Shadow AI: what it is, the risks, and how to bring it into the open

Shadow AI: what it is, the risks, and how to bring it into the open

Shadow AI is any AI tool, account or feature your staff use for work that the company has not approved and cannot see. The classic case is an employee pasting a client contract into a personal ChatGPT account to summarize it. The fix is rarely a ban: find what people use, give them an approved option that is as good, and set two or three clear rules.

On this page

What is shadow AI?

Shadow AI is the use of AI at work outside the company's view. It covers three things, and most guides only talk about the first:

  • Personal accounts: free or paid ChatGPT, Claude, Gemini or Perplexity accounts used for work tasks.
  • Unapproved tools: AI note-takers that join calls, browser extensions that read every page, AI writing or image apps signed up for with a work email.
  • Hidden features: AI switched on inside software you already pay for, such as a CRM, help desk or design tool, without anyone reviewing what data it sends where.

The third group is the easiest to miss. Nobody "installed" anything, yet customer records may now go to a new AI provider under terms nobody read.

Shadow AI fix in four weeks: week 1 amnesty survey, week 2 register and risk tiers, week 3 approved tools and swap table, week 4 short rules, team training and closing personal accounts for company data

Shadow AI vs shadow IT

Shadow IT is any unapproved software or device, like a team running its projects in a personal Trello board. Shadow AI is a subset with two extra problems.

Shadow IT Shadow AI
What leaves the company Files stored in the wrong place Text pasted into prompts, which may be kept or used for training
Output risk Low: the tool stores what you give it High: the tool writes new content that can be wrong and still look right
Cost to start Usually a sign-up Free, instant, in any browser tab
How visible Often shows up in expenses or SSO logs Personal accounts on personal devices leave almost no trace

Why employees use shadow AI

Mostly because it helps them and the approved route is slow or missing. Microsoft and LinkedIn's 2024 Work Trend Index, a survey of 31,000 knowledge workers in 31 countries, found that 78% of AI users bring their own AI tools to work. At small and medium-sized companies the figure was 80%.

That number changes how you should respond. If most people who use AI are already bringing their own, a ban pushes the habit onto phones and personal laptops, where you see even less. The goal is to make the approved option the easy one.

Shadow AI risks

The risks are real, but they are specific. Name them, and you can put one control on each.

Risk What happens Control
Data used for training Consumer chat accounts can use conversations to train models unless the user turns it off Business plans only for company data
Confidentiality and contracts Client data goes to a third party your contract or NDA does not allow Data rules by type: public, internal, confidential, personal
Personal data Customer or staff details processed without a legal basis or a vendor agreement No personal data in any tool without a signed vendor agreement
Wrong output A confident but wrong answer goes into a report, contract or customer reply A named human checks anything that leaves the team
Account sprawl Work history sits in personal accounts that leave when the person leaves Company accounts, set up through single sign-on
Over-permissioned add-ons Extensions and note-takers get access to mail, calendar or every page viewed Review app permissions before approval

On the first row: OpenAI's data controls FAQ says ChatGPT Free and Plus conversations are used to improve its models by default, and users can turn this off in Settings under Data controls. It also says content from ChatGPT Business, Enterprise and Edu workspaces is not used for training by default. Other vendors set their own terms, so check each one. That single difference is why moving work onto business plans removes most of the data risk in one step.

How to detect shadow AI

Start with the cheap methods. They find most of it.

  1. Ask. Run the amnesty survey below. People will tell you, as long as there is no penalty for the answer.
  2. Check expenses and card statements for AI subscriptions bought on company cards.
  3. Review app consents in Google Workspace or Microsoft 365. Look for AI apps that staff have connected to mail, calendar or files.
  4. List browser extensions on managed devices. Look for AI writing, summarizing and meeting tools.
  5. Audit AI features in your existing software. Ask each vendor which AI features are on and which provider processes the data.
  6. Check network or DNS logs for traffic to AI services, if you have the tools. This finds volume, not intent.

None of these catches a personal account on a personal phone. Only a better approved option and clear rules do that.

The AI amnesty survey you can copy

This is the step none of the top results gives you, and it does most of the work. Send it from the leadership team, say plainly that there is no penalty for honest answers, and give people one week.

Subject: Which AI tools help you at work? (2 minutes, no penalty)

We want to support the AI tools that help you, and make them safe.
There is no penalty for anything you tell us here.

