Shadow IT, with the data flowing outward
Shadow IT was the unsanctioned SaaS subscription on a corporate card. Shadow AI is the analyst pasting a customer list into a public chatbot to get it summarised, the developer with a coding assistant the security team has never heard of, the manager running a meeting transcript through a free tool to get the actions out. None of it is malicious. All of it is invisible to the organisation's AI governance, and most of it moves data that the organisation is accountable for into a system it has no contract with.
The scale is the point. Microsoft and LinkedIn's 2024 Work Trend Index, a survey of 31,000 people in 31 countries, found that three quarters of knowledge workers were already using generative AI at work and that 78% of those users were bringing their own tools rather than using one their employer provided. Whatever the figure in any given organisation, the governance position is the same: the AI inventory the organisation thinks it has is a fraction of the AI actually in use.
Why it happens
Three causes, and a ban addresses none of them.
The tools are useful and the sanctioned alternative is worse or absent. People route around a slow approval process the same way they always have. Where there is no approved tool, the unapproved one wins by default.
AI is arriving inside software that is already approved. A feature switched on by a vendor in a product the organisation already licenses is not something anyone chose to adopt. The document editor, the CRM and the meeting platform all now have a model in them, often processing content on a third party's infrastructure, and the organisation's approval of the product predates the feature.
Nobody has said what is allowed. Absent an acceptable use policy that names permitted tools and permitted data, every employee makes the call alone, and the safe assumption for a busy person is that it is fine.
What is actually at risk
The obvious exposure is confidentiality: customer data, personal data, source code and commercially sensitive text leaving the organisation through a channel it does not log, to a provider whose terms may permit training on it. That is sensitive information disclosure without an attacker.
The less obvious exposure is accountability. A decision influenced by an unapproved tool's output is still the organisation's decision. If it is wrong, biased or fabricated, the organisation owns the consequence and has no record of how it was reached. Where the tool was used on anything customer-facing, regulated or subject to the EU AI Act's transparency duties, the organisation may also have obligations it does not know it has triggered.
And there is a quieter cost: an organisation that cannot see its own AI use cannot set an appetite for it, cannot answer a regulator's question about it, and cannot benefit from it deliberately.
What reduces it
The measures that work are the ones that make sanctioned use easier than unsanctioned use, and then make unsanctioned use visible.
- Provide an approved tool with a contract that forbids training on inputs, and make it at least as good as the free one. This does more than any policy.
- Publish the policy, short, naming what may be used for what, and what data may never be pasted anywhere. AI acceptable use policy.
- Teach it. The EU AI Act's Article 4 duty on AI literacy applies to deployers now, and a workforce that understands why the data matters needs less policing.
- Look. Web gateway and CASB logs already show which AI services are being reached and by how many people. That is the discovery step for the inventory, not an enforcement step.
- Inventory vendor features. Ask each existing supplier which AI features are on, where the data goes, and whether they can be switched off. Add every answer to the AI inventory.
Blocking every AI domain at the firewall is sometimes right for a specific high-sensitivity population. As a general measure it moves the problem to personal devices and removes the visibility that the logs were providing.
Where it sits in the register
No documented AI policy is the condition that makes shadow AI the default rather than the exception, and AI literacy gap in the deploying organisation is why staff cannot be expected to judge the data question alone. Sensitive information disclosure is the usual consequence. The controls are the AI acceptable use policy, an AI literacy programme, and the ownership and accountability framework that gives someone the job of maintaining the inventory.