Shadow AI: Shadow AI is the use of AI tools inside an organization without the knowledge or approval of IT, security, or leadership: personal ChatGPT accounts, browser extensions, and AI features quietly switched on inside existing software.
The name borrows from shadow IT, the long-standing problem of employees adopting unapproved software because the sanctioned tools are slow to arrive or hard to use. Shadow AI is the same pattern at higher speed. Someone pastes a customer contract into a free chat assistant to summarize it, installs a meeting-notes bot that joins every call, or turns on an AI feature inside a tool the company already pays for, and nobody responsible for data protection knows.
The exposure is mostly about data. Consumer AI tools may retain conversations and use them to improve models unless settings or paid plans say otherwise, so confidential material can leave the company with no record. For regulated work that can mean protected health information, privileged client documents, financial data covered by GLBA or SOX, or employee records going somewhere they are not allowed to go. There is also no audit trail, no consistency in quality, and no way to answer a customer who asks how their data is handled.
Bans rarely work; they push usage further underground. What does work is to provide approved tools with business-grade data terms, publish a short plain-language policy that says what can and cannot be pasted where, keep an allow-list people can request additions to, and ask teams what they already use without punishing honest answers. The rule to repeat: never put confidential data into a consumer AI tool unless your organization has approved it.
Example at work
A finance manager discovers that three analysts have been using personal AI accounts to clean up spreadsheets containing customer payment data. Instead of writing them up, she gets the company's enterprise AI plan extended to her team within two weeks, runs a 30-minute session on what is allowed, and adds the tool to the onboarding checklist.
Why it matters
Shadow AI is probably already happening on your team. The question is whether it happens with protected data and no visibility, or with approved tools and clear rules. Getting ahead of it is a governance problem with a practical, low-drama solution.
Related terms
- Workplace AI policyA workplace AI policy is a written set of rules that tells employees which AI tools they may use, what data they may put into them, how to verify and disclose AI-assisted work, and who to ask when unsure.
- Data privacyData privacy, in the context of AI, is the set of rules and practices that govern what information you put into an AI system, who can see it, how long the vendor keeps it, and whether it is used to train future models.
- Personally identifiable information (PII)Personally identifiable information (PII) is any data that can identify a specific person on its own or in combination with other data, such as a name, address, Social Security number, email, phone number, photo, or account ID.
- AI governanceAI governance is the set of policies, roles, controls, and oversight processes an organization uses to decide how AI is adopted, used, monitored, and held accountable across the business.
- Zero data retention (ZDR)Zero data retention (ZDR) is an arrangement in which an AI provider does not store your prompts or the model's responses after the request is processed, so nothing is kept for training, debugging, or later review. Mainly offered on API and enterprise plans.