1. Which AI tools have you used for work in the last 3 months?
   (ChatGPT, Claude, Gemini, Copilot, note-takers, extensions, other)
2. Free account, paid personal account, or company account?
3. What do you use each one for? (one line each)
4. What kind of information have you put in?
   (public / internal / client or customer / personal data)
5. If we gave you one approved AI tool, what must it do for you?

Question 5 matters most. It tells you what the approved tool has to do, so people stop needing the shadow one.

Swap table: shadow habit to approved option

Use the survey answers to fill a table like this. Each row replaces a habit with something as easy, plus one rule.

Shadow habit Approved option Rule
Personal ChatGPT for drafting and summaries Company ChatGPT, Claude or Gemini business plan Company data only in the company account
Free AI note-taker joining client calls The note-taker built into your approved meeting tool Tell attendees; client calls need consent
Pasting spreadsheets with customer data into a chatbot Approved tool with a vendor agreement, data removed or masked No personal data without a vendor agreement
AI browser extension that reads every page Remove, or approve one after a permissions review Extensions only from the approved list
AI features switched on in the CRM by default Keep on or switch off after a vendor check New AI features reviewed before rollout

A 30-day plan to bring shadow AI into the open

Week Do this Done when
1 Send the amnesty survey. Pull expense, app-consent and extension data. Most staff have answered
2 List every tool and use in one register. Tier each use: low, medium or high risk. Register complete, high-risk uses flagged
3 Buy or switch on the approved tool. Publish the swap table. Every common use has an approved option
4 Publish short rules, run a 30-minute session per team, set a date to close personal-account use for company data. Rules signed, review date set

Week 2 is where shadow AI turns into governance. Our guide to an AI governance framework covers the register, owners and risk tiers in more detail. For week 4, the generative AI policy template gives you the sections to write, and these AI acceptable use policy examples show the clauses most companies get wrong. If people still ignore the rules after launch, read how to roll out a company AI policy so they follow it.

There is also a legal reason to do the training step. If the EU AI Act applies to you, Article 4 of Regulation 2024/1689 asks deployers of AI systems to take measures to ensure a sufficient level of AI literacy among their staff. That duty has applied since February 2, 2025. Keep a record of who was trained and when. This is a summary of the rule, not legal advice.

Want the approved setup, rules and team guidance done for you? AI Setup for Your Company builds them from a short brief about how your teams already use AI.

Shadow AI FAQ

What is shadow AI?

Shadow AI is the use of AI tools, accounts or features for work without the company's approval or knowledge. Common examples are personal ChatGPT or Claude accounts used for work, AI note-takers joining calls, AI browser extensions, and AI features switched on inside existing software. The main risks are company data leaving through consumer accounts and unchecked AI output reaching customers.

What are the risks of shadow AI?

The main risks are confidential or personal data going to providers you have no agreement with, conversations in consumer accounts being used to train models by default, wrong AI output reaching clients, and work history stuck in personal accounts. Each has a direct control: business plans, data rules by type, human review of anything that leaves the team, and company accounts through single sign-on.

How do you detect shadow AI?

Start by asking staff through a short no-penalty survey, then check expense reports for AI subscriptions, review the AI apps connected to Google Workspace or Microsoft 365, list browser extensions on managed devices, and ask software vendors which AI features are on. Network or DNS logs can show traffic volume to AI services. No method sees personal accounts on personal phones.

Should companies ban ChatGPT to stop shadow AI?

A ban usually moves the habit onto personal phones and laptops, where you see even less. Microsoft and LinkedIn's 2024 Work Trend Index found 78% of AI users bring their own AI tools to work. A safer approach is to provide an approved business plan, set clear rules on what data can go in, and train people to check output before it is used.

What is the difference between shadow AI and shadow IT?

Shadow IT is any software or device used without approval. Shadow AI is a subset with two extra risks. What staff paste into prompts may be kept or used for training, and the tool creates new content that can be wrong while looking right. Shadow AI is also harder to see, because a free account in a browser tab leaves almost no trace.

Is shadow AI a compliance issue?

It can be. Personal data put into an unapproved AI tool may breach privacy law or customer contracts, and client data may breach an NDA. If the EU AI Act applies to your company, Article 4 asks deployers of AI systems to ensure staff have sufficient AI literacy, which is hard to show when you do not know which tools people use. Check the rules that apply to you.

Laisser un commentaire :