GovernanceCore
Sourced index

Shadow AI Risk Index

The governance gap, by the numbers.

Updated 27 Jul, 05:07 BST

Live evidence feedFeed refreshed 27 Jul, 05:07 BST
98%

of organizations have employees using unsanctioned AI tools — shadow AI is effectively universal.

Unseen Security, State of Shadow AI 2026

Benchmark view

Enterprise exposure signals

Separate surveys; useful as directional signals, not a single comparable dataset.

Risk landscape

What can operate in the shadows?

Shadow AI is not a product category. It is any AI model, application, agent or workflow operating without the knowledge, authorization or governance oversight appropriate to its risk.

Named products in the examples describe common surfaces; they are not claims that those products are inherently unsafe.

01

Everyday workplace AI

Tools employees can start using in minutes, often through personal accounts or features hidden inside approved software.

Prompts & uploads

AI chatbots

Consumer or personal-account assistants used for company work without an approved enterprise boundary.

What it looks like

  • Personal ChatGPT, Claude, Gemini or Perplexity accounts
  • Employees uploading contracts, customer files or internal reports

Risk exposure

Sensitive-data leakageRetention and training exposureNo enterprise audit trail

Monitor

AI domains accessed · Personal vs enterprise login · Files and bytes uploaded

Hidden features

Embedded SaaS AI

AI features quietly enabled inside already-approved CRM, HR, productivity or support software.

What it looks like

  • CRM summarization enabled by a business team
  • AI scoring added to an HR or customer-support workflow

Risk exposure

Undocumented processingSecondary use of enterprise dataUnreviewed automated decisions

Monitor

Enabled AI features · Vendor data terms · Data sources and affected users

Session access

Browser AI & extensions

Extensions and browser copilots that can observe pages, forms, email and authenticated applications.

What it looks like

  • Page summarizer with access to every visited site
  • AI email or writing extension active in business systems

Risk exposure

Page and session exposureOver-broad extension permissionsForm-data capture

Monitor

Extension ID and publisher · Requested permissions · Users and business sites accessed

Consent & recordings

Meeting & voice AI

Personal transcription, note-taking, voice-cloning or meeting bots introduced without approval.

What it looks like

  • Unapproved bot joins a confidential meeting
  • Call recordings sent to a personal transcription service

Risk exposure

Missing consentSensitive recording retentionBiometric and voice-data exposure

Monitor

Bots joining meetings · Organizer and consent · Recording location and retention

02

Models and developer tools

AI introduced through code, model downloads, extensions, endpoints and personal credentials.

Source & secrets

Coding assistants

Unapproved IDE extensions, command-line assistants and web code generators operating on proprietary code.

What it looks like

  • Personal coding assistant in VS Code
  • Repository content pasted into a web generator

Risk exposure

Source-code leakageExposed credentialsInsecure or unlicensed output

Monitor

Extension inventory · Repositories accessed · Secret-scanning and code findings

Endpoints & keys

Model APIs

Developers or teams calling model providers through personal keys, unofficial gateways or unapproved accounts.

What it looks like

  • Personal API key in a prototype
  • Application sending production data to an unreviewed model endpoint

Risk exposure

Uncontrolled data transferMissing logs and controlsSpend and residency exposure

Monitor

Provider endpoints · API-key owner · Tokens, data volume and destination region

Supply chain

Local & open models

Models downloaded and run locally without provenance, license, security or suitability review.

What it looks like

  • Model downloaded from a public repository
  • Local assistant indexing company folders

Risk exposure

Malicious model artifactsLicense or provenance gapsUnmonitored local processing

Monitor

Model name, source and hash · License and safety documentation · Device and indexed folders

03

Agents and connected automation

Systems that can call tools, cross application boundaries and take action with inherited permissions.

Actions & autonomy

Autonomous agents

Agents created outside formal onboarding that can read, decide, call tools or change enterprise systems.

What it looks like

  • Research agent with browser and file access
  • Internal script that triages tickets and changes records

Risk exposure

Excessive permissionsUnapproved consequential actionsUnclear ownership

Monitor

Agent owner and purpose · Tool calls and actions · Approval boundary and kill switch

Connected systems

MCP servers & tools

Unreviewed Model Context Protocol servers that extend an assistant into data stores and business tools.

What it looks like

  • Remote MCP server added to a desktop assistant
  • Community connector with access to GitHub, Drive or a database

Risk exposure

Tool poisoningPrompt injectionCredential and system exposure

Monitor

Server endpoint and publisher · Connected tools and scopes · MCP calls and payloads

Cross-system movement

No-code AI workflows

AI steps inserted into automation, spreadsheet and low-code workflows outside engineering controls.

What it looks like

  • Workflow summarizes inbound customer records
  • AI step classifies documents then updates a CRM

Risk exposure

Unreviewed data movementSilent decision errorsCascading automated actions

Monitor

Trigger and downstream actions · Connected systems · Run volume, failures and owner

04

Knowledge and decision systems

AI connected to internal information or used to influence outcomes affecting people and customers.

Knowledge access

Informal RAG systems

Retrieval assistants connected to internal documents without preserving source permissions or review.

What it looks like

  • Team chatbot indexing a shared drive
  • Prototype connected to SharePoint, email or a customer database

Risk exposure

Over-broad retrievalCross-user data exposureStale or untraceable answers

Monitor

Indexed repositories · Permission inheritance · Queries, citations and access denials

People & outcomes

AI-assisted decisions

Informal models used to rank, score or recommend outcomes affecting employees, customers or applicants.

What it looks like

  • Résumé ranking built by a recruiting team
  • Customer-risk or eligibility scoring in a spreadsheet

Risk exposure

Bias and discriminationMissing human reviewRegulatory and explainability gaps

Monitor

Use-case owner · People affected · Decision volume, review and appeal path

Example pathways

How a useful shortcut becomes a governance risk

Confidential file leakage

  1. Employee
  2. Personal chatbot
  3. Customer file upload
  4. External model provider

Agent blast radius

  1. Developer
  2. Unknown agent
  3. Inherited credentials
  4. Repository + cloud + SaaS actions

Hidden automated decision

  1. Business team
  2. Embedded AI feature
  3. Unreviewed scoring
  4. Customer or employee outcome

Untrusted tool connection

  1. Assistant
  2. Remote MCP server
  3. Prompt or tool injection
  4. Data exfiltration or unsafe action

Risk watch

Latest signals and incidents

Current reporting that points to unsanctioned use, data exposure, unknown agents, or enterprise AI-control failures.

Figures are drawn from third-party research whose scopes and methodologies differ, so they are indicative rather than directly comparable. Live stories are selected from the site's hourly news and incident feeds using a narrow Shadow AI and enterprise-exposure filter. Each item links to its source. Benchmarks reviewed Jul 23, 2026.