Guide

What is shadow AI?

Shadow AI is AI used for work without the IT or security team knowing about it or approving it. This guide covers what counts, how it differs from shadow IT, how common it is, what can go wrong, how to find it, and how to govern it without a ban.

In short
  • Shadow AI is any AI tool, AI feature, or model call used for work that the organization has not approved and cannot see.
  • It is shadow IT with one important difference: every prompt sends company data to a model provider, under that provider's terms.
  • It is common. In a June 2026 survey, 66% of office professionals said they had used AI tools at work they believed were not permitted.
  • No single detection method sees all of it. Domain logs show which tools are used; only inspecting the traffic shows what data goes with it.
  • Bans push usage onto personal devices. Giving people a sanctioned tool and protecting the data in the prompt works better.

Shadow AI: a definition

Shadow AI is the use of AI tools, AI features, or AI models for work without the knowledge, approval, or oversight of the organization's IT or security team. The term comes from shadow IT, and like shadow IT it is rarely malicious. People use it because it helps them get work done faster than the approved alternative, or because there is no approved alternative.

In practice it takes three forms:

  • Public AI tools on personal accounts. A chatbot, writing assistant, image generator, or search tool signed up for with a private email address and used for company work.
  • AI features inside approved software. A meeting notetaker added to a video call, an AI assistant switched on in a SaaS product the company already pays for, or a browser extension that reads the page.
  • Programmatic AI. API keys on a developer's card, coding assistants, scripts, and agents that call a model directly. These often hold credentials and act on systems, which is covered in more depth in Your agents are shadow AI with credentials and MCP servers are the new shadow AI surface.

Whether something is shadow AI depends on the account, not the product. The same tool can be sanctioned under an enterprise agreement and shadow AI on a personal account, because the data terms, the retention, and the controls are different.

Shadow AI vs shadow IT

Shadow AI is a subset of shadow IT, but the controls built for shadow IT do not cover it well. The table shows where the two differ.

Shadow ITShadow AI
What it isAny app, device, or cloud service used without IT approvalAny AI tool, feature, or model used without IT approval
How data leavesFiles are stored or synced in an unapproved serviceData is typed or pasted into a prompt, or read by the tool, and sent to a model provider each time
What happens to itStored under the service's termsProcessed, possibly retained, and on some consumer plans used to train models
Where it hidesNew domains and appsNew domains, but also AI features inside domains and apps you already approved
Cost to startOften a subscription or a purchaseUsually free and instant, which is why it spreads faster
Typical controlApp discovery, CASB, procurementThose, plus inspection of what is in the prompt

Examples of shadow AI

Typical cases:

  • A sales manager pastes a customer contract into ChatGPT on a personal account to summarize the renewal terms.
  • A meeting notetaker such as Otter or Fireflies joins a board call because one attendee connected it to their calendar.
  • A developer uses Cursor or GitHub Copilot on a personal subscription against the company's repositories.
  • An HR advisor asks DeepSeek to rewrite a performance review, including the employee's name and medical absence.
  • A finance analyst installs a browser extension that adds an AI sidebar to every page, including the ERP.
  • An operations team builds an agent on a model API with a key paid for on an expense report, and gives it read access to the ticketing system.

Each of these tools has its own data terms. Of the 813 AI services documented in our AI Service Directory, 133 train on customer content by default and 60% do not say whether they do. Every entry quotes the vendor's own document, so you can check the terms of the tools you find.

How common is shadow AI?

The surveys point the same way: many people who use AI at work use some of it without approval, and most organizations cannot yet tell which tools.

66%
of office professionals have used AI tools at work they believed were not permitted (PagerDuty, June 2026)
47%
of generative AI users access tools through personal accounts (Netskope, 2026)
43%
of breached organizations had a shadow AI incident, up from 20% a year earlier (IBM, 2026)

The governance side lags behind. ISACA's 2026 AI Pulse Poll found that 38% of organizations have a formal, comprehensive AI policy. IBM's 2026 breach report found that about seven in ten breached organizations had no governance policies for managing AI or for spotting unapproved use.

Our own deployment data shows the scale once it becomes visible. The median organization has 73 distinct AI services in use across its network, and one in four has more than 120. The methodology, and every other figure with a link to its source, is in The State of Shadow AI 2026.

The risks of shadow AI

Data leaving under someone else's terms. Anything in a prompt goes to the provider. On a personal account, what happens next is set by the consumer terms the employee accepted, which may include retention and model training. Our deployments see a median of about 50 attempted data leaks to AI tools a day: personal data, credentials, or financial data in a prompt.

Regulatory exposure. Under Article 28 of the GDPR, a processor handling personal data on your behalf has to be bound by a contract. A personal AI account has no contract with your organization. Sector rules add to this: financial entities under DORA and essential entities under NIS2 are expected to know their ICT third parties, which shadow AI by definition are not. See AI under DORA and NIS2.

Breaches that cost more. In IBM's 2026 data, about half of shadow AI incidents resulted in data loss or compromise, and about one in five drew a regulatory fine.

Tools that take actions. Agents and coding assistants with credentials can read and change systems. When one is set up without review, nobody has checked what it can reach.

