Key takeaways
- Shadow artificial intelligence (shadow AI) is the use of AI tools, models, or services without the knowledge, approval, or oversight of the people accountable for an organisation’s data, risk, and compliance.
- Adoption is close to universal. Gartner found that 68% of employees use unauthorised AI tools at work, up from 41% in 2023, and most of that usage never reaches an approval queue.
- The common framing, a data-leakage and security problem, is incomplete. Shadow AI is first a governance failure: it is the AI that never made it onto your inventory.
- Under the
EU AI Act, obligations attach to the organisation regardless of how a system was adopted, so an incomplete AI inventory is itself a compliance gap. - The answer is not a ban. It is discovery, a central AI register, clear ownership, and risk classification: the work of turning ungoverned AI into governed AI.

What is shadow artificial intelligence?
Shadow artificial intelligence is the use of AI tools, models, or services by employees or teams without the knowledge, approval, or governance of the people responsible for the organisation’s data, risk, and compliance. In practice it is the marketing manager drafting campaigns in a personal chatbot account, the analyst pasting a customer file into a free model to summarise it, and the developer accepting code from an assistant that was never reviewed by security. A quick note on the term, because search engines conflate two meanings. “AI shadow” can refer to image-editing tools that generate realistic shadows in photographs. That is not the subject here. In a governance and compliance context, shadow artificial intelligence means unsanctioned, ungoverned AI use inside an organisation, the direct descendant of shadow IT. The defining feature is invisibility. The tool works, the employee is more productive, and nobody responsible for oversight knows the system exists. That gap between the AI an organisation actually runs on and the AI it can account for is the entire problem. Our own explainer on the shadow AI governance gap frames it the same way: you cannot govern what you have not seen.
Shadow AI vs shadow IT
Shadow IT taught a generation of security teams that employees adopt tools faster than approval processes can keep up. Shadow AI shares that root cause but adds two properties that make it sharper. First, data does not just sit in an unapproved app; it leaves the perimeter and becomes an input that a third-party model may retain or train on. Second, the output is non-deterministic, so the same prompt can produce different answers, and a plausible-sounding response can be wrong. A misconfigured file-sharing tool leaks what you put in it. An ungoverned model can leak what you put in, then shape a decision on the way out.
Why shadow AI is spreading so fast
Three forces push adoption. Generative AI arrived as a consumer product first, so employees met it at home before governance met it at work. The productivity gains are immediate and personal, which makes the tools sticky. And access is frictionless: a browser tab and an email address, with no procurement step to slow anyone down. The numbers describe a near-universal behaviour rather than a fringe one. Gartner reported that 68% of employees use unauthorised AI tools, up from 41% in 2023. Survey work compiled in the UpGuard State of Shadow AI put the figure even higher, with 81% of employees and 88% of security leaders admitting to unapproved AI use. Industry reporting places overall shadow AI usage growth at roughly 156% between 2023 and 2025, with general-purpose chat assistants accounting for the overwhelming majority of unsanctioned activity. The pattern to notice is that this is not confined to junior staff experimenting at the edges. Executives and senior technical staff are among the heaviest users, precisely the people handling the most sensitive material. Prohibition tends to move that behaviour further out of sight rather than stopping it.
