Security and privacy
What is shadow AI?
In short
Shadow AI is the use of AI tools, such as public chatbots, browser extensions or AI features inside other apps, for work without the approval or oversight of IT and security teams. It usually happens because people want to work faster and no approved option meets their needs. The main risks are company data leaving your control, unreviewed outputs and no record of what was shared.
Shadow AI is what happens when people use AI at work without the company knowing or approving it. Someone pastes a customer email into a free chatbot to draft a reply. A developer installs an AI coding extension on a work laptop. A team turns on an AI feature inside a SaaS tool that nobody in security has reviewed.
None of this is usually malicious. People reach for AI because it saves them time. The problem is that the company loses sight of where its data goes, and cannot show auditors or customers what happened to it.
What counts as shadow AI?
Shadow AI covers any AI use that sits outside the tools and rules your organisation has approved. Typical examples:
- Public chatbots on personal accounts. Free or personal plans of consumer AI assistants, used with work data.
- Browser extensions. AI writing, summarising or meeting tools that can read every page a person opens.
- AI features inside approved apps. A tool you already bought adds an AI assistant, and it is switched on without a review of where the data is processed.
- Personal API keys. Developers wiring a model API into scripts or internal tools with their own key and card.
- Homemade agents and automations. Workflows that connect a model to email, drives or databases using one person’s credentials.
Why do employees use unapproved AI tools?
Understanding the cause matters, because the fix follows from it.
- There is no approved option. If the company offers nothing, people find their own.
- The approved option is worse. It is slower, cannot see the documents people need, or cannot take action in the apps they use every day.
- Getting approval takes too long. A request that takes weeks loses to a free sign-up that takes a minute.
- People do not know the rules. Many employees simply do not realise that pasting a contract into a chatbot is a data transfer to a third party.
Why is shadow AI risky?
The main risks are about data, accountability and quality. The OWASP Top 10 for LLM Applications lists sensitive information disclosure as one of the top risks for AI systems, and shadow AI makes that risk hard to even see.
- Data leaves your control. Whatever goes into a prompt is processed, and often stored, by a provider you have no contract with. Consumer plans may have different data use terms from business plans.
- No audit trail. If a customer or regulator asks what happened to their data, you cannot answer.
- Personal data and compliance. Personal data sent to an unvetted processor can break privacy laws and your own customer contracts.
- Oversharing through connected tools. An extension or homemade agent that can read a whole drive or inbox exposes far more than a single pasted paragraph.
- Unchecked outputs. Answers that are wrong, made up or biased end up in customer emails, code and reports without review.
- Account risk. Personal accounts are not covered by company sign-in, so they are not disabled when someone leaves.
Shadow AI vs sanctioned AI: what is the difference?
| Question | Shadow AI | Sanctioned AI |
|---|---|---|
| Who chose the tool? | An individual or team, on their own | IT and security, after review |
| Sign-in | Personal account or personal API key | Company single sign-on, disabled when people leave |
| Data terms | Whatever the consumer terms say | A contract, a data processing agreement and known retention |
| What the AI can read | Whatever the person pastes or grants | Scoped by permissions and policy |
| Record of use | None the company can see | Audit trail of who did what |
| Review of risky actions | None | Approvals for actions that change data |
How do you detect shadow AI?
You cannot manage what you cannot see. Most teams combine several signals:
- Network signals. DNS, web proxy or secure web gateway logs show traffic to known AI domains.
- Cloud access security broker (CASB). A CASB classifies SaaS apps, including AI tools, and can report or block them.
- Identity provider grants. Check which third-party apps people have granted access to their work email, calendar and drive through OAuth consent screens.
- Endpoint and browser inventories. List installed browser extensions and desktop apps.
- Spending. Expense reports and card statements reveal personal AI subscriptions and API bills.
- Asking people. A friendly survey about which AI tools help them most often finds more than the logs do, and tells you what people actually need.
How do you manage shadow AI?
Blocking alone pushes use onto personal phones, where you see nothing. A workable programme has five parts.
- Offer a sanctioned alternative that is genuinely useful. It should answer from company documents, work inside the apps people already use, and be available through company sign-in. This is the single most effective step, because it removes the reason for shadow use.
- Write a short acceptable use policy. Name the approved tools, list the data classes that may never go into any AI tool, and explain how to ask for a new tool.
- Make approval fast. Publish a simple intake process for new AI tools with a clear turnaround.
- Control data at the source. Use permissions so AI only sees what each person may see, and mask personal data before it reaches a model. See PII masking for AI.
- Keep a record and review it. An audit trail of AI use, plus human approval for actions that write or delete data.
Frameworks such as the NIST AI Risk Management Framework give a structure for this work: govern, map, measure and manage. Its companion Generative AI Profile (NIST AI 600-1) covers risks specific to generative AI, including data privacy.
What should a sanctioned AI option include?
If the approved tool is weaker than a free chatbot, shadow AI will continue. Check for:
- Sign-in with your identity provider, so access ends when employment ends.
- Answers from company knowledge that respect who is allowed to see which file.
- A choice of models, so teams are not tempted elsewhere for a better one.
- Clear data terms: where data is stored and whether it is used for training.
- Approvals before the AI sends, changes or deletes anything.
- A record of use that security can review.
For how data escapes in AI systems more generally, read AI data leakage. For options that keep data inside your own environment, read What is private AI?.
How promptev handles shadow AI
promptev is a platform for building AI agents that a company approves and runs itself, which gives people a sanctioned place to use AI at work.
- Sign-in can use any OpenID Connect or SAML 2.0 provider (such as Entra ID, Okta or Google), people can be added and removed from your directory with SCIM, and SSO can be required for everyone. Disabling a member removes access at once.
- Agents answer from company knowledge and follow Google Drive, SharePoint, OneDrive and Dropbox sharing, so a file the asker cannot open is never fetched.
- Agents run on the company’s own model keys from providers such as OpenAI, Anthropic and Google Gemini, and customer data is never used for training.
- By default, connector tools that write ask for approval once in a conversation, and destructive tools always ask.
- An audit trail records every run, approval and settings change, with who did it.
- People can reach approved agents in the Agent library, in Slack or on mobile. More on the controls is on the governance page.
Frequently asked questions
Is shadow AI the same as shadow IT?
Shadow AI is a kind of shadow IT. The difference is that AI tools take in free text, files and questions, so people can paste sensitive data into them in seconds, and the tool may keep or learn from it depending on its terms.
Should companies ban ChatGPT and other AI chatbots?
A ban on its own rarely works, because people switch to personal devices and accounts where you have even less visibility. Most security teams pair a clear policy with an approved tool that is good enough that people choose it.
How do I find out which AI tools employees use?
Common sources are web proxy and DNS logs, a cloud access security broker (CASB), browser extension inventories, the OAuth app grants in your identity provider and expense reports. A short, non-punitive survey also helps, because people will often tell you if they are not afraid of being blamed.
Is all unapproved AI use dangerous?
No. Asking a chatbot to rephrase a public paragraph carries little risk. The risk rises with the data involved: customer records, personal data, source code, contracts, financials and anything under a confidentiality agreement.
What should an AI acceptable use policy include?
It should list approved tools, say which kinds of data may never go into any AI tool, explain how to request a new tool, and state who reviews AI outputs before they reach customers. Keep it short enough that people actually read it.

Faisal Saeed is Founder & CEO of Promptev, building next-gen context engineering infrastructure that enables teams to orchestrate, scale, and deploy production-ready generative AI systems with confidence.