Wasted spend. Teams pay for overlapping AI subscriptions on expense reports while the licenses the company bought go unused. More on AI licensing costs.

Why blocking AI does not stop shadow AI

The first response in many organizations is to block the best-known AI domains. It rarely holds. The tools are useful, there are hundreds of them, new ones appear every week, and a phone on a mobile connection sits outside every network control. The PagerDuty figure above says as much: two thirds of office workers have already used AI they thought was not allowed.

What does move behaviour is a better sanctioned option. Netskope's 2026 report found 62% of workplace AI users on company-managed accounts, up from 25% a year earlier, while personal-account use fell from 78% to 47%. People switch when the approved route is as good as the unapproved one.

How to detect shadow AI

There are several ways to find shadow AI, and each one sees a different slice. Most organizations need at least two.

MethodWhat it findsWhat it misses
Firewall, DNS, and proxy logsWhich AI domains are reached, by whom, how oftenWhat was sent; AI features inside approved domains; anything off the corporate network
SSE / CASB with TLS inspectionApp-level activity, and content for the apps the vendor supportsLong-tail AI tools without a connector; AI features inside approved apps; local agents
Browser extensionPrompts typed into web tools in managed browsersDesktop apps, mobile, unmanaged browsers, API and agent traffic
Identity and SaaS discoveryAccounts, SSO sign-ins, OAuth grants to AI apps, expense linesPersonal accounts with no company login; what data is used
Endpoint inventoryInstalled AI apps, extensions, coding agents, MCP configuration filesWeb usage; what data is sent
Inline AI traffic inspectionWhich AI service, which user, and what data is in each prompt, across the long tailTraffic that does not pass through it, such as personal devices on mobile data
AI gatewayEvery API and agent call routed through it, by key and identityAnything that calls a model directly instead

A practical starting point is the logs you already have. Export the destinations from your firewall or secure web gateway and match them against a list of AI domains. The AI Service Directory has a domain lookup for this: paste a hostname and it tells you which AI service it belongs to. That gives you a first inventory in an afternoon. It will not tell you what data went with each request, which is the question the board and the regulator will ask next.

For a structured version of this exercise, our free Shadow AI assessment runs it against your own traffic.

How to govern shadow AI without a ban

  1. Get an inventory. Which AI services are in use, by which teams, how often. Include programmatic use: API keys, coding agents, MCP servers.
  2. Classify by data terms, not by brand. For each service, check whether it trains on inputs, how long it keeps them, and where it stores them. A tool that keeps nothing is a different risk from one that trains on everything.
  3. Offer a sanctioned route that is as good. A secure AI workspace with the models people actually want, so the approved choice is also the convenient one.
  4. Protect the data, not just the domain. Redact personal data and secrets from prompts before they leave, block the few services that are genuinely unacceptable, and redirect users to the approved tool when they hit one.
  5. Bring programmatic AI under the same rules. Route apps and agents through a gateway with keys tied to identity, guardrails, and budgets.
  6. Measure and repeat. Track the number of services, attempted leaks, and the share of usage on sanctioned tools every month. The goal is to know where shadow AI is, not to get it to zero.

Shadow AI FAQ

What is shadow AI?

Shadow AI is the use of AI tools, AI features, or AI models for work without the knowledge or approval of the organization's IT or security team. It covers public chatbots used on personal accounts, AI features switched on inside approved software, browser extensions, and API keys or agents that call models directly.

What is the difference between shadow AI and shadow IT?

Shadow IT is any technology used without IT approval. Shadow AI is the part of it that sends data to an AI model. The difference that matters is where the data goes: with shadow AI, company data is sent to a model provider in every prompt, under terms the organization never agreed to, and often through tools or domains that are already approved.

Is using ChatGPT at work shadow AI?

It depends on the account and the approval. ChatGPT used through an enterprise agreement the organization has signed and configured is sanctioned AI. The same tool used on a personal account for work, or used for data the policy does not allow, is shadow AI.

How do you discover shadow AI?

Combine sources. Network and firewall logs show which AI domains are reached. Identity and SaaS discovery show accounts and OAuth grants. Endpoint scans show installed apps, extensions, and agent configuration files. Only inspection of the traffic itself, in the network path or through a gateway, shows what data is being sent.

Is shadow AI illegal?

Using an AI tool is not illegal in itself. The data sent to it can be. Under the GDPR, personal data handed to a processor has to be covered by a contract with that processor, and a personal AI account has no such contract with your organization. Confidentiality clauses in customer contracts can be breached the same way.

Should we block AI tools to stop shadow AI?

Blocking on its own tends to move usage to personal devices and accounts, where it is harder to see. Surveys show most employees have used AI they believed was not permitted. Organizations that provide a sanctioned route see usage move onto it, which is why visibility plus a good approved option works better than a ban.

Find out how much shadow AI you have

The median organization in our deployments has 73 AI services in use. The free assessment shows yours, and what data is going to them.

Free Shadow AI Assessment

Related

The State of Shadow AI 2026

Every shadow AI statistic linked to its study, plus our own deployment figures.

AI Service Directory

Domains, training, retention, and residency for 813 AI services, quoted from vendor terms.

Shadow AI visibility with Unseen

See which AI tools your team uses and what data goes with each prompt.