no oversight. It differs from shadow IT because the barrier is near zero, the sensitive data flows outward, and some of it is systems your own teams build.
- It happens because sanctioned paths are slow and often missing. Around two-thirds of employees use unapproved AI tools, and most hide it.
- The cost is real: IBM found shadow AI adds about $670K to a breach, and 97% of AI-breached organizations lacked access controls.
- The biggest exposures are data and IP leakage, GDPR and EU AI Act non-compliance, a wider attack surface, unmonitored bias, and audit gaps.
- Control follows a sequence: discover, inventory, offer alternatives, set a usable policy, monitor. Discovery and inventory come first, because you cannot govern what you cannot see.
Frequently asked questions
Shadow AI is any AI tool or system being used or built inside an organization without official approval, review, or oversight. That covers an employee pasting company data into a public chatbot, a team running an unsanctioned copilot, and engineers fine-tuning a model or wiring up an agent that governance has never seen.
Shadow IT is unsanctioned apps, devices, and cloud services. Shadow AI is a specific, sharper case. The barrier to adoption is a browser tab rather than a signup, the main risk is the sensitive data employees put in rather than what attackers pull out, and some shadow AI is not a bought tool at all but a model or agent your own people build.
Because risk builds up with no owner and no record. Data and IP leave your control, personal data can breach GDPR and the EU AI Act, unvetted tools widen the attack surface, and outputs enter real decisions with no bias or accuracy check. IBM's 2025 report links shadow AI to roughly $670K in additional breach cost and to one in five breaches.
A ban without a sanctioned alternative usually backfires. It does not remove the demand that drives shadow AI; it pushes the same behavior further out of sight, where you cannot see or protect it. The more effective move is to offer a vetted, fast, approved option and make it the easy default, then set clear rules around it.
Start with discovery, then inventory. Use network logs, SSO and OAuth grants, cloud and code scans, and a no-blame amnesty to find what is actually in use, then record each system and use case with an owner, the data it touches, and a risk classification. Policy and monitoring only work once you can see the full picture.
Both frameworks assume you know what you are running. Sending personal data to an unvetted tool can breach GDPR through missing lawful basis, absent data-processing agreements, or uncontrolled transfers, with fines up to 4% of global turnover. Ungoverned high-risk uses breach the EU AI Act, where Article 99 penalties reach €35M or 7% of turnover. In both cases, an undiscovered system is an undocumented one, and that is where audits fail.