Common examples of shadow AI
Shadow AI is easiest to grasp by function, because it shows up wherever a repetitive task meets an available model. <table header-row=”true”> <tr> <td>Function</td> <td>Typical shadow AI use</td> <td>What is exposed</td> </tr> <tr> <td>Marketing</td> <td>Drafting copy and generating images in personal accounts</td> <td>Brand data, unreleased campaigns</td> </tr> <tr> <td>Engineering</td> <td>Unsanctioned code assistants and snippet generators</td> <td>Source code, secrets, licence risk</td> </tr> <tr> <td>Data and analytics</td> <td>Pasting datasets into a chatbot to summarise or clean</td> <td>Customer and financial records</td> </tr> <tr> <td>HR and recruiting</td> <td>Screening or ranking candidates with a consumer tool</td> <td>Personal data, discrimination risk</td> </tr> <tr> <td>Finance and legal</td> <td>Summarising contracts or filings in a free model</td> <td>Confidential and privileged material</td> </tr> </table> Two details make these examples more than anecdotes. The HR case can pull an organisation into high-risk territory under the EU AI Act, because AI used for recruitment and candidate evaluation is classified as high-risk. And the analytics case is where sensitive data most often crosses into a third-party model, which is why roughly 38% of employees admit to sharing sensitive work information with AI tools without permission, according to security research summarised by Orca Security.
The real risks: beyond data leakage
Data and intellectual property exposure is the risk everyone names first, and the cost is now measurable. The IBM Cost of a Data Breach 2025 report found that breaches involving shadow AI cost around 670,000 US dollars more than breaches without it, and that 20% of breached organisations had suffered an incident involving shadow AI. The same report found that 97% of organisations that experienced an AI-related breach lacked proper AI access controls, and 63% had no AI governance policy at all. But data leakage is only the most visible failure. Four other risks matter as much:
- Security and attack surface. Unsanctioned models and their integrations sit outside monitoring, and their traffic often resembles ordinary web activity, so conventional tooling misses it.
- Compliance and regulatory exposure. If a tool processes personal data or feeds a high-risk decision, the organisation carries the obligation whether or not it knew the tool existed.
- Accuracy and decision quality. A confident, wrong answer that shapes a hiring, credit, or clinical judgement is a governance event, not a typo.
- Agentic risk. As tools gain the ability to act, not just answer, an ungoverned agent with access to systems can take consequential steps no one authorised.
What the security framing misses
Most coverage of shadow AI stops at the leaked file. That framing is correct but shallow, because it treats the problem as a perimeter to defend rather than a population to govern. The deeper exposure is ungoverned accountability: no owner, no risk classification, no record that the system exists, and therefore no way to answer a regulator, an auditor, or a board that asks a simple question. Which AI systems are we running, who owns them, and what could they do? A security tool can block a connection. It cannot tell you that.
Shadow AI is an EU AI Act problem, not only a security problem
This is where the governance lens changes the stakes. The EU AI Act does not offer an exemption for AI that employees adopted without approval. Its obligations attach to the organisation acting as a deployer or provider, regardless of how a given system entered the estate. An organisation that cannot produce a complete, risk-classified inventory of the AI it uses cannot demonstrate compliance, and shadow AI is precisely the population missing from that inventory. Several obligations bite directly. Article 4 requires providers and deployers to ensure a sufficient level of AI literacy among staff, and it has applied since 2 February 2025. Where AI is used for a high-risk purpose, such as recruitment or creditworthiness, the deployer inherits duties around human oversight, input data governance, and log retention. The enforcement calendar is close: obligations for general-purpose AI models applied from 2 August 2025, and the bulk of the high-risk regime applies from 2 August 2026. Penalties are structured to be felt, reaching up to 7% of global annual turnover for prohibited practices and up to 3% for most other obligation breaches. The same principle sits at the centre of the major frameworks. The NIST AI Risk Management Framework makes maintaining an inventory of AI systems and assigning clear accountability a foundational part of its GOVERN and MAP functions. ISO/IEC 42001, the AI management system standard, expects an organisation to keep a record of its AI systems and define roles and responsibilities around them. Across every serious framework, the first move is the same: know what you have.
From detection to governance: closing the shadow AI gap
Security vendors answer shadow AI with detect-and-block. That is a necessary control, but it is a starting point, not a destination. Governance answers with a lifecycle: discover, inventory, assign an owner, classify the risk, govern the system through its life, and attest to it on a schedule. The difference is the difference between stopping a connection and being able to stand behind every AI decision your organisation makes. The object that makes this possible is an AI register: a single system of record that holds every AI system, its owner, its purpose, its risk tier, and its evidence. Our own AI registry is built for exactly this transition, turning a scattered, invisible AI footprint into a governed one. Once a system is on the register, it stops being shadow AI. It becomes an asset with an owner and a control set, which is the only state from which compliance, oversight, and honest board reporting are possible.
Why banning does not work
A blanket ban feels decisive and rarely holds. Employees who found real value in a tool do not stop; they move to personal devices and personal accounts, where you have even less visibility than before. Prohibition converts a governable problem into an invisible one. The organisations that make progress pair enablement with governance: approved tools that are genuinely good, a clear and fast route to get a new tool assessed, and a register that captures what is actually in use. Enablement plus governance beats prohibition, because it works with the behaviour instead of against it.
How to bring shadow AI under governance in practice
A workable programme has five moves, in order.
- Discover. Combine an anonymous usage survey with technical discovery from network and SaaS logs. The goal is an honest first picture, not a disciplinary exercise.
- Register. Record every system found in one central AI register, so the inventory becomes a living record rather than a spreadsheet that ages the day it is finished.
- Assign ownership and classify risk. Give every system a named owner and a risk tier, using the
EU AI Actcategories where they apply. Ownership is what makes the rest enforceable. - Enable and educate. Provide approved alternatives that people actually want to use, and meet the Article 4 literacy duty with training that explains why the register exists.
- Attest continuously. Re-confirm ownership, risk tier, and controls on a schedule, and report the state of the estate to the board. Continuous attestation is what keeps the inventory true.
None of these steps is exotic. What makes them work is doing them in a system built for governance rather than in a static document, so that the register stays current as the AI estate changes underneath it.
FAQ
What is shadow artificial intelligence? Shadow artificial intelligence is the use of AI tools, models, or services inside an organisation without the knowledge, approval, or oversight of the people accountable for its data, risk, and compliance. It is the AI equivalent of shadow IT, with the added risk that data leaves the perimeter into a third-party model and outputs can shape decisions. What is an example of shadow AI? A common example is an analyst pasting a spreadsheet of customer records into a free chatbot to summarise it, using a personal account that security and compliance never approved. Other frequent examples include marketing teams generating copy in personal AI accounts and developers accepting code from unsanctioned assistants. Why is shadow AI a problem? Because it creates exposure no one is managing: sensitive data can leave the organisation, decisions can rest on unverified outputs, and the AI never appears on any inventory. Under the EU AI Act, obligations apply regardless of how a tool was adopted, so unrecorded AI is a direct compliance gap, not just a security one. How does shadow AI work? It spreads through frictionless access. An employee signs up for a consumer AI tool with a browser and an email address, uses it to do real work faster, and never routes it through procurement or security. Because the traffic looks like ordinary web activity and the productivity gain is real, the usage persists and multiplies quietly. How do you detect shadow AI? Detection combines two methods: an anonymous survey that asks people what they actually use, and technical discovery from network, proxy, and SaaS logs that surfaces AI traffic and applications. The output of both should feed a central AI register so that detection leads to governance rather than a one-off audit. Can you stop shadow AI by banning AI tools? Rarely. Bans tend to push usage onto personal devices and accounts, where visibility is lower still. The more durable approach pairs governance with enablement: approved tools that people want, a fast assessment path for new ones, and a register that keeps the inventory honest.
Conclusion
Shadow artificial intelligence is not, at its core, a story about rogue employees or leaked files. It is a story about the distance between the AI an organisation runs on and the AI it can account for. Security controls narrow that distance; only governance closes it. The organisations that will pass an audit, satisfy the EU AI Act, and give their boards a straight answer are the ones that move shadow AI onto a register, give every system an owner and a risk tier, and keep that record true over time. If you want a single place to start, start with the inventory: put the AI you cannot see onto an AI registry, and it stops being a shadow.