Shadow AI

What is shadow AI?

Shadow AI is AI that is used for work inside your organisation without your organisation knowing. A colleague pastes a customer contract into a chatbot to get a summary. Someone in sales runs a client list through a free tool to enrich it. Somebody in finance builds an agent that reads a mailbox, and shares it with three colleagues.

The name comes from shadow IT, the old problem of teams buying software without going through IT. Shadow AI is the same shape with the friction removed. Shadow IT at least needed a purchase, an installation or an admin password. Shadow AI needs a browser tab.

It matters that this is almost never bad intent. In nearly every case somebody found a tool that made their work genuinely faster and used it. That is the correct instinct in an employee. The problem is not the motivation, it is that nobody can see what is happening.

How it takes hold

Three things drive it, and all three are things you can influence.

The approved route is slower than the unapproved one. If getting access to a sanctioned tool takes six weeks and a free alternative takes six seconds, people will use the free alternative for anything urgent. Every time.

Nobody said what the rules are. Most organisations have never told staff which categories of information may never go into an external tool. In the absence of a rule, people apply their own judgement, and their judgement is calibrated on how useful the answer was.

It spreads by demonstration. One colleague shows another that a task now takes ten minutes instead of an afternoon. That is a far stronger recommendation than any internal communication about an approved platform.

What actually goes wrong

Data leaves your control. Pasting a contract, a patient record or a price list into a consumer tool means that data is now processed somewhere you have no agreement with, under terms you have not read, possibly outside the EU. This is a data protection question before it is a security question.

Agents with no owner. An agent built by one person and shared with a team keeps running when that person changes role or leaves. It still uses their account, still reads real data, and nobody remembers it exists until it breaks or does something it should not.

No trail behind a decision. If a quote, a rejection letter or an assessment came out of an unapproved tool, you cannot reconstruct afterwards what it was based on. That is uncomfortable in a dispute and worse in an audit.

Wrong answers with nobody checking. A sanctioned tool sits on your own data with some form of grounding. A consumer chatbot answers from general knowledge, confidently, including about your own policies that it has never seen.

An unmanaged attack surface. An agent nobody knows about is also an agent nobody has secured. It has tools, credentials and inputs, and a prompt injection in an incoming email can set those in motion.

Why banning does not work

The reflex is a policy that forbids the use of external AI tools. It is understandable and it does not work, for two reasons.

The first is that you cannot see it. A ban you cannot enforce simply pushes the same behaviour further out of sight, onto personal devices and personal accounts, where you have no visibility at all. You have not reduced the risk, you have made it invisible.

The second is that the productivity gain is real. If the ban actually worked, you would be asking people to do their job slower than they know how to. That does not hold, and the people most likely to break the rule are the ones getting the most value out of it.

What does work is duller. Give people a sanctioned tool that is good enough that the unapproved one stops being attractive. Say clearly which categories of information may never leave the organisation, in concrete terms rather than as a principle. Make registering an agent take two minutes and carry no risk of being told off. And accept that a registry which includes the awkward entries is worth more than a policy that produces a clean-looking void.

What to watch out for with shadow AI

Amnesty first, rules second. If the first thing that happens to someone who admits to using a tool is a reprimand, you will never hear about the second one. Ask what people are using, without consequences, before you tighten anything.

Look inside the software you already bought. A lot of shadow AI is not a separate tool at all. It is an AI feature that a supplier switched on in a product you already use. Nobody chose it, and it processes your data all the same.

Personal accounts are the hardest part. A colleague using a private account on a private laptop is outside everything you control. This is a conversation and a culture question, not a technical one.

Write the rule in nouns, not principles. "Handle data responsibly" tells nobody anything. "Customer data, personnel files, contracts and source code do not go into external tools" is something a person can actually apply on a Tuesday afternoon.

Shadow AI is a signal, not just a risk. The tools people reach for tell you exactly where your processes are slow. That is free product research, and it is worth reading as such before you go and shut it all down.

Last Updated: August 25, 2026 Back to Dictionary
Keywords
shadow ai shadow it ai governance agent registry agent identity data governance ai literacy prompt injection compliance copilot data leakage