Skip to content
atlas

Shadow AI

Also known as: unsanctioned AI

Staff using AI tools at work without the organisation knowing about them or having approved them.

Draft - this entry has not been reviewed yet.

Formal

Any use of AI services, models or extensions inside an organisation that has not been through its approval, risk assessment and supplier checks, so data sent to them is outside its control and oversight.

In plain English

Like an employee who takes work papers home to a friend for help - well meant, but the company has no idea who has read them or where copies ended up.

In practice

An auditor at an accounting firm pastes a client's confidential annual accounts into a free online AI chat to get a summary, not knowing the provider may keep the text and use it to train future models.

Why it matters

Useful AI tools are free and one click away, so bans alone rarely work; without approved options and clear rules, personal and secret data quietly leaves the organisation.

Technical deep dive

Shadow AI is a subset of shadow IT, but it has three properties that make it harder to manage. First, the data flow is the point of the tool: using a chat assistant means sending text, files or code to a third-party model, so every use is a potential disclosure. Second, output flows back into work products - contracts, code, case decisions - carrying hallucinations, licence contamination or bias into the organisation's records without any trace of how it was produced. Third, AI arrives not only as new services but as features switched on inside already-approved SaaS, as browser extensions with read access to every page, as desktop agents and MCP servers with local file and shell access, and as locally run open-weight models that never cross the network perimeter. The widely reported 2023 case in which Samsung engineers pasted proprietary source code into ChatGPT, followed by an internal ban, is the reference example.

The key technical distinction is between consumer and enterprise tiers of the same product. Consumer terms have commonly allowed use of prompts to improve models (often with an opt-out), longer retention and human review, whereas enterprise and API offerings typically exclude training on customer data, offer retention controls, SSO, audit logs and a data processing agreement. Under GDPR, sending personal data to a provider without a data processing agreement under Art. 28, without a transfer basis under Chapter V where data leaves the EEA, and without a record in the Art. 30 register is unlawful processing regardless of intent - and, depending on what happens to the data, may amount to a personal data breach.

Discovery combines several telemetry sources: secure web gateway, CASB or SSE logs and DNS data categorised for generative-AI domains; OAuth consent grants to third-party AI apps in Microsoft 365 or Google Workspace; browser-extension and software inventories from endpoint management; expense reports and card transactions for AI subscriptions; and admin consoles of approved SaaS for newly enabled AI features. Control options range from monitoring and coaching prompts, through DLP inspection of uploads and pastes to AI domains, to blocking - but blocking alone tends to push use to personal devices, which is why the recommended pattern is to provide a sanctioned enterprise alternative, publish an acceptable-use policy with data classification rules, and run a fast intake process for new tools.

Shadow AI also creates regulatory blind spots under the EU AI Act. An organisation cannot meet deployer obligations under Art. 26 for high-risk use it does not know about - for example a manager screening CVs with an unapproved tool - and Art. 4 expects providers and deployers to support AI literacy among staff. AI governance, with an inventory, clear ownership and approved tools, is therefore the structural mitigation, while technical controls provide detection and enforcement.

What to learn first

Everything this builds on, foundations first.

  1. Artificial intelligence (AI)
  2. →Shadow AI

Relationships

A kind of
Shadow IT

Sources & further reading